cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

RogueKiller V10.0.3.0 [Oct 22 2014] par Adlice Software
email : http://www.adlice.com/contact/
Remont�es : http://forum.adlice.com
Site web : https://www.surlatoile.org/RogueKiller/
Blog : http://www.adlice.com

Syst�me d'exploitation : Windows XP (5.1.2600 Service Pack 3) 32 bits version
D�marr� en : Mode normal
Utilisateur : Remi [Administrateur]
Mode : Suppression -- Date : 10/24/2014 12:17:37

��� Processus : 0 ���

��� Registre : 16 ���
[PUM.HomePage] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.winfuture.de -> Remplac�(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.winfuture.de -> Remplac�(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.winfuture.de -> Remplac�(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.winfuture.de -> Remplac�(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.SearchPage] HKEY_USERS\S-1-5-21-329068152-1177238915-1606980848-1004\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> Remplac�(e) (http://go.microsoft.com/fwlink/?LinkId=54896)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3BAAFD91-9818-4282-A734-845C40F2190C} | DhcpNameServer : 10.0.0.1 10.0.0.1 -> Remplac�(e) ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{3BAAFD91-9818-4282-A734-845C40F2190C} | DhcpNameServer : 10.0.0.1 10.0.0.1 -> Remplac�(e) ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{3BAAFD91-9818-4282-A734-845C40F2190C} | DhcpNameServer : 10.0.0.1 10.0.0.1 -> Remplac�(e) ()
[PUM.StartMenu] HKEY_USERS\S-1-5-21-329068152-1177238915-1606980848-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowSetProgramAccessAndDefaults : 0 -> Remplac�(e) (1)
[PUM.StartMenu] HKEY_USERS\S-1-5-21-329068152-1177238915-1606980848-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 2 -> Remplac�(e) (1)
[PUM.StartMenu] HKEY_USERS\S-1-5-21-329068152-1177238915-1606980848-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyDocs : 2 -> Remplac�(e) (1)
[PUM.StartMenu] HKEY_USERS\S-1-5-21-329068152-1177238915-1606980848-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 2 -> Remplac�(e) (1)
[PUM.StartMenu] HKEY_USERS\S-1-5-21-329068152-1177238915-1606980848-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowControlPanel : 2 -> Remplac�(e) (1)
[PUM.StartMenu] HKEY_USERS\S-1-5-21-329068152-1177238915-1606980848-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyComputer : 2 -> Remplac�(e) (1)
[PUM.StartMenu] HKEY_USERS\S-1-5-21-329068152-1177238915-1606980848-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 2 -> Remplac�(e) (1)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Remplac�(e) (0)

��� T�ches : 1 ���
[Suspicious.Path] MP Scheduled Scan.job -- c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe (Scan -ScheduleJob -WinTask -RestrictPrivilegesScan) -> Supprim�(e)

��� Fichiers : 0 ���

��� Fichier Hosts : 0 [Too big!] ���

��� Antirootkit : 3 (Driver: Charg�) ���
[IAT:Addr] (firefox.exe @ sti.dll) CFGMGR32.dll - CM_Reenumerate_DevNode : C:\WINDOWS\system32\SETUPAPI.dll @ 0x779526a5
[IAT:Addr] (firefox.exe @ sti.dll) CFGMGR32.dll - CM_Get_DevNode_Status : C:\WINDOWS\system32\SETUPAPI.dll @ 0x778ec6eb
[IAT:Addr] (firefox.exe @ sti.dll) CFGMGR32.dll - CM_Get_Parent : C:\WINDOWS\system32\SETUPAPI.dll @ 0x77957a5d

��� Navigateurs web : 4 ���
[FIREFX:Addon] fs6h06ni.default : Microsoft .NET Framework Assistant [{20a82645-c095-46ed-80e3-08825760534b}] -> Supprim�(e)
[FIREFX:Addon] fs6h06ni.default : Adblock Plus [{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}] -> Supprim�(e)
[FIREFX:Addon] fs6h06ni.default : avast! Online Security [wrc@avast.com] -> Supprim�(e)
[PUP][FIREFX:Addon] fs6h06ni.default : cacaoweb [cacaoweb@cacaoweb.org] -> Supprim�(e)

��� V�rification MBR : ���
+++++ PhysicalDrive0: ST3160812AS +++++
--- User ---
[MBR] 0b6103fd7dd0e73220d059fe16c2a250
[BSP] 6cc154c5d8af335ee4bc5d4bd8aea872 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 60000 MB
1 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 122881185 | Size: 92616 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Fonction incorrecte. )

+++++ PhysicalDrive1: WD Ext HDD 1021 USB Device +++++
--- User ---
[MBR] 8e5136b34b1af10a5d0cc3096c89a2be
[BSP] 4c29d1acb7498dffe1e2bd427083bc3f : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1907726 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n'est pas prise en charge. )

+++++ PhysicalDrive2: HUAWEI TF CARD Storage USB Device +++++
Error reading User MBR! ([15] Le p�riph�rique n'est pas pr�t. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Cette demande n'est pas prise en charge. )

+++++ PhysicalDrive3: Generic USB SD Reader USB Device +++++
Error reading User MBR! ([15] Le p�riph�rique n'est pas pr�t. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Cette demande n'est pas prise en charge. )

+++++ PhysicalDrive4: Generic USB CF Reader USB Device +++++
Error reading User MBR! ([15] Le p�riph�rique n'est pas pr�t. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Cette demande n'est pas prise en charge. )

+++++ PhysicalDrive5: Generic USB SM Reader USB Device +++++
Error reading User MBR! ([15] Le p�riph�rique n'est pas pr�t. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Cette demande n'est pas prise en charge. )

+++++ PhysicalDrive6: Generic USB MS Reader USB Device +++++
Error reading User MBR! ([15] Le p�riph�rique n'est pas pr�t. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Cette demande n'est pas prise en charge. )


============================================
RKreport_SCN_10242014_121433.log

Publicité


Signaler le contenu de ce document

Publicité