cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

RogueKiller V10.9.4.0 [Jul 30 2015] (H'37) (1F'E, Adlice
'D(1J/ 'D%DC*1HFJ : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
'DEHB9 : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

F8'E 'D*4:JD : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
J(/# AJ : 'DH69 'D7(J9J
'DE3*./E : salim [E3$HD]
Started from : C:\Users\salim\Desktop\RogueKiller.exe
'DH69 : -0A -- 'DJHE : 08/03/2015 01:50:09

¤¤¤ 'D9EDJ) : 0 ¤¤¤

¤¤¤ 'DE3,D : 6 ¤¤¤
[VT.Unknown] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce | Kaspersky Setup : "C:\Users\salim\Desktop\KIS16.0.0.396fr-FR.exe" /-reboot_restart_async_continue [7][x] -> DE J*E 'D*-/J/
[VT.Unknown] (X64) HKEY_USERS\S-1-5-21-600521514-3379170514-1243366079-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce | Kaspersky Setup : "C:\Users\salim\Desktop\KIS16.0.0.396fr-FR.exe" /-restricted_service [7][x] -> DE J*E 'D*-/J/
[VT.Unknown] (X86) HKEY_USERS\S-1-5-21-600521514-3379170514-1243366079-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce | Kaspersky Setup : "C:\Users\salim\Desktop\KIS16.0.0.396fr-FR.exe" /-restricted_service [7][x] -> DE J*E 'D*-/J/
[Hj.RegVal] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell : C:\Windows\explorer.exe -> %3*(/'D (explorer.exe)
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> DE J*E 'D*-/J/
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> DE J*E 'D*-/J/

¤¤¤ 'DEG'E : 4 ¤¤¤
[Suspicious.Path] %WINDIR%\Tasks\FacebookUpdateTaskUserS-1-5-21-600521514-3379170514-1243366079-1000UA.job -- C:\Users\salim\AppData\Local\Facebook\Update\FacebookUpdate.exe (/ua /installsource scheduler) -> DE J*E 'D*-/J/
[Suspicious.Path] %WINDIR%\Tasks\GoogleUpdateTaskMachineUA.job -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (/ua /installsource scheduler) -> DE J*E 'D*-/J/
[Suspicious.Path] \FacebookUpdateTaskUserS-1-5-21-600521514-3379170514-1243366079-1000UA -- C:\Users\salim\AppData\Local\Facebook\Update\FacebookUpdate.exe (/ua /installsource scheduler) -> DE J*E 'D*-/J/
[Suspicious.Path] \GoogleUpdateTaskMachineUA -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (/ua /installsource scheduler) -> DE J*E 'D*-/J/

¤¤¤ 'DEDA'* : 0 ¤¤¤

¤¤¤ EDA 'DGH3* : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 178.32.95.1 paypal.com

¤¤¤ Antirootkit : 8 (Driver: DE J*E 'D*-EJD [0xc000036b]) ¤¤¤
[IAT:Inl(Hook.IEAT)] (chrome.exe @ USER32.dll) ntdll.dll - NlsAnsiCodePage : Unknown @ 0x79093f19 (call 0x2003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe @ USER32.dll) ntdll.dll - NlsAnsiCodePage : Unknown @ 0x64093f19 (call 0xed003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe @ USER32.dll) ntdll.dll - NlsAnsiCodePage : Unknown @ 0x7c093f19 (call 0x5003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe @ USER32.dll) ntdll.dll - NlsAnsiCodePage : Unknown @ 0x6d093f19 (call 0xf6003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe @ USER32.dll) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xfffffffffc093f19 (call 0x85003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe @ USER32.dll) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xffffffffe6093f19 (call 0x6f003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe @ USER32.dll) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xffffffff9f093f19 (call 0x28003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe @ USER32.dll) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xfffffffff9093f19 (call 0x82003f09)

¤¤¤ 'DE*5A- : 2 ¤¤¤
[PUM.Proxy][FIREFX:Config] le6kb42v.default : user_pref("network.proxy.http", "12345proxy.net"); -> DE J*E 'D*-/J/
[PUM.Proxy][FIREFX:Config] le6kb42v.default : user_pref("network.proxy.http_port", 80); -> DE J*E 'D*-/J/

¤¤¤ A-5 'D MBR : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MK6459GSXP +++++
--- User ---
[MBR] d975295b1ec12c66e9cab2a1961f9955
[BSP] 50b4de275d388c3c6676493c60ef6fd6 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 11340 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 23226368 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 23431168 | Size: 314484 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
3 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 667496448 | Size: 284553 MB
User = LL1 ... OK
User = LL2 ... OK


Publicité


Signaler le contenu de ce document

Publicité