cjoint

Publicité


Publicité

Format du document : application/octet-stream

Prévisualisation

RogueKiller V10.8.1.0 [Jun 3 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Démarré en : Mode normal
Utilisateur : Anaïs [Administrateur]
Démarré depuis : C:\Users\Anaïs\Desktop\RogueKiller.exe
Mode : Scan -- Date : 06/05/2015 21:18:31

¤¤¤ Processus : 0 ¤¤¤

¤¤¤ Registre : 11 ¤¤¤
[PUM.HomePage] HKEY_USERS\S-1-5-21-1667155602-786327165-4248829186-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.search.ask.com/?l=dis&o=APN10113&gct=hp -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 190.55.60.129 181.47.248.145 200.115.192.28 [-][(Unknown Country?) (XX)][ARGENTINA (AR)] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 190.55.60.129 181.47.248.145 200.115.192.28 [-][(Unknown Country?) (XX)][X] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 190.55.60.129 181.47.248.145 200.115.192.28 [-][(Unknown Country?) (XX)][ARGENTINA (AR)] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0148E811-4BB3-4189-AE93-AEB5DC0C0DFC} | DhcpNameServer : 10.11.0.1 [(Private Address) (XX)] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E031BA64-8B39-4B45-AEDA-0EE0D6BE180C} | DhcpNameServer : 190.55.60.129 181.47.248.145 200.115.192.28 [-][(Unknown Country?) (XX)][ARGENTINA (AR)] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{0148E811-4BB3-4189-AE93-AEB5DC0C0DFC} | DhcpNameServer : 10.11.0.1 [(Private Address) (XX)] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{E031BA64-8B39-4B45-AEDA-0EE0D6BE180C} | DhcpNameServer : 190.55.60.129 181.47.248.145 200.115.192.28 [-][(Unknown Country?) (XX)][ARGENTINA (AR)] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{0148E811-4BB3-4189-AE93-AEB5DC0C0DFC} | DhcpNameServer : 10.11.0.1 [(Private Address) (XX)] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{E031BA64-8B39-4B45-AEDA-0EE0D6BE180C} | DhcpNameServer : 190.55.60.129 181.47.248.145 200.115.192.28 [-][(Unknown Country?) (XX)][ARGENTINA (AR)] -> Trouvé(e)
[PUM.StartMenu] HKEY_USERS\S-1-5-21-1667155602-786327165-4248829186-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Trouvé(e)

¤¤¤ Tâches : 3 ¤¤¤
[Suspicious.Path] \\DealPly -- C:\Users\ANAS~1\AppData\Roaming\DealPly\UPDATE~1\UPDATE~1.EXE (/Check) -> Trouvé(e)
[Suspicious.Path] \\Funmoods -- C:\Users\ANAS~1\AppData\Roaming\Funmoods\UPDATE~1\UPDATE~1.EXE (/Check) -> Trouvé(e)
[Suspicious.Path] \\VisualBeeRecovery -- C:\Users\Anaïs\AppData\Local\VisualBeeExe\VisualBeeRecovery.exe (/s) -> Trouvé(e)

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤

¤¤¤ Navigateurs web : 1 ¤¤¤
[PUP][FIREFX:Addon] pwkd5uc7.default : DealPly [{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}] -> Trouvé(e)

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MK3256GSY +++++
--- User ---
[MBR] 7c30a7022b10b996e3221de642295d79
[BSP] 977f01a32e32af36642d389726686d4c : HP|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 81920 | Size: 15000 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 30801920 | Size: 290204 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK


Publicité


Signaler le contenu de ce document

Publicité