cjoint

Publicité


Publicité

Format du document : text/x-log

Prévisualisation

RogueKiller V10.6.3.0 (x64) [May 11 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Démarré en : Mode normal
Utilisateur : Katia [Administrateur]
Démarré depuis : C:\Users\Katia\Desktop\RogueKillerX64.exe
Mode : Scan -- Date : 05/16/2015 16:54:53

¤¤¤ Processus : 4 ¤¤¤
[Suspicious.Path|VT.Unknown] cvxasync.exe(4024) -- C:\ProgramData\nvxasync\cvxasync.exe[-] -> Tué(e) [TermProc]
[Suspicious.Path|VT.Unknown] nvxasync.exe(1100) -- C:\Users\Katia\AppData\Roaming\nvxasync\nvxasync.exe[-] -> Tué(e) [TermProc]
[Suspicious.Path] BitTorrent.exe(4260) -- C:\Users\Katia\AppData\Roaming\BitTorrent\BitTorrent.exe[7]VT(1) -> Tué(e) [TermProc]
[Suspicious.Path|VT.Unknown] nvxasync.exe(4520) -- C:\Users\Katia\AppData\Roaming\nvxasync\nvxasync.exe[-] -> Tué(e) [TermProc]

¤¤¤ Registre : 19 ¤¤¤
[Orphan] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -> Trouvé(e)
[Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -> Trouvé(e)
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-807251443-3844359417-4129039656-1000\Software\Microsoft\Windows\CurrentVersion\Run | BitTorrent : "C:\Users\Katia\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED [7][x] -> Trouvé(e)
[Suspicious.Path|VT.Unknown] (X64) HKEY_USERS\S-1-5-21-807251443-3844359417-4129039656-1000\Software\Microsoft\Windows\CurrentVersion\Run | nvxasync : C:\Users\Katia\AppData\Roaming\nvxasync\nvxasync.exe [-] -> Trouvé(e)
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-807251443-3844359417-4129039656-1000\Software\Microsoft\Windows\CurrentVersion\Run | BitTorrent : "C:\Users\Katia\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED [7][x] -> Trouvé(e)
[Suspicious.Path|VT.Unknown] (X86) HKEY_USERS\S-1-5-21-807251443-3844359417-4129039656-1000\Software\Microsoft\Windows\CurrentVersion\Run | nvxasync : C:\Users\Katia\AppData\Roaming\nvxasync\nvxasync.exe [-] -> Trouvé(e)
[Suspicious.Path|VT.Unknown] (X64) HKEY_USERS\S-1-5-21-807251443-3844359417-4129039656-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell : C:\ProgramData\nvxasync\cvxasync.exe [-] -> Trouvé(e)
[Suspicious.Path|VT.Unknown] (X86) HKEY_USERS\S-1-5-21-807251443-3844359417-4129039656-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell : C:\ProgramData\nvxasync\cvxasync.exe [-] -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-807251443-3844359417-4129039656-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.surfvox.com/ -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-807251443-3844359417-4129039656-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.surfvox.com/ -> Trouvé(e)
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Trouvé(e)
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-807251443-3844359417-4129039656-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Trouvé(e)
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-807251443-3844359417-4129039656-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Trouvé(e)
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-807251443-3844359417-4129039656-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Trouvé(e)
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-807251443-3844359417-4129039656-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Trouvé(e)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] 6e0caf5bc98fff7ecd6c90b5b93afd96
[BSP] a5bc7ed7915632cf36d37ae0db611e44 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 953867 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: KINGSTON SMS200S3120G +++++
--- User ---
[MBR] 7ff619790286dbf16d3fb2c78355c737
[BSP] 3d6149674c51f92d3702657868d96a22 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 350 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 718848 | Size: 114121 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK


Publicité


Signaler le contenu de ce document

Publicité