cjoint

Publicité


Publicité

Format du document : text/x-log

Prévisualisation

RogueKiller V10.5.1.0 [Mar 5 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Démarré en : Mode normal
Utilisateur : Emixam [Administrateur]
Démarré depuis : C:\Users\Emixam\Downloads\RogueKiller.exe
Mode : Scan -- Date : 03/08/2015 11:51:55

¤¤¤ Processus : 3 ¤¤¤
[Tr.Zeus] mbamservice.exe(2336) -- D:\Malwarebytes Anti-Malware\mbamservice.exe[7] -> Tué(e) [TermProc]
[Suspicious.Path] vs_ultimate.exe(4144) -- C:\ProgramData\Package Cache\{34d5e430-78c9-4fbf-af41-9fd56b21c111}\vs_ultimate.exe[7] -> Tué(e) [TermProc]
[Suspicious.Path] vs_ultimate.exe(4372) -- C:\ProgramData\Package Cache\{34d5e430-78c9-4fbf-af41-9fd56b21c111}\vs_ultimate.exe[7] -> Tué(e) [TermProc]

¤¤¤ Registre : 9 ¤¤¤
[Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce | {34d5e430-78c9-4fbf-af41-9fd56b21c111} : "C:\ProgramData\Package Cache\{34d5e430-78c9-4fbf-af41-9fd56b21c111}\vs_ultimate.exe" /burn.log.append "C:\Users\Emixam\AppData\Local\Temp\dd_vs_ultimate_20150307174724.log" /burn.runonce -> Trouvé(e)
[Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce | Malwarebytes Anti-Malware (cleanup) : "C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe" "C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware" -> Trouvé(e)
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rndohkq (System32\drivers\urahvnu.sys) -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3935834411-1407586616-2159970557-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://asus.msn.com -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3935834411-1407586616-2159970557-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://asus.msn.com -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Trouvé(e)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 21 (Driver: Non chargé [0xc000036b]) ¤¤¤
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrLoadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d4d0 (jmp 0x7231d2d8)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrUnloadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d5f0 (jmp 0x7231d1f4)
[IAT:Inl(Hook.IEAT)] (chrome.exe) aswCmnBS.dll - usnCloseTracker : D:\AVASTA~1\aswCmnOS.dll @ 0x73d13eb0 (jmp dword near [0x73e205c0])
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrLoadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d4d0 (jmp 0x715ad2d8)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrUnloadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d5f0 (jmp 0x715ad1f4)
[IAT:Inl(Hook.IEAT)] (chrome.exe) aswCmnBS.dll - usnCloseTracker : D:\AVASTA~1\aswCmnOS.dll @ 0x73d13eb0 (jmp dword near [0x73e205c0])
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrLoadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d4d0 (jmp 0x71a8d2d8)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrUnloadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d5f0 (jmp 0x71a8d1f4)
[IAT:Inl(Hook.IEAT)] (chrome.exe) aswCmnBS.dll - usnCloseTracker : D:\AVASTA~1\aswCmnOS.dll @ 0x73d13eb0 (jmp dword near [0x73e205c0])
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrLoadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d4d0 (jmp 0x716ad2d8)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrUnloadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d5f0 (jmp 0x716ad1f4)
[IAT:Inl(Hook.IEAT)] (chrome.exe) aswCmnBS.dll - usnCloseTracker : D:\AVASTA~1\aswCmnOS.dll @ 0x73d13eb0 (jmp dword near [0x73e205c0])
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrLoadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d4d0 (jmp 0x7178d2d8)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrUnloadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d5f0 (jmp 0x7178d1f4)
[IAT:Inl(Hook.IEAT)] (chrome.exe) aswCmnBS.dll - usnCloseTracker : D:\AVASTA~1\aswCmnOS.dll @ 0x73d13eb0 (jmp dword near [0x73e205c0])
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrLoadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d4d0 (jmp 0x71b9d2d8)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrUnloadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d5f0 (jmp 0x71b9d1f4)
[IAT:Inl(Hook.IEAT)] (chrome.exe) aswCmnBS.dll - usnCloseTracker : D:\AVASTA~1\aswCmnOS.dll @ 0x73d13eb0 (jmp dword near [0x73e205c0])
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrLoadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d4d0 (jmp 0x720fd2d8)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - LdrUnloadDll : D:\Avast Antivirus\snxhk.dll @ 0x7234d5f0 (jmp 0x720fd1f4)
[IAT:Inl(Hook.IEAT)] (chrome.exe) aswCmnBS.dll - usnCloseTracker : D:\AVASTA~1\aswCmnOS.dll @ 0x73d13eb0 (jmp dword near [0x73e205c0])

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS545050A7E380 +++++
--- User ---
[MBR] eaa284202aa95d7fc9fde9b78de48f7e
[BSP] 6038da5abdb86a32e945c2c6aa172f56 : Windows Vista/7/8 MBR Code
Partition table:
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: Samsung M3 Portable USB Device +++++
--- User ---
[MBR] 59f72cf49849636072294033c5950bda
[BSP] 8da2f4969ed28a25203a872eb5a92278 : Windows XP MBR Code
Partition table:
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )


Publicité


Signaler le contenu de ce document

Publicité