cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

RogueKiller V10.9.1.0 (x64) [Jul 9 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7600 ) 64 bits version
Démarré en : Mode normal
Utilisateur : TWINS [Administrateur]
Démarré depuis : C:\Users\TWINS\Desktop\RogueKillerX64.exe
Mode : Suppression -- Date : 07/14/2015 16:29:41

¤¤¤ Processus : 0 ¤¤¤

¤¤¤ Registre : 14 ¤¤¤
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} -> Supprimé(e)
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | vProt : "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe" -> Supprimé(e)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-960387390-1940335497-2698470163-1000\Software\Microsoft\Internet Explorer\Main | Start Page : https://mysearch.avg.com/?cid={45CE4901-93CE-4385-A4FA-A6AC9B534D53}&mid=84f98f4b1f6a47d0a39435581dcaa37c-82fac28ad201cd710aa53beed47215041b0881ce&lang=fr&ds=AVG&coid=avgtbavg&cmpid=0615pit&pr=fr&d=2015-07-12 18:05:49&v=4.1.4.948&pid=wtu&sg=&sap=hp -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-960387390-1940335497-2698470163-1000\Software\Microsoft\Internet Explorer\Main | Start Page : https://mysearch.avg.com/?cid={45CE4901-93CE-4385-A4FA-A6AC9B534D53}&mid=84f98f4b1f6a47d0a39435581dcaa37c-82fac28ad201cd710aa53beed47215041b0881ce&lang=fr&ds=AVG&coid=avgtbavg&cmpid=0615pit&pr=fr&d=2015-07-12 18:05:49&v=4.1.4.948&pid=wtu&sg=&sap=hp -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{206775AE-A62A-4A69-A88F-11471EF12CAB} | DhcpNameServer : 0.0.0.0 ([(Private Address) (XX)]) -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5B74962C-E035-401C-BFE9-00DF1440BE89} | DhcpNameServer : 0.0.0.0 ([(Private Address) (XX)]) -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{206775AE-A62A-4A69-A88F-11471EF12CAB} | DhcpNameServer : 0.0.0.0 ([(Private Address) (XX)]) -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{5B74962C-E035-401C-BFE9-00DF1440BE89} | DhcpNameServer : 0.0.0.0 ([(Private Address) (XX)]) -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{206775AE-A62A-4A69-A88F-11471EF12CAB} | DhcpNameServer : 0.0.0.0 ([(Private Address) (XX)]) -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{5B74962C-E035-401C-BFE9-00DF1440BE89} | DhcpNameServer : 0.0.0.0 ([(Private Address) (XX)]) -> Remplacé(e) ()
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-960387390-1940335497-2698470163-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | disabletaskmgr : 1 -> Supprimé(e)
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-960387390-1940335497-2698470163-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | disabletaskmgr : 1 -> ERROR [2]
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Remplacé(e) (2)
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Remplacé(e) (2)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 3 (Driver: Chargé) ¤¤¤
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ USER32.dll) ntdll.dll - NlsAnsiCodePage : Unknown @ 0x7a493f19 (call 0x3003f09)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ USER32.dll) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xfffffffffa493f19 (call 0x83003f09)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ USER32.dll) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xcb493f19 (call 0x54003f09)

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: ST9500420AS +++++
--- User ---
[MBR] c0f62bdc619eb69c3fba65267c255fd4
[BSP] 9fccc9f94b3272c58d93673002fd2a7b : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 156109 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 319918080 | Size: 156266 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 639950848 | Size: 164464 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK


Publicité


Signaler le contenu de ce document

Publicité