A voir également:
- Utilisation de list kill'em
- Utilisation chromecast - Guide
- Télécharger gratuitement notice d'utilisation - Guide
- List disk - Guide
- Directory list & print - Télécharger - Divers Utilitaires
- Liste déroulante de choix excel - Guide
121 réponses
▶ Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
mais cette fois-ci :
▶ choisis l'Option Clean
ton PC va redemarrer,
laisse travailler l'outil.
en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,
▶ colle le contenu dans ta reponse
mais cette fois-ci :
▶ choisis l'Option Clean
ton PC va redemarrer,
laisse travailler l'outil.
en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,
▶ colle le contenu dans ta reponse
¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.0.0.9 ¤¤¤¤¤¤¤¤¤¤
User : Marie-Luce (Administrateurs)
Update on 13/06/2010 by g3n-h@ckm@n ::::: 01.25
Start at: 15:47:13 | 16.06.2010
Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6000 32-bit) #
Internet Explorer 8.0.6001.18904
Windows Firewall Status : Enabled
AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
C:\ -> Disque fixe local | 93.16 Go (23.97 Go free) [Vista] | NTFS
E:\ -> Disque fixe local | 91.69 Go (91.33 Go free) [Data] | NTFS
F:\ -> Disque CD-ROM
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\svchost.exe
C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WerCon.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\runonce.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\OGAExec.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\OGAExec.exe
C:\Program Files\List_Kill'em\ERUNT.EXE
C:\Program Files\List_Kill'em\pv.exe
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\Windows\Temp\18f8c10edcaa5772cebb4396.tmp
Quarantined & Deleted !! : C:\Windows\Temp\2aeb9c30d9c8b1b73c11b4c8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\4be7f3b121d496bf276b7ef3.tmp
Quarantined & Deleted !! : C:\Windows\Temp\5612eccbbccb99d9bbfe385f.tmp
Quarantined & Deleted !! : C:\Windows\Temp\5c7dc81b1175eafa15db042.tmp
Quarantined & Deleted !! : C:\Windows\Temp\603fce146543c9aab8148ba.tmp
Quarantined & Deleted !! : C:\Windows\Temp\67f93cad9cf8835651237405.tmp
Quarantined & Deleted !! : C:\Windows\Temp\68cb26eb6cc00044f1ed2afb.tmp
Quarantined & Deleted !! : C:\Windows\Temp\77f2d81dbd56a945a8ed2420.tmp
Quarantined & Deleted !! : C:\Windows\Temp\78e2d129912cc0f63b60a858.tmp
Quarantined & Deleted !! : C:\Windows\Temp\963e72d4bc0ff35073c832c8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\a0bf5d48317aa10fed799496.tmp
Quarantined & Deleted !! : C:\Windows\Temp\b7cc7c205f28d080e41a9970.tmp
Quarantined & Deleted !! : C:\Windows\Temp\b9a8d8efabae2d35a15b68c8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\bbf1242d6b2200cb7b8ea62a.tmp
Quarantined & Deleted !! : C:\Windows\Temp\c6602e7c419f5fc6e25759c5.tmp
Quarantined & Deleted !! : C:\Windows\Temp\c97ed968be982ad39a033f7.tmp
Quarantined & Deleted !! : C:\Windows\Temp\ce57d3adabb0053ac459fd25.tmp
Quarantined & Deleted !! : C:\Windows\Temp\dadb6c314f1f2edec7dba99b.tmp
Quarantined & Deleted !! : C:\Windows\Temp\db8eab529a898a9596b9c128.tmp
Quarantined & Deleted !! : C:\Windows\Temp\e42b151f4842540e47027da7.tmp
Quarantined & Deleted !! : C:\Windows\Temp\e5a35446feab0638b0706c37.tmp
Quarantined & Deleted !! : C:\Windows\Temp\fc9ec0d6985884b2b3081994.tmp
Quarantined & Deleted !! : C:\Users\Marie-Luce\AppData\Local\GDIPFONTCACHEV1.DAT
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$IF63PE4.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$IKEVIIF.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$IMIQDIB.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$IP3D19H.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$IWL3RDD.log
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$R3JMSRF.BAK
