cjoint

Publicité


Publicité

Format du document : text/x-log

Prévisualisation

RogueKiller V10.5.7.0 [Mar 22 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : michael&laurence [Administrator]
Started from : C:\Users\michael&laurence\Downloads\RogueKiller.exe
Mode : Scan -- Date : 03/28/2015 11:03:54

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 16 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-728640682-1901507235-1574901044-1000\Software\Microsoft\Windows\CurrentVersion\Run | Google+ Auto Backup : "C:\Users\michael&laurence\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart -> Found
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-728640682-1901507235-1574901044-1000\Software\Microsoft\Windows\CurrentVersion\Run | Google+ Auto Backup : "C:\Users\michael&laurence\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart -> Found
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-728640682-1901507235-1574901044-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce | Uninstall C:\Users\michael&laurence\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64 : C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\michael&laurence\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64" -> Found
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-728640682-1901507235-1574901044-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce | Uninstall C:\Users\michael&laurence\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910 : C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\michael&laurence\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910" -> Found
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-728640682-1901507235-1574901044-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce | Uninstall C:\Users\michael&laurence\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64 : C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\michael&laurence\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64" -> Found
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-728640682-1901507235-1574901044-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce | Uninstall C:\Users\michael&laurence\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910 : C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\michael&laurence\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910" -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 109.88.203.3 62.197.111.140 [(Unknown Country?) (XX)][BELGIUM (BE)] -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 109.88.203.3 62.197.111.140 [(Unknown Country?) (XX)][BELGIUM (BE)] -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 109.88.203.3 62.197.111.140 [(Unknown Country?) (XX)][BELGIUM (BE)] -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B304ACD6-D11C-402D-B8E2-23C083CFEB15} | DhcpNameServer : 109.88.203.3 62.197.111.140 [(Unknown Country?) (XX)][BELGIUM (BE)] -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{B304ACD6-D11C-402D-B8E2-23C083CFEB15} | DhcpNameServer : 109.88.203.3 62.197.111.140 [(Unknown Country?) (XX)][BELGIUM (BE)] -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{B304ACD6-D11C-402D-B8E2-23C083CFEB15} | DhcpNameServer : 109.88.203.3 62.197.111.140 [(Unknown Country?) (XX)][BELGIUM (BE)] -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Found

¤¤¤ Tasks : 1 ¤¤¤
[Suspicious.Path] \Microsoft\Windows\Media Center\PeriodicScanRetry -- %windir%\ehome\MCUpdate.exe (-pscn 0) -> Found

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD6400BEVT-22A0RT0 +++++
--- User ---
[MBR] d0aa3cb7df06ca7238409a65c56685ed
[BSP] 9f03bc15cd3ff7242c1a5eae66116899 : Windows Vista/7/8 MBR Code
Partition table:
User = LL1 ... OK
User = LL2 ... OK


Publicité


Signaler le contenu de ce document

Publicité