Ok autant pour moi
Le rapport de suppression est le suivant
RogueKiller V7.5.0 [24/05/2012] par Tigzy
mail: tigzyRK<at>gmail<dot>com
Remontees:
http://www.sur-la-toile.com/discussion- ... ntees.html
Blog:
http://tigzyrk.blogspot.com
Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Demarrage : Mode normal
Utilisateur: Charles [Droits d'admin]
Mode: Suppression -- Date: 26/05/2012 12:09:26
¤¤¤ Processus malicieux: 1 ¤¤¤
[SUSP PATH] SpotifyWebHelper.exe -- C:\Users\Charles\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe -> KILLED [TermProc]
¤¤¤ Entrees de registre: 53 ¤¤¤
[SUSP PATH] HKCU\[...]\Run : Spotify Web Helper ("C:\Users\Charles\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe") -> DELETED
[SUSP PATH] At1.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At10.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At11.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At12.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At13.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At14.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At15.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At16.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At17.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At18.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At19.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At2.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At20.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At21.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At22.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At23.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At24.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At25.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At26.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At27.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At28.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At29.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At3.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At30.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At31.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At32.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At33.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At34.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At35.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At36.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At37.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At38.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At39.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At4.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At40.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At41.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At42.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At43.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At44.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At45.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At46.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At47.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At48.job @ : C:\ProgramData\o2364IcY.exe_ -> DELETED
[SUSP PATH] At5.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At6.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At7.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At8.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[SUSP PATH] At9.job @ : C:\ProgramData\o2364IcY.exe -> DELETED
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤
¤¤¤ Driver: [CHARGE] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ Fichier HOSTS: ¤¤¤
ÿþ1
¤¤¤ MBR Verif: ¤¤¤
+++++ PhysicalDrive0: ST9160823ASG +++++
--- User ---
[MBR] 9346cdeec0f1bfab671eaccec31a278c
[BSP] 162060bb474056eae6dde76395768ebf : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 211 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 434176 | Size: 10240 Mo
2 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 21405696 | Size: 142174 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Termine : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt