cjoint

Publicité


Publicité

Format du document : application/octet-stream

Prévisualisation

ÿþRogueKiller V12.11.9.0 [Aug 3 2017] (Premium) par Adlice Software
email : http://www.adlice.com/fr/contact/
Remontées : https://forum.adlice.com
Site web : http://www.adlice.com/fr/download/roguekiller/
Blog : http://www.adlice.com/fr/

Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Démarré en : Mode sans échec prise en charge réseau
Utilisateur : widen-finalis [Administrateur]
Démarré depuis : C:\Program Files\RogueKiller\RogueKiller.exe
Mode : Suppression -- Date : 08/08/2017 21:20:38 (Durée : 02:11:27)

¤¤¤ Processus : 3 ¤¤¤
[Proc.RunPE] PDFelement.exe(748) -- C:\Users\widen-finalis\Desktop\lfsu-cewbé-100%s suite 5.5 ~ lfsu100%sf pt 1 & Zs++sfce apps ~ cad jess-jess m moulue st conrad 17_3 & 17_9\PDFelement.6.0.3.2154.Port.xcd\PDFelement.exe[-] -> Tué(e) [TermProc]
[Proc.Injected] PDFelement.exe(1716) -- C:\Users\widen-finalis\Desktop\lfsu-cewbé-100%s suite 5.5 ~ lfsu100%sf pt 1 & Zs++sfce apps ~ cad jess-jess m moulue st conrad 17_3 & 17_9\PDFelement.6.0.3.2154.Port.xcd\PDFelement.exe[-] -> Tué(e) [TermProc]
[Proc.RunPE] PDFelement.exe(1200) -- C:\Users\widen-finalis\Desktop\lfsu-cewbé-100%s suite 5.5 ~ lfsu100%sf pt 1 & Zs++sfce apps ~ cad jess-jess m moulue st conrad 17_3 & 17_9\PDFelement.6.0.3.2154.Port.xcd\PDFelement.exe[-] -> Tué(e) [TermProc]

¤¤¤ Registre : 3 ¤¤¤
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aswVmm (\??\C:\Users\WIDEN-~1\AppData\Local\Temp\aswVmm.sys) -> Supprimé(e)
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\aswVmm (\??\C:\Users\WIDEN-~1\AppData\Local\Temp\aswVmm.sys) -> Supprimé(e)
[PUM.SearchPage] HKEY_USERS\S-1-5-21-4183021106-2149456055-877251859-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Remplacé(e) (http://search.msn.com/spbasic.htm)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 1 ¤¤¤
[File.Forged|VT.Unknown][Fichier] C:\Windows\unsignedthemes.exe -> Remplacé(e) au redémarrage ( @Src C:\Users\widen-finalis\AppData\Local\Temp\snack\unsignedthemes.exe)

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Non chargé [0xc000035f]) ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 581a776eda556d8f81a090acd17d9b70
[BSP] 6b8521bd6518f14fe89be3fa5f6094b6 : Unknown MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 13312 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 27265024 | Size: 2997 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 33404819 | Size: 222164 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: +++++
Error reading User MBR! ([57] Paramètre incorrect. )
Error reading LL1 MBR! ([79] Le délai de temporisation de sémaphore a expiré. )
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )

+++++ PhysicalDrive2: +++++
--- User ---
[MBR] e5c512cc5ddca0b8afa66b736f6c455b
[BSP] f19fe6ab6ca90069cd9e8a8b3c45ec67 : Unknown|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0xff) [VISIBLE] Offset (sectors): 4294967295 | Size: 2097151 MB
1 - [XXXXXX] UNKNOWN (0xff) [VISIBLE] Offset (sectors): 4294967295 | Size: 2097151 MB
2 - [XXXXXX] UNKNOWN (0xff) [VISIBLE] Offset (sectors): 4294967295 | Size: 2097151 MB
3 - [XXXXXX] UNKNOWN (0xff) [VISIBLE] Offset (sectors): 4294967295 | Size: 279168 MB
Error reading LL1 MBR! ([32] Cette demande n?est pas prise en charge. )
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )

+++++ PhysicalDrive3: +++++
--- User ---
[MBR] 2d9fed53a97163d2ba52a7e9b6b95624
[BSP] 3d1aaedf9a1eccd13cd04f3f4113ba48 : Legit.Unknown|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 64 | Size: 122367 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )

+++++ PhysicalDrive4: +++++
--- User ---
[MBR] 7a0e5b587078eafea26e065f01c93a32
[BSP] e3e89e48327d6ab3a81d8bb892c575d2 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] FAT16 (0x6) [VISIBLE] Offset (sectors): 63 | Size: 243 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )

+++++ PhysicalDrive5: +++++
--- User ---
[MBR] 1d85ed8d4a980c74df074e0864dfd083
[BSP] 0ed7054157441c76a4e04b614ebdb693 : Empty|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 8192 | Size: 29660 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )

+++++ PhysicalDrive6: +++++
--- User ---
[MBR] d1c5f8f9715227d9038205c7fd153bff
[BSP] dce0812770503e7b532c015c6fe72699 : Unknown|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 128 | Size: 3775 MB [Unknown Bootstrap | Unknown Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )

+++++ PhysicalDrive7: +++++
--- User ---
[MBR] 02dcf3daa7b80e7f8c5772707acfbcf2
[BSP] 59638a3d4377b4d07c14a5463bf72f9d : Legit.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 32 | Size: 14663 MB [Unknown Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )


Publicité


Signaler le contenu de ce document

Publicité