cjoint

Publicité


Publicité

Format du document : text/x-log

Prévisualisation

RogueKiller V10.0.4.0 [Oct 29 2014] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : https://www.surlatoile.org/RogueKiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 8.1 (6.3.9200 ) 64 bits version
Démarré en : Mode normal
Utilisateur : Michelle [Administrateur]
Mode : Scan -- Date : 11/02/2014 18:09:44

¤¤¤ Processus : 0 ¤¤¤

¤¤¤ Registre : 23 ¤¤¤
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BthAvrcpTg (\SystemRoot\System32\drivers\BthAvrcpTg.sys) -> Trouvé(e)
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BthHFEnum (\SystemRoot\System32\drivers\bthhfenum.sys) -> Trouvé(e)
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bthhfhid (\SystemRoot\System32\drivers\BthHFHid.sys) -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://google.com -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://google.com -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-752061620-813652355-3721536411-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://google.com -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-752061620-813652355-3721536411-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://google.com -> Trouvé(e)
[PUM.SearchPage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://google.com -> Trouvé(e)
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://google.com -> Trouvé(e)
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-752061620-813652355-3721536411-1001\Software\Microsoft\Internet Explorer\Main | Search Page : http://google.com -> Trouvé(e)
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-752061620-813652355-3721536411-1001\Software\Microsoft\Internet Explorer\Main | Search Page : http://google.com -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-752061620-813652355-3721536411-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-752061620-813652355-3721536411-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-752061620-813652355-3721536411-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-752061620-813652355-3721536411-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-752061620-813652355-3721536411-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-752061620-813652355-3721536411-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-752061620-813652355-3721536411-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-752061620-813652355-3721536411-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Trouvé(e)

