cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

RogueKiller V10.11.2.0 (x64) [Oct 20 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.10240) 64 bits version
Started in : Normal mode
User : Dr Afif [Administrator]
Started from : C:\Users\Dr Afif\Downloads\RogueKillerX64.exe
Mode : Delete -- Date : 10/25/2015 01:49:42

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 11 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ IDM Shell Extension | (default) : {CDC95B92-E27C-4745-A8C5-64A52A78855D} [x] -> Deleted
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8} -> Deleted
[Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8} -> Deleted
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-867048366-947366980-3932137788-1000\Software\Microsoft\Windows\CurrentVersion\Run | IDMan : C:\Windows.old\Users\Dr Afif\AppData\Local\Temp\Rar$EXb0.300\IDMan.exe /onboot [-][x] -> Deleted
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-867048366-947366980-3932137788-1000\Software\Microsoft\Windows\CurrentVersion\Run | IDMan : C:\Windows.old\Users\Dr Afif\AppData\Local\Temp\Rar$EXb0.300\IDMan.exe /onboot [-][x] -> ERROR [2]
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.oursurfing.com/?type=hp&ts=1442938002&z=c6234d67faa6aeb5b87af8fg5zfzbo2t9cbb7eee7o&from=amt&uid=toshibaxmq01abf050_z3jhc596txxz3jhc596t -> Replaced (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://www.oursurfing.com/?type=hp&ts=1442938002&z=c6234d67faa6aeb5b87af8fg5zfzbo2t9cbb7eee7o&from=amt&uid=toshibaxmq01abf050_z3jhc596txxz3jhc596t -> Replaced (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
[PUM.SearchPage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.oursurfing.com/web/?type=ds&ts=1442938002&z=c6234d67faa6aeb5b87af8fg5zfzbo2t9cbb7eee7o&from=amt&uid=toshibaxmq01abf050_z3jhc596txxz3jhc596t&q={searchTerms} -> Replaced (http://go.microsoft.com/fwlink/?LinkId=54896)
[PUM.SearchPage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Search_URL : http://www.oursurfing.com/web/?type=ds&ts=1442938002&z=c6234d67faa6aeb5b87af8fg5zfzbo2t9cbb7eee7o&from=amt&uid=toshibaxmq01abf050_z3jhc596txxz3jhc596t&q={searchTerms} -> Replaced (http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{c754cfd5-8450-488b-a56f-a472a985c581} | NameServer : 62.240.110.198,62.240.110.197 ([X][X]) -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{c754cfd5-8450-488b-a56f-a472a985c581} | NameServer : 62.240.110.198,62.240.110.197 ([X][X]) -> Replaced ()

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 1 (Driver: Loaded) ¤¤¤
[IAT:Addr(Hook.IEAT)] (explorer.exe @ rpcrt4.dll) ntdll!NtAlpcConnectPortEx : C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\prremote.dll @ 0x732b64f0

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABF050 +++++
--- User ---
[MBR] 17e4fcb924ad65b8365502d31f715ba3
[BSP] fc33180834f6f3ab6c118703fef42330 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 99998 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 204800000 | Size: 185000 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 583680000 | Size: 191939 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: Multiple Card Reader USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive2: ZTE MMC Storage USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )


Publicité


Signaler le contenu de ce document

Publicité