Voici ce que j'obtiens :
RogueKiller V8.4.0 [Dec 15 2012] par Tigzy
mail : tigzyRK<at>gmail<dot>com
Remontees :
http://www.sur-la-toile.com/discussion- ... ntees.htmlSite Web :
http://www.sur-la-toile.com/RogueKiller/Blog :
http://tigzyrk.blogspot.com/Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Demarrage : Mode normal
Utilisateur : Simon [Droits d'admin]
Mode : Recherche -- Date : 15/12/2012 16:21:32
¤¤¤ Processus malicieux : 0 ¤¤¤
¤¤¤ Entrees de registre : 3 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : taprte (rundll32.exe "C:\Users\Simon\AppData\Roaming\taprte.dll",AGetReport) -> TROUVÉ
[RUN][SUSP PATH] HKUS\S-1-5-21-3799954329-621549533-4250650775-1000[...]\Run : taprte (rundll32.exe "C:\Users\Simon\AppData\Roaming\taprte.dll",AGetReport) -> TROUVÉ
[HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-21-3799954329-621549533-4250650775-1000\$df0dcb2beff964c4ced1139dc83e2345\n.) -> TROUVÉ
¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤
[ZeroAccess][FILE] n : C:\$recycle.bin\S-1-5-18\$df0dcb2beff964c4ced1139dc83e2345\n --> TROUVÉ
[ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-18\$df0dcb2beff964c4ced1139dc83e2345\@ --> TROUVÉ
[ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-21-3799954329-621549533-4250650775-1000\$df0dcb2beff964c4ced1139dc83e2345\@ --> TROUVÉ
[ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-18\$df0dcb2beff964c4ced1139dc83e2345\U --> TROUVÉ
[ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-3799954329-621549533-4250650775-1000\$df0dcb2beff964c4ced1139dc83e2345\U --> TROUVÉ
[ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-18\$df0dcb2beff964c4ced1139dc83e2345\L --> TROUVÉ
[ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-3799954329-621549533-4250650775-1000\$df0dcb2beff964c4ced1139dc83e2345\L --> TROUVÉ
[ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_32\Desktop.ini --> TROUVÉ
[ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini --> TROUVÉ
¤¤¤ Driver : [NON CHARGE] ¤¤¤
¤¤¤ Infection : ZeroAccess ¤¤¤
¤¤¤ Fichier HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
¤¤¤ MBR Verif: ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MK5076GSX +++++
--- User ---
[MBR] 4aa60032028cfbdf27afec1e008f1f8b
[BSP] ba65921aebb208850d9b6c4c58b7d0a4 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 459669 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 941811712 | Size: 16967 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 976560128 | Size: 103 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Termine : << RKreport[1]_S_15122012_162132.txt >>
RKreport[1]_S_15122012_162132.txt