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$RF63PE4.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$RKEVIIF.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$RMIQDIB.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$RP3D19H.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$RWL3RDD.log
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$R3JMSRF.BAK
=======
Hosts :
=======
127.0.0.1 localhost
========
Registry
========
Deleted : "HKCU\Software\Search Settings"
=================
Internet Explorer
=================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.google.com/?gws_rd=ssl
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
===============
Security Center
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
cval REG_DWORD 1 (0x1)
UacDisableNotify REG_DWORD 1 (0x1)
InternetSettingsDisableNotify REG_DWORD 1 (0x1)
AutoUpdateDisableNotify REG_DWORD 1 (0x1)
FirstRunDisabled REG_DWORD 1 (0x1)
AntiVirusDisableNotify REG_DWORD 0 (0x0)
FirewallDisableNotify REG_DWORD 0 (0x0)
UpdatesDisableNotify REG_DWORD 0 (0x0)
AntiVirusOverride REG_DWORD 1 (0x1)
FirewallOverride REG_DWORD 1 (0x1)
========
Services
=========
Ndisuio : Start = 3
EapHost : Start = 2
Wlansvc : Start = 2
SharedAccess : Start = 2
windefend : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
============
Disk Cleaned
anti-ver blaster : OK
Prefetch cleaned
================
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys
kernel: MBR read successfully
user & kernel MBR OK
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
User : Marie-Luce (Administrateurs)
Update on 13/06/2010 by g3n-h@ckm@n ::::: 01.25
Start at: 15:47:13 | 16.06.2010
Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6000 32-bit) #
Internet Explorer 8.0.6001.18904
Windows Firewall Status : Enabled
AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
C:\ -> Disque fixe local | 93.16 Go (23.97 Go free) [Vista] | NTFS
E:\ -> Disque fixe local | 91.69 Go (91.33 Go free) [Data] | NTFS
F:\ -> Disque CD-ROM
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\svchost.exe
C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WerCon.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\runonce.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\OGAExec.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\OGAExec.exe
C:\Program Files\List_Kill'em\ERUNT.EXE
C:\Program Files\List_Kill'em\pv.exe
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\Windows\Temp\18f8c10edcaa5772cebb4396.tmp
Quarantined & Deleted !! : C:\Windows\Temp\2aeb9c30d9c8b1b73c11b4c8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\4be7f3b121d496bf276b7ef3.tmp
Quarantined & Deleted !! : C:\Windows\Temp\5612eccbbccb99d9bbfe385f.tmp
Quarantined & Deleted !! : C:\Windows\Temp\5c7dc81b1175eafa15db042.tmp
Quarantined & Deleted !! : C:\Windows\Temp\603fce146543c9aab8148ba.tmp
Quarantined & Deleted !! : C:\Windows\Temp\67f93cad9cf8835651237405.tmp
Quarantined & Deleted !! : C:\Windows\Temp\68cb26eb6cc00044f1ed2afb.tmp
Quarantined & Deleted !! : C:\Windows\Temp\77f2d81dbd56a945a8ed2420.tmp
Quarantined & Deleted !! : C:\Windows\Temp\78e2d129912cc0f63b60a858.tmp
Quarantined & Deleted !! : C:\Windows\Temp\963e72d4bc0ff35073c832c8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\a0bf5d48317aa10fed799496.tmp
Quarantined & Deleted !! : C:\Windows\Temp\b7cc7c205f28d080e41a9970.tmp
Quarantined & Deleted !! : C:\Windows\Temp\b9a8d8efabae2d35a15b68c8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\bbf1242d6b2200cb7b8ea62a.tmp
Quarantined & Deleted !! : C:\Windows\Temp\c6602e7c419f5fc6e25759c5.tmp
Quarantined & Deleted !! : C:\Windows\Temp\c97ed968be982ad39a033f7.tmp
Quarantined & Deleted !! : C:\Windows\Temp\ce57d3adabb0053ac459fd25.tmp
Quarantined & Deleted !! : C:\Windows\Temp\dadb6c314f1f2edec7dba99b.tmp
Quarantined & Deleted !! : C:\Windows\Temp\db8eab529a898a9596b9c128.tmp
Quarantined & Deleted !! : C:\Windows\Temp\e42b151f4842540e47027da7.tmp
Quarantined & Deleted !! : C:\Windows\Temp\e5a35446feab0638b0706c37.tmp
Quarantined & Deleted !! : C:\Windows\Temp\fc9ec0d6985884b2b3081994.tmp
Quarantined & Deleted !! : C:\Users\Marie-Luce\AppData\Local\GDIPFONTCACHEV1.DAT
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$IF63PE4.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$IKEVIIF.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$IMIQDIB.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$IP3D19H.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$IWL3RDD.log
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$R3JMSRF.BAK
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$RF63PE4.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$RKEVIIF.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$RMIQDIB.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$RP3D19H.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$RWL3RDD.log
Deleted !! : C:\$Recycle.bin\S-1-5-21-3982350614-2042332163-1476040662-1000\$R3JMSRF.BAK
=======
Hosts :
=======
127.0.0.1 localhost
========
Registry
========
Deleted : "HKCU\Software\Search Settings"
=================
Internet Explorer
=================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.google.com/?gws_rd=ssl
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
===============
Security Center
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
cval REG_DWORD 1 (0x1)
UacDisableNotify REG_DWORD 1 (0x1)
InternetSettingsDisableNotify REG_DWORD 1 (0x1)
AutoUpdateDisableNotify REG_DWORD 1 (0x1)
FirstRunDisabled REG_DWORD 1 (0x1)
AntiVirusDisableNotify REG_DWORD 0 (0x0)
FirewallDisableNotify REG_DWORD 0 (0x0)
UpdatesDisableNotify REG_DWORD 0 (0x0)
AntiVirusOverride REG_DWORD 1 (0x1)
FirewallOverride REG_DWORD 1 (0x1)
========
Services
=========
Ndisuio : Start = 3
EapHost : Start = 2
Wlansvc : Start = 2
SharedAccess : Start = 2
windefend : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
============
Disk Cleaned
anti-ver blaster : OK
Prefetch cleaned
================
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys
kernel: MBR read successfully
user & kernel MBR OK
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
mais cette fois-ci :
▶ choisis l'option ADD KEY
un document texte va s'ouvrir à l'apparition de : Text Please
▶copie/colle le texte en gras ci-dessous :
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "UacDisableNotify" /t REG_DWORD /d "0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "InternetSettingsDisableNotify" /t REG_DWORD /d "0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "AutoUpdateDisableNotify" /t REG_DWORD /d "0"
ensuite onglet "Fichier" clic sur enregistrer , puis ferme ce bloc notes
Laisse travailler l'outil
à la fin un rapport s'ouvre ,
▶ poste le resultat
mais cette fois-ci :
▶ choisis l'option ADD KEY
un document texte va s'ouvrir à l'apparition de : Text Please
▶copie/colle le texte en gras ci-dessous :
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "UacDisableNotify" /t REG_DWORD /d "0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "InternetSettingsDisableNotify" /t REG_DWORD /d "0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "AutoUpdateDisableNotify" /t REG_DWORD /d "0"
ensuite onglet "Fichier" clic sur enregistrer , puis ferme ce bloc notes
Laisse travailler l'outil
à la fin un rapport s'ouvre ,
▶ poste le resultat
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
¤¤¤¤¤¤¤¤¤¤ Keys :
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "UacDisableNotify" /t REG_DWORD /d "0
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "InternetSettingsDisableNotify" /t REG_DWORD /d "0
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "AutoUpdateDisableNotify" /t REG_DWORD /d "0"
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "UacDisableNotify" /t REG_DWORD /d "0
