cjoint

Publicité


Publicité

Format du document : application/octet-stream

Prévisualisation

RogueKiller V10.8.2.0 [Jun 9 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Démarré en : Mode normal
Utilisateur : sg [Administrateur]
Démarré depuis : C:\Users\sg\Desktop\RogueKiller.exe
Mode : Scan -- Date : 06/14/2015 22:03:59

¤¤¤ Processus : 0 ¤¤¤

¤¤¤ Registre : 10 ¤¤¤
[Suspicious.Path|VT.Unknown] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | PPort12reminder : "C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini" [7][x][-] -> Trouvé(e)
[Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | CitrixReceiver : "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk" [x] -> Trouvé(e)
[PUM.HomePage] HKEY_USERS\S-1-5-21-280633692-3265817483-3066732948-1006\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.bluewin.ch/ -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 [-][SWITZERLAND (CH)][-][-] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 [-][SWITZERLAND (CH)][-][-] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 [-][SWITZERLAND (CH)][-][-] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A181CF0E-2F2F-4766-867E-95E9778CC481} | DhcpNameServer : 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 [-][SWITZERLAND (CH)][-][-] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{A181CF0E-2F2F-4766-867E-95E9778CC481} | DhcpNameServer : 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 [-][SWITZERLAND (CH)][-][-] -> Trouvé(e)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{A181CF0E-2F2F-4766-867E-95E9778CC481} | DhcpNameServer : 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 [-][SWITZERLAND (CH)][-][-] -> Trouvé(e)
[PUM.StartMenu] HKEY_USERS\S-1-5-21-280633692-3265817483-3066732948-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Trouvé(e)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 1 ¤¤¤
[Suspicious.Startup|VT.Unknown][Fichier] OneNote 2010 - Capture d’écran et lancement.lnk -- C:\Users\sg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 - Capture d’écran et lancement.lnk -> Trouvé(e)

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 23 (Driver: Chargé) ¤¤¤
[SSDT:Addr(Hook.SSDT)] NtAlertResumeThread[13] : Unknown @ 0x8a7c3960
[SSDT:Addr(Hook.SSDT)] NtAlertThread[14] : Unknown @ 0x8a7c3a40
[SSDT:Addr(Hook.SSDT)] NtAllocateVirtualMemory[19] : Unknown @ 0x8a7c1270
[SSDT:Addr(Hook.SSDT)] ExpInterlockedPopEntrySListResume[59] : Unknown @ 0x8a712490
[SSDT:Addr(Hook.SSDT)] NtCreateMutant[74] : Unknown @ 0x8a7c36b0
[SSDT:Addr(Hook.SSDT)] NtCreateThread[87] : Unknown @ 0x8a70b150
[SSDT:Addr(Hook.SSDT)] NtFreeVirtualMemory[131] : Unknown @ 0x8a7c10d0
[SSDT:Addr(Hook.SSDT)] NtImpersonateAnonymousToken[145] : Unknown @ 0x8a7c37a0
[SSDT:Addr(Hook.SSDT)] NtImpersonateThread[147] : Unknown @ 0x8a7c3880
[SSDT:Addr(Hook.SSDT)] NtMapViewOfSection[168] : Unknown @ 0x8a7c14b0
[SSDT:Addr(Hook.SSDT)] NtOpenEvent[177] : Unknown @ 0x8a7c35d0
[SSDT:Addr(Hook.SSDT)] NtOpenProcessToken[191] : Unknown @ 0x8a6d0238
[SSDT:Addr(Hook.SSDT)] NtOpenThreadToken[199] : Unknown @ 0x8a7c3f18
[SSDT:Addr(Hook.SSDT)] NtResumeThread[304] : Unknown @ 0x8a7a2990
[SSDT:Addr(Hook.SSDT)] NtSetContextThread[316] : Unknown @ 0x8a7c3e38
[SSDT:Addr(Hook.SSDT)] NtSetInformationProcess[333] : Unknown @ 0x8a7c3008
[SSDT:Addr(Hook.SSDT)] NtSetInformationThread[335] : Unknown @ 0x8a7c3d48
[SSDT:Addr(Hook.SSDT)] NtSuspendProcess[366] : Unknown @ 0x8a7c34f0
[SSDT:Addr(Hook.SSDT)] NtSuspendThread[367] : Unknown @ 0x8a7c3b88
[SSDT:Addr(Hook.SSDT)] NtTerminateProcess[370] : Unknown @ 0x8a7d3440
[SSDT:Addr(Hook.SSDT)] NtTerminateThread[371] : Unknown @ 0x8a7c3c68
[SSDT:Addr(Hook.SSDT)] NtUnmapViewOfSection[385] : Unknown @ 0x8a7c13f0
[SSDT:Addr(Hook.SSDT)] NtWriteVirtualMemory[399] : Unknown @ 0x8a7c11a0

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS725025A9A364 +++++
--- User ---
[MBR] 9562048908bbc39599b8ee8f8cba18d4
[BSP] efb05454c4c9c42e87fab3ee1014dc88 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 239 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 489888 | Size: 238235 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK


Publicité


Signaler le contenu de ce document

Publicité