cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

ÿþRogueKiller V12.3.0.0 (x64) [May 22 2016] (Gratuit) par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 8.1 (6.3.9600) 64 bits version
Démarré en : Mode normal
Utilisateur : ayoub-pc [Administrateur]
Démarré depuis : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 05/27/2016 16:29:18

¤¤¤ Processus : 0 ¤¤¤

¤¤¤ Registre : 22 ¤¤¤
[PUP] (X64) HKEY_LOCAL_MACHINE\Software\InstalledBrowserExtensions -> Trouvé(e)
[PUP] (X64) HKEY_LOCAL_MACHINE\Software\Tarma Installer -> Trouvé(e)
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Conduit -> Trouvé(e)
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\GlobalUpdate -> Trouvé(e)
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\InstallCore -> Trouvé(e)
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\InstalledBrowserExtensions -> Trouvé(e)
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\PIP -> Trouvé(e)
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\SmdmF -> Trouvé(e)
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Super Radio -> Trouvé(e)
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\SweetIM -> Trouvé(e)
[PUP] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7} -> Trouvé(e)
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-2989162816-207459483-2485748632-1001\Software\Microsoft\Windows\CurrentVersion\Run | FrappsyPlayer : "C:\Users\ayoub-pc\AppData\Local\Frappsy\FrappsyPlayer\FrappsyPlayer.exe" /hide [-][x] -> Trouvé(e)
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-2989162816-207459483-2485748632-1001\Software\Microsoft\Windows\CurrentVersion\Run | FrappsyPlayer : "C:\Users\ayoub-pc\AppData\Local\Frappsy\FrappsyPlayer\FrappsyPlayer.exe" /hide [-][x] -> Trouvé(e)
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /svc) -> Trouvé(e)
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /medsvc) -> Trouvé(e)
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /svc) -> Trouvé(e)
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /medsvc) -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2989162816-207459483-2485748632-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://en-maktoob.yahoo.com/?fr=vmn&type=vmn__webcompa__1_0__ya__hp_WCYID10195_swoc_campaign_151119__yaie -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2989162816-207459483-2485748632-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://en-maktoob.yahoo.com/?fr=vmn&type=vmn__webcompa__1_0__ya__hp_WCYID10195_swoc_campaign_151119__yaie -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2989162816-207459483-2485748632-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung13.msn.com -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2989162816-207459483-2485748632-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung13.msn.com -> Trouvé(e)
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-2989162816-207459483-2485748632-1001\Control Panel\Desktop | SCRNSAVE.EXE : C:\WINDOWS\Screen_Samsung.scr [-] -> Trouvé(e)

¤¤¤ Tâches : 2 ¤¤¤
[Suspicious.Path] \Funmoods -- C:\Users\ayoub-pc\AppData\Roaming\Funmoods\UpdateProc\UpdateTask.exe (/Check) -> Trouvé(e)
[Suspicious.Path] \SUPatchForW10Up -- "%programdata%\Samsung\SamsungUpdatePatch\SUPatchForW10Up.exe" -> Trouvé(e)

¤¤¤ Fichiers : 2 ¤¤¤
[PUP][Répertoire] C:\Users\ayoub-pc\AppData\Roaming\OpenCandy -> Trouvé(e)
[PUP][Répertoire] C:\Users\ayoub-pc\AppData\Local\Pokki -> Trouvé(e)

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤

¤¤¤ Navigateurs web : 3 ¤¤¤
[PUP][CHROME:Addon] Default : Funmoods Chat [bbjciahceamgodcoidkjpchnokgfpphh] -> Trouvé(e)
[PUP][CHROME:Addon] Default : Funmoods [cjpglkicenollcignonpgiafdgfeehoj] -> Trouvé(e)
[PUP][CHROME:Addon] Default : Web Navigation [lkemddiljapcmhicklfpcbpfffahfbja] -> Trouvé(e)

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: ST500LM012 HN-M500MBB +++++
--- User ---
[MBR] dff2154c075a50bd3d891a2067205f1b
[BSP] 237f1459112b0d8ced71c5a12380c2ed : Empty|VT.Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 500 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 1026048 | Size: 300 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1640448 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 1902592 | Size: 451484 MB
4 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 926543872 | Size: 349 MB
5 - [SYSTEM] Basic data partition | Offset (sectors): 927258625 | Size: 23153 MB
6 - [SYSTEM] Basic data partition | Offset (sectors): 974675969 | Size: 1024 MB
User = LL1 ... OK
User = LL2 ... OK


Publicité


Signaler le contenu de ce document

Publicité