cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

RogueKiller V10.9.3.0 [Jul 21 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Démarré en : Mode normal
Utilisateur : nimbus [Administrateur]
Démarré depuis : C:\Users\nimbus\Downloads\RogueKiller.exe
Mode : Scan -- Date : 07/29/2015 16:36:35

¤¤¤ Processus : 5 ¤¤¤
[VT.RiskWare[WebToolbar:not-a-virus]/Win32.Agent] Upbgbeie.exe(1124) -- C:\Program Files\daugava\Upbgbeie.exe[-] -> Tué(e) [TermProc]
[VT.PUA.Win32.Perion.N] Ejemidvlf.exe(2184) -- C:\Program Files\daugava\Ejemidvlf.exe[-] -> Tué(e) [TermProc]
[VT.Adware.Generic.1294170] csrcc.exe(2568) -- C:\Program Files\daugava\csrcc.exe[-] -> Tué(e) [TermProc]
[VT.PUP.Optional.SweetPacks.A] ExtensionUpdaterService.exe(2872) -- C:\Program Files\IB Updater\ExtensionUpdaterService.exe[-] -> Tué(e) [TermProc]
[PUP|VT.PUP.Optional.Cherimoya.A] (SVC) cherimoya -- system32\drivers\cherimoya.sys[7] -> ERROR [41c]

¤¤¤ Registre : 30 ¤¤¤
[PUP] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087} (C:\Program Files\IB Updater\Extension64.dll) -> Trouvé(e)
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087} (C:\Program Files\IB Updater\Extension64.dll) -> Trouvé(e)
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} -> Trouvé(e)
[PUP] (X86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar | {F9639E4A-801B-4843-AEE3-03D9DA199E77} : Incredibar Toolbar -> Trouvé(e)
[VT.PUA.Win32.Perion.N] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | daugava : C:\Program Files\daugava\Ejemidvlf.exe [-] -> Trouvé(e)
[PUP|VT.PUP.Optional.Cherimoya.A] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cherimoya (system32\drivers\cherimoya.sys) -> Trouvé(e)
[PUP|VT.Adware.Generic.1294170] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\csrcc ("C:\Program Files\daugava\csrcc.exe") -> Trouvé(e)
[PUP|VT.PUP.Optional.SweetPacks.A] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IB Updater (C:\Program Files\IB Updater\ExtensionUpdaterService.exe) -> Trouvé(e)
[PUP|VT.PUP.Optional.Cherimoya.A] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cherimoya (system32\drivers\cherimoya.sys) -> Trouvé(e)
[PUP|VT.Adware.Generic.1294170] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\csrcc ("C:\Program Files\daugava\csrcc.exe") -> Trouvé(e)
[PUP|VT.PUP.Optional.SweetPacks.A] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IB Updater (C:\Program Files\IB Updater\ExtensionUpdaterService.exe) -> Trouvé(e)
[PUP|VT.PUP.Optional.Cherimoya.A] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\cherimoya (system32\drivers\cherimoya.sys) -> Trouvé(e)
[PUP|VT.Adware.Generic.1294170] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\csrcc ("C:\Program Files\daugava\csrcc.exe") -> Trouvé(e)
[PUP|VT.PUP.Optional.SweetPacks.A] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\IB Updater (C:\Program Files\IB Updater\ExtensionUpdaterService.exe) -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-670051216-3045037141-1862671522-1000\Software\Microsoft\Internet Explorer\Main | Start Page : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-670051216-3045037141-1862671522-1000\Software\Microsoft\Internet Explorer\Main | Start Page : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-670051216-3045037141-1862671522-1000\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-670051216-3045037141-1862671522-1000\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.SearchPage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-670051216-3045037141-1862671522-1000\Software\Microsoft\Internet Explorer\Main | Search Page : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-670051216-3045037141-1862671522-1000\Software\Microsoft\Internet Explorer\Main | Search Page : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.SearchPage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Search_URL : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Search_URL : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-670051216-3045037141-1862671522-1000\Software\Microsoft\Internet Explorer\Main | Default_Search_URL : https://safesearch.avira.com/ -> Trouvé(e)
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-670051216-3045037141-1862671522-1000\Software\Microsoft\Internet Explorer\Main | Default_Search_URL : https://safesearch.avira.com/ -> Trouvé(e)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost

¤¤¤ Antirootkit : 0 (Driver: Non chargé [0xc000036b]) ¤¤¤

¤¤¤ Navigateurs web : 2 ¤¤¤
[PUP][FIREFX:Addon] ohhcwaei.default : IB Updater [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}] -> Trouvé(e)
[PUM.HomePage][FIREFX:Config] ohhcwaei.default : user_pref("browser.startup.homepage", "http://www.lemonde.fr/"); -> Trouvé(e)

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD10EZEX-60ZF5A0 +++++
--- User ---
[MBR] b2c462ac324038b451b7d4c9aad7a11b
[BSP] eccb26a397e770a5973037742cf6c8da : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 953767 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK


Publicité


Signaler le contenu de ce document

Publicité