le contenu
RogueKiller V4.3.7 par Tigzy
contact sur
http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Remontees:
http://www.sur-la-toile.com/discussion- ... ntees.html
Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Demarrage : Mode normal
Utilisateur: didier [Droits d'admin]
Mode: Suppression -- Date : 05/04/2011 20:42:14
Processus malicieux: 2
[APPDT/TMP/DESKTOP] ndg.exe -- c:\users\didier\appdata\local\ndg.exe -> KILLED
[APPDT/TMP/DESKTOP] lsnfier.exe -- c:\users\didier\appdata\roaming\microsoft\notification de cadeaux msn\lsnfier.exe -> KILLED
Entrees de registre: 7
[APPDT/TMP/DESKTOP] Notification de cadeaux MSN.lnk : C:\Users\didier\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe -> DELETED
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{9313BE16-BF96-46ED-8D59-D9B7ED7516C7} : NameServer (0.0.0.0) -> NOT REMOVED, USE DNSFIX
[DNS] HKLM\[...]\ControlSet002\Parameters\Interfaces\{9313BE16-BF96-46ED-8D59-D9B7ED7516C7} : NameServer (0.0.0.0) -> NOT REMOVED, USE DNSFIX
[DNS] HKLM\[...]\ControlSet003\Parameters\Interfaces\{9313BE16-BF96-46ED-8D59-D9B7ED7516C7} : NameServer (0.0.0.0) -> NOT REMOVED, USE DNSFIX
[FILE ASSO] HKCU\[...]Software\Classes\.exe\shell\open\command : ("C:\Users\didier\AppData\Local\ndg.exe" -a "%1" %*) -> REPLACED : ("%1" %*)
[FILE ASSO] HKCU\[...]Software\Classes\exefile\shell\open\command : ("C:\Users\didier\AppData\Local\ndg.exe" -a "%1" %*) -> REPLACED : ("%1" %*)
[FILE ASSO] HKLM\[...]Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command : ("C:\Users\didier\AppData\Local\ndg.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") -> REPLACED : ("C:\Program Files\internet explorer\iexplore.exe")
Fichier HOSTS:
127.0.0.1 localhost
::1 localhost
Termine : << RKreport[1].txt >>
RKreport[1].txt