Re: Sablier de la souris qui tourne indéfiniment
Posté : jeu. 10 mai 2012 19:14
Bonsoir,
Voilà le Rapport RogueKiller :
RogueKiller V7.4.4 [08/05/2012] par Tigzy
mail: tigzyRK<at>gmail<dot>com
Remontees: http://www.sur-la-toile.com/discussion- ... ntees.html
Blog: http://tigzyrk.blogspot.com
Systeme d'exploitation: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Demarrage : Mode normal
Utilisateur: Maël [Droits d'admin]
Mode: Suppression -- Date: 10/05/2012 19:13:36
¤¤¤ Processus malicieux: 1 ¤¤¤
[SUSP PATH] SpotifyWebHelper.exe -- C:\Users\Maël\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe -> KILLED [TermProc]
¤¤¤ Entrees de registre: 5 ¤¤¤
[SUSP PATH] HKCU\[...]\Run : Spotify Web Helper ("C:\Users\Maël\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe") -> DELETED
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤
¤¤¤ Driver: [NON CHARGE] ¤¤¤
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ Fichier HOSTS: ¤¤¤
127.0.0.1 localhost
127.0.0.1 activate.adobe.com
¤¤¤ MBR Verif: ¤¤¤
+++++ PhysicalDrive0: WDC WD3200BEKT-60F3T1 +++++
--- User ---
[MBR] 408a562c14c040601116062909fedba0
[BSP] 71311cba74403f570223a666a72b7f04 : Windows Vista/7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 305043 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] 88be900b81d4e27ef800065f2c8780ee
[BSP] 5d1a242686ce60ac1f61664168bb24fd : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 409600 | Size: 59392 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 122044416 | Size: 40000 Mo
2 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 203964416 | Size: 600 Mo
3 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 205193216 | Size: 200 Mo
Termine : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
@+
Voilà le Rapport RogueKiller :
RogueKiller V7.4.4 [08/05/2012] par Tigzy
mail: tigzyRK<at>gmail<dot>com
Remontees: http://www.sur-la-toile.com/discussion- ... ntees.html
Blog: http://tigzyrk.blogspot.com
Systeme d'exploitation: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Demarrage : Mode normal
Utilisateur: Maël [Droits d'admin]
Mode: Suppression -- Date: 10/05/2012 19:13:36
¤¤¤ Processus malicieux: 1 ¤¤¤
[SUSP PATH] SpotifyWebHelper.exe -- C:\Users\Maël\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe -> KILLED [TermProc]
¤¤¤ Entrees de registre: 5 ¤¤¤
[SUSP PATH] HKCU\[...]\Run : Spotify Web Helper ("C:\Users\Maël\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe") -> DELETED
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤
¤¤¤ Driver: [NON CHARGE] ¤¤¤
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ Fichier HOSTS: ¤¤¤
127.0.0.1 localhost
127.0.0.1 activate.adobe.com
¤¤¤ MBR Verif: ¤¤¤
+++++ PhysicalDrive0: WDC WD3200BEKT-60F3T1 +++++
--- User ---
[MBR] 408a562c14c040601116062909fedba0
[BSP] 71311cba74403f570223a666a72b7f04 : Windows Vista/7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 305043 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] 88be900b81d4e27ef800065f2c8780ee
[BSP] 5d1a242686ce60ac1f61664168bb24fd : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 409600 | Size: 59392 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 122044416 | Size: 40000 Mo
2 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 203964416 | Size: 600 Mo
3 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 205193216 | Size: 200 Mo
Termine : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
@+