cjoint

Publicité


Publicité

Format du document : text/x-log

Prévisualisation

RogueKiller V9.2.10.0 (x64) [Jul 11 2014] par Adlice Software
Mail : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site Web : https://www.surlatoile.org/RogueKiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Démarrage : Mode normal
Utilisateur : janot [Droits d'admin]
Mode : Suppression -- Date : 09/14/2014 16:50:51

¤¤¤ Processus malicieux : 0 ¤¤¤

¤¤¤ Entrées de registre : 36 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del4688376 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" [x] -> SUPPRIMÉ
[Suspicious.Path] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del13637342 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" [x] -> SUPPRIMÉ
[Suspicious.Path] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del46772968 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" [x] -> SUPPRIMÉ
[Suspicious.Path] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del40649804 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" [x] -> SUPPRIMÉ
[Suspicious.Path] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del4038943 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" [x] -> SUPPRIMÉ
[Suspicious.Path] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del9532643 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" [x] -> SUPPRIMÉ
[Suspicious.Path] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del3930803 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" [x] -> SUPPRIMÉ
[Suspicious.Path] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del4688376 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del13637342 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del46772968 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del40649804 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del4038943 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del9532643 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del3930803 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del4688376 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del13637342 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del46772968 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del40649804 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del4038943 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del9532643 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del3930803 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del4688376 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del13637342 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del46772968 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del40649804 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del4038943 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del9532643 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del3930803 : cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del" -> ERROR [2]
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-813451756-248047063-479339143-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NON SELECTIONNÉ
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-813451756-248047063-479339143-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NON SELECTIONNÉ
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-813451756-248047063-479339143-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NON SELECTIONNÉ
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-813451756-248047063-479339143-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NON SELECTIONNÉ
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NON SELECTIONNÉ
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NON SELECTIONNÉ
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NON SELECTIONNÉ
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NON SELECTIONNÉ

¤¤¤ Tâches planifiées : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: CHARGE) ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ MBR Verif : ¤¤¤
+++++ PhysicalDrive0: WDC WD10 EADX-22TDHB0 SATA Disk Device +++++
--- User ---
[MBR] eb837f51894c2d98a2b0a95566414334
[BSP] 74760bb55391995f4ec887af376f4d02 : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 20480 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 41945088 | Size: 100 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 42149888 | Size: 466382 MB
3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 997300224 | Size: 466905 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: Generic- Multi-Card USB Device +++++
Error reading User MBR! ([15] Le périphérique n?est pas prêt. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )


============================================
RKreport_SCN_09142014_122123.log - RKreport_SCN_09142014_164930.log

Publicité


Signaler le contenu de ce document

Publicité