¤¤¤ Tâches : 4 ¤¤¤
[Suspicious.Path] ILUPSTSQ.job -- C:\Users\Michelle\AppData\Roaming\ILUPSTSQ.exe (/infocmdline=UglviTHQwm+aiKBwfTFkD8k/vVNmZzb8IcokORRSS/khmFo8UnohKmeQOZZ+434MPk2OGxp3x0G8J7Zh0zpe+eTl/763aDo+597mvB6z8umKpkMCF1/WKxp79w9NohOLMalVedS0EPNcnTZxgRJvNnuYdoh8hvIOGkdkzzS60cJscQ2cGYA9CgzZYkNUGMt2PMhp+6i+YumvGny1gFMlxFwYcG6BL28+h25VwFIW9wz8X16OLKdqwpagxqAzCr7axMzLKG+fY/gMElDfd1aAmoASitK2PnpbEADePyi5Y9CD1XCdzYnzIGiu6CGVyQWTzic3NUwi1MvAY61y5rN78gkX3vHfz/gPcWgFttPbVNPCBD5MfvWBKtcVFRvPCRASj1HoGRceSTp/sBgD8VVjAJueXzsGMJ3vIbNSjFOgboLl6XOxMw00S34C3GUb9odbeFr3sxr+IWu+I+/Ln1gFsX7zdA/1iCV5ce4gVKYA5dd7gYu3d+omWrCspXn9+JvJsZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=) -> Trouvé(e)
[Suspicious.Path] XIF.job -- C:\Users\Michelle\AppData\Roaming\XIF.exe (/infocmdline=WmK/T9vYHxgasRHRQI8dWW4l0hSLmZfTWMWRbtSMz6zrmIyHwkojNwvRjT1y0kdn3VqxrUu5rS2WYc54NTuhQgY41d9iPc4YWNrGv6kH+4pimiqpAAVTqJqyNWIrCTZi6CFM09WWAMR3/QMVbkPqDVANpOFD1fpoHeLeDDIqt0liVqVHFQhShhEcIAH9AZPqQR3XnPmF0fk1Vq/2CGQZgru5cDwpsqiiGiqrDQ/4qLbMSzuzrmcg+9nkVvaTdIMToSmlYACafOcLFi4ARL1unonjZeCtk8MHJKiAu7eFWtRqgLX6igPauMqFGwXoXDBOb+pRliWFgzNLEB1M6yp3pZh8o7i6o+Tsi91POgM9w69cGKaLUHIU7cVLHhNBmDbfPDvugRz65TFmsBuTsOL/3JL0iHso8RCHqVlfHoMzVO/+ag9DMq6jPfoHxwnDhfJxh6zo4/j2Mfsj2EqqvSCn04qVKAi/kbV7OBI3bW1hZG4jzmQuhmy7vx2KTMBu8kPk) -> Trouvé(e)
[Suspicious.Path] \\ILUPSTSQ -- C:\Users\Michelle\AppData\Roaming\ILUPSTSQ.exe (/infocmdline=UglviTHQwm+aiKBwfTFkD8k/vVNmZzb8IcokORRSS/khmFo8UnohKmeQOZZ+434MPk2OGxp3x0G8J7Zh0zpe+eTl/763aDo+597mvB6z8umKpkMCF1/WKxp79w9NohOLMalVedS0EPNcnTZxgRJvNnuYdoh8hvIOGkdkzzS60cJscQ2cGYA9CgzZYkNUGMt2PMhp+6i+YumvGny1gFMlxFwYcG6BL28+h25VwFIW9wz8X16OLKdqwpagxqAzCr7axMzLKG+fY/gMElDfd1aAmoASitK2PnpbEADePyi5Y9CD1XCdzYnzIGiu6CGVyQWTzic3NUwi1MvAY61y5rN78gkX3vHfz/gPcWgFttPbVNPCBD5MfvWBKtcVFRvPCRASj1HoGRceSTp/sBgD8VVjAJueXzsGMJ3vIbNSjFOgboLl6XOxMw00S34C3GUb9odbeFr3sxr+IWu+I+/Ln1gFsX7zdA/1iCV5ce4gVKYA5dd7gYu3d+omWrCspXn9+JvJsZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=) -> Trouvé(e)
[Suspicious.Path] \\XIF -- C:\Users\Michelle\AppData\Roaming\XIF.exe (/infocmdline=WmK/T9vYHxgasRHRQI8dWW4l0hSLmZfTWMWRbtSMz6zrmIyHwkojNwvRjT1y0kdn3VqxrUu5rS2WYc54NTuhQgY41d9iPc4YWNrGv6kH+4pimiqpAAVTqJqyNWIrCTZi6CFM09WWAMR3/QMVbkPqDVANpOFD1fpoHeLeDDIqt0liVqVHFQhShhEcIAH9AZPqQR3XnPmF0fk1Vq/2CGQZgru5cDwpsqiiGiqrDQ/4qLbMSzuzrmcg+9nkVvaTdIMToSmlYACafOcLFi4ARL1unonjZeCtk8MHJKiAu7eFWtRqgLX6igPauMqFGwXoXDBOb+pRliWFgzNLEB1M6yp3pZh8o7i6o+Tsi91POgM9w69cGKaLUHIU7cVLHhNBmDbfPDvugRz65TFmsBuTsOL/3JL0iHso8RCHqVlfHoMzVO/+ag9DMq6jPfoHxwnDhfJxh6zo4/j2Mfsj2EqqvSCn04qVKAi/kbV7OBI3bW1hZG4jzmQuhmy7vx2KTMBu8kPk) -> Trouvé(e)

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 2 (Driver: Non chargé [0xc000036b]) ¤¤¤
[IAT:Addr] (firefox.exe @ combase.dll) ext-ms-win-com-clbcatq-l1-1-0.dll - GetCatalogObject2 : C:\WINDOWS\SYSTEM32\clbcatq.dll @ 0x77663206
[IAT:Addr] (firefox.exe @ combase.dll) ext-ms-win-com-clbcatq-l1-1-0.dll - GetCatalogObject : C:\WINDOWS\SYSTEM32\clbcatq.dll @ 0x7766278d

¤¤¤ Navigateurs web : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] 6sqe3mu9.default : user_pref("browser.startup.homepage", "http://portail.free.fr/"); -> Trouvé(e)

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: HGST HTS541010A9E680 +++++
--- User ---
[MBR] 1be177f18099da25ec446a3cf97d7514
[BSP] 9ae116ca9c6ee3039898d312cab59b74 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097151 MB
User = LL1 ... OK
User = LL2 ... OK


Publicité


Signaler le contenu de ce document

Publicité