cjoint

Publicité


Publicité

Format du document : application/octet-stream

Prévisualisation

RogueKiller V10.8.0.0 [Jun 1 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 8.1 (6.3.9200 ) 64 bits version
Démarré en : Mode normal
Utilisateur : Benjamin [Administrateur]
Démarré depuis : F:\RogueKiller.exe
Mode : Suppression -- Date : 06/13/2015 09:23:16

¤¤¤ Processus : 1 ¤¤¤
[Suspicious.Path] hnseC14B.tmp(2484) -- C:\Users\Benjamin\AppData\Roaming\34444335-1432637186-5737-4C30-3863BBA43501\hnseC14B.tmp[-] -> Tué(e) [TermProc]

¤¤¤ Registre : 12 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mulikety (C:\Users\Benjamin\AppData\Roaming\34444335-1432637186-5737-4C30-3863BBA43501\hnseC14B.tmp) -> Supprimé(e)
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mulikety (C:\Users\Benjamin\AppData\Roaming\34444335-1432637186-5737-4C30-3863BBA43501\hnseC14B.tmp) -> Supprimé(e)
[PUM.HomePage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://hp13.msn.com -> Remplacé(e) (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
[PUM.HomePage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://hp13.msn.com -> Remplacé(e) (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://hp13.msn.com -> Remplacé(e) (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://hp13.msn.com -> Remplacé(e) (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://hp13.msn.com -> Remplacé(e) (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://hp13.msn.com -> Remplacé(e) (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E8259A57-340F-4EE5-8062-A4A372B4114D} | DhcpNameServer : 172.20.10.1 [(Private Address) (XX)] -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{EDB5CD9C-BEF6-482B-9E3E-6CFC17705E56} | DhcpNameServer : 40.23.1.201 40.23.1.202 [UNITED STATES (US)][UNITED STATES (US)] -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{E8259A57-340F-4EE5-8062-A4A372B4114D} | DhcpNameServer : 172.20.10.1 [(Private Address) (XX)] -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{EDB5CD9C-BEF6-482B-9E3E-6CFC17705E56} | DhcpNameServer : 40.23.1.201 40.23.1.202 [UNITED STATES (US)][UNITED STATES (US)] -> Remplacé(e) ()

¤¤¤ Tâches : 2 ¤¤¤
[Suspicious.Path] ALKFYECZ1.job -- C:\ProgramData\LolliScan\LolliScan.exe -> Supprimé(e)
[Suspicious.Path] \\ALKFYECZ1 -- C:\ProgramData\LolliScan\LolliScan.exe -> Supprimé(e)

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Non chargé [0xc000036b]) ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABD075 +++++
--- User ---
[MBR] dd9cdefeef8145f5944f84a415e58541
[BSP] 41854b723c365339391f3a9184162681 : Empty MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 650 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 1333248 | Size: 260 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1865728 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 2127872 | Size: 689708 MB
4 - [SYSTEM] Basic data partition | Offset (sectors): 1414649856 | Size: 24652 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: SanDisk Cruzer Slice USB Device +++++
--- User ---
[MBR] 885b0e5cef8174a8e60aa9313ab2c9fa
[BSP] 3ec8d7f36fe72d0e3a655a0c49f879ce : Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 16128 | Size: 15259 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )


============================================
RKreport_SCN_06132015_092248.log

Publicité


Signaler le contenu de ce document

Publicité