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "InternetSettingsDisableNotify" /t REG_DWORD /d "0
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "AutoUpdateDisableNotify" /t REG_DWORD /d "0"
▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
mais cette fois-ci :
▶ choisis l'option Kill_Rtk
un document texte va s'ouvrir à l'apparition de : Text Please
▶copie/colle le texte en gras ci-dessous :
jtnmf
ensuite onglet "Fichier" clic sur enregistrer , puis ferme ce bloc notes
Laisse travailler l'outil
à la fin un rapport s'ouvre ,
▶ poste le resultat
mais cette fois-ci :
▶ choisis l'option Kill_Rtk
un document texte va s'ouvrir à l'apparition de : Text Please
▶copie/colle le texte en gras ci-dessous :
jtnmf
ensuite onglet "Fichier" clic sur enregistrer , puis ferme ce bloc notes
Laisse travailler l'outil
à la fin un rapport s'ouvre ,
▶ poste le resultat
¤¤¤¤¤¤¤¤¤¤ Kill_Rtk By g3n-h@ckm@n ¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤ Rootkit ¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤ Services :
¤¤¤¤¤ Files :
¤¤¤¤¤ Keys | Root
¤¤¤¤¤ Keys | Services
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤ Rootkit ¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤ Services :
¤¤¤¤¤ Files :
¤¤¤¤¤ Keys | Root
¤¤¤¤¤ Keys | Services
¤¤¤¤¤¤¤¤¤¤ Kill_Rtk By g3n-h@ckm@n ¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤ Rootkit ¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤ Services :
¤¤¤¤¤ Files :
¤¤¤¤¤ Keys | Root
¤¤¤¤¤ Keys | Services
¤¤¤¤¤¤¤¤¤¤ Kill_Rtk By g3n-h@ckm@n ¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤ Rootkit ¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤ Services :
¤¤¤¤¤ Files :
¤¤¤¤¤ Keys | Root
¤¤¤¤¤ Keys | Services
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤ Rootkit ¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤ Services :
¤¤¤¤¤ Files :
¤¤¤¤¤ Keys | Root
¤¤¤¤¤ Keys | Services
¤¤¤¤¤¤¤¤¤¤ Kill_Rtk By g3n-h@ckm@n ¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤ Rootkit ¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤ Services :
¤¤¤¤¤ Files :
¤¤¤¤¤ Keys | Root
¤¤¤¤¤ Keys | Services
¤¤¤¤¤¤¤¤¤¤ Kill_Rtk By g3n-h@ckm@n ¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤ Rootkit ¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤ Services :
¤¤¤¤¤ Files :
¤ File deleted !! : C:\Windows\System32\Drivers\jtnmf.sys
¤¤¤¤¤ Keys | Root
¤ Key deleted !! : HKLM\System\CurrentControlSet\Enum\Root\LEGACY_jtnmf
¤ Key deleted !! : HKLM\System\ControlSet003\Enum\Root\LEGACY_jtnmf
¤¤¤¤¤ Keys | Services
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤ Rootkit ¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤ Services :
¤¤¤¤¤ Files :
¤ File deleted !! : C:\Windows\System32\Drivers\jtnmf.sys
¤¤¤¤¤ Keys | Root
¤ Key deleted !! : HKLM\System\CurrentControlSet\Enum\Root\LEGACY_jtnmf
¤ Key deleted !! : HKLM\System\ControlSet003\Enum\Root\LEGACY_jtnmf
¤¤¤¤¤ Keys | Services
Ben je sais pas je voyais plus rien dans les réponses, bref je crois que c'est bon,
alors ce rapport?
alors ce rapport?
¤¤¤¤¤¤¤¤¤¤ Kill_Rtk By g3n-h@ckm@n ¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤ Rootkit ¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤ Services :
¤¤¤¤¤ Files :
¤ File deleted !! : C:\Windows\System32\Drivers\jtnmf.sys
¤¤¤¤¤ Keys | Root
¤ Key deleted !! : HKLM\System\CurrentControlSet\Enum\Root\LEGACY_jtnmf
¤ Key deleted !! : HKLM\System\ControlSet003\Enum\Root\LEGACY_jtnmf
¤¤¤¤¤ Keys | Services
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤ Rootkit ¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤ Services :
¤¤¤¤¤ Files :
¤ File deleted !! : C:\Windows\System32\Drivers\jtnmf.sys
¤¤¤¤¤ Keys | Root
¤ Key deleted !! : HKLM\System\CurrentControlSet\Enum\Root\LEGACY_jtnmf
¤ Key deleted !! : HKLM\System\ControlSet003\Enum\Root\LEGACY_jtnmf
¤¤¤¤¤ Keys | Services