cjoint

Publicité


Publicité

Format du document : application/octet-stream

Prévisualisation

RogueKiller V9.2.1.0 [Jun 23 2014] par Adlice Software
Mail : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site Web : http://www.surlatoile.org/RogueKiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7600 ) 32 bits version
Démarrage : Mode normal
Utilisateur : Bernard [Droits d'admin]
Mode : Suppression -- Date : 08/18/2015 15:27:10

¤¤¤ Processus malicieux : 3 ¤¤¤
[Suspicious.Path] explorer.exe -- C:\Users\Bernard\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll[7] -> DECHARGÉE
[Suspicious.Path] explorer.exe -- C:\Users\Bernard\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\Telemetry.dll[7] -> DECHARGÉE
[Suspicious.Path] explorer.exe -- C:\Users\Bernard\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\LoggingPlatform.DLL[7] -> DECHARGÉE

¤¤¤ Entrées de registre : 18 ¤¤¤
[Suspicious.Path] HKEY_USERS\S-1-5-21-2525338459-2630905149-3183968354-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce | Uninstall C:\Users\Bernard\AppData\Local\Microsoft\OneDrive\17.3.4604.0120 : C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Bernard\AppData\Local\Microsoft\OneDrive\17.3.4604.0120" [x] -> SUPPRIMÉ
[PUM.Proxy] HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> REMPLACÉ (0)
[PUM.Proxy] HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> REMPLACÉ (0)
[PUM.Proxy] HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:49178;https=127.0.0.1:49178 -> SUPPRIMÉ
[PUM.Proxy] HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:49178;https=127.0.0.1:49178 -> ERROR [2]
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 24.200.241.37 24.202.72.13 24.200.0.1 -> REMPLACÉ ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 24.200.241.37 24.202.72.13 24.200.0.1 -> REMPLACÉ ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 24.200.241.37 24.202.72.13 24.200.0.1 -> REMPLACÉ ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{42DB4F39-E7DA-46D2-88E3-C3BD755E213B} | DhcpNameServer : 24.200.241.37 24.202.72.13 24.200.0.1 -> REMPLACÉ ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{CCC8D4C8-F12A-4540-B558-B4E24AD1CBD3} | DhcpNameServer : 10.188.15.20 172.21.100.3 -> REMPLACÉ ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{42DB4F39-E7DA-46D2-88E3-C3BD755E213B} | DhcpNameServer : 24.200.241.37 24.202.72.13 24.200.0.1 -> REMPLACÉ ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{CCC8D4C8-F12A-4540-B558-B4E24AD1CBD3} | DhcpNameServer : 10.188.15.20 172.21.100.3 -> REMPLACÉ ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{42DB4F39-E7DA-46D2-88E3-C3BD755E213B} | DhcpNameServer : 24.200.241.37 24.202.72.13 24.200.0.1 -> REMPLACÉ ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{CCC8D4C8-F12A-4540-B558-B4E24AD1CBD3} | DhcpNameServer : 10.188.15.20 172.21.100.3 -> REMPLACÉ ()
[PUM.Policies] HKEY_USERS\S-1-5-21-2525338459-2630905149-3183968354-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | disableregistrytools : 0 -> SUPPRIMÉ
[PUM.Policies] HKEY_USERS\S-1-5-21-2525338459-2630905149-3183968354-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> SUPPRIMÉ
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> REMPLACÉ (0)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> REMPLACÉ (0)

¤¤¤ Tâches planifiées : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: CHARGE) ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ MBR Verif : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA DT01ACA100 ATA Device +++++
--- User ---
[MBR] 64e1b4d028fac4ae5fea8306fda5dc3c
[BSP] b1aa91f5575e23fd3f372142eb70fbb0 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 953767 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_DEL_03152015_113016.log - RKreport_DEL_06302015_121236.log - RKreport_DEL_08162015_115129.log - RKreport_SCN_03152015_112746.log
RKreport_SCN_06302015_120909.log - RKreport_SCN_08162015_114515.log - RKreport_SCN_08182015_152516.log

Publicité


Signaler le contenu de ce document

Publicité