cjoint

Publicité


Publicité

Format du document : text/x-log

Prévisualisation

RogueKiller V10.5.7.0 (x64) [Mar 22 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 8.1 (6.3.9200 ) 64 bits version
Démarré en : Mode normal
Utilisateur : Manon [Administrateur]
Démarré depuis : C:\Users\Manon\Downloads\RogueKillerX64.exe
Mode : Scan -- Date : 03/25/2015 21:13:17

¤¤¤ Processus : 3 ¤¤¤
[Suspicious.Path] BitTorrent.exe(4700) -- C:\Users\Manon\AppData\Roaming\BitTorrent\BitTorrent.exe[7] -> Tué(e) [TermProc]
[Suspicious.Path] setup.exe(2164) -- C:\Users\Manon\AppData\Local\Installer\Install_27421\setup.exe[x] -> Tué(e) [TermProc]
[Suspicious.Path] OPERAT~1.EXE(13160) -- C:\Users\Manon\AppData\Roaming\OPERAT~1.EXE[x] -> Tué(e) [TermProc]

¤¤¤ Registre : 8 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3491266530-455972535-2292282241-1002\Software\Microsoft\Windows\CurrentVersion\Run | BitTorrent : "C:\Users\Manon\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED -> Trouvé(e)
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3491266530-455972535-2292282241-1002\Software\Microsoft\Windows\CurrentVersion\Run | BitTorrent : "C:\Users\Manon\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3491266530-455972535-2292282241-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://asus13.msn.com -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3491266530-455972535-2292282241-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://asus13.msn.com -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Trouvé(e)

¤¤¤ Tâches : 1 ¤¤¤
[Suspicious.Path] \\Installer_delay -- C:\Users\Manon\AppData\Local\Installer\Install_27421\setup.exe (/S /SCHEDULE /MAG=smtyc /pn=delay /pixGuid=72060631-5D5A-4D37-9FAF-DDF813B131B5) -> Trouvé(e)

¤¤¤ Fichiers : 1 ¤¤¤
[Suspicious.Path][Fichier] WindowsProviderWizard.lnk -- C:\Users\Manon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsProviderWizard.lnk [LNK@] C:\Users\Manon\AppData\Roaming\WindowsProviderWizard.exe -> Trouvé(e)

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: HGST HTS541010A9E680 +++++
--- User ---
[MBR] d2a9ace879a208bb2ec61f2ee87d0b74
[BSP] 6851fe151f1518935f4f5a061e01cdb9 : Empty MBR Code
Partition table:
0 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 100 MB
1 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 206848 | Size: 900 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 2050048 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 2312192 | Size: 381096 MB
4 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 782796800 | Size: 450 MB
5 - Basic data partition | Offset (sectors): 783718400 | Size: 550704 MB
6 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1911560192 | Size: 20490 MB
User = LL1 ... OK
User = LL2 ... OK


Publicité


Signaler le contenu de ce document

Publicité