cjoint

Publicité


Publicité

Format du document : application/octet-stream

Prévisualisation

RogueKiller V10.8.1.0 [Jun 3 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Démarré en : Mode normal
Utilisateur : hp [Administrateur]
Démarré depuis : C:\Users\hp\Desktop\RogueKiller.exe
Mode : Suppression -- Date : 06/07/2015 10:42:58

¤¤¤ Processus : 0 ¤¤¤

¤¤¤ Registre : 9 ¤¤¤
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> Supprimé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 192.168.1.1 0.0.0.0 [-][(Private Address) (XX)] -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 192.168.1.1 0.0.0.0 [-][(Private Address) (XX)] -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 192.168.1.1 0.0.0.0 [-][(Private Address) (XX)] -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{66439100-3D04-468F-90CC-448D2F0DBCA5} | DhcpNameServer : 192.168.1.1 0.0.0.0 [-][(Private Address) (XX)] -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{66439100-3D04-468F-90CC-448D2F0DBCA5} | DhcpNameServer : 192.168.1.1 0.0.0.0 [-][(Private Address) (XX)] -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{66439100-3D04-468F-90CC-448D2F0DBCA5} | DhcpNameServer : 192.168.1.1 0.0.0.0 [-][(Private Address) (XX)] -> Remplacé(e) ()
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Remplacé(e) (2)
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Remplacé(e) (2)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost

¤¤¤ Antirootkit : 14 (Driver: Non chargé [0xc000036b]) ¤¤¤
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0x509d3f19 (call 0xd9003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0x249d3f19 (call 0xad003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xffffffff869d3f19 (call 0xf003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0x189d3f19 (call 0xa1003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0x379d3f19 (call 0xc0003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xfffffffff99d3f19 (call 0x82003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xffffffffe99d3f19 (call 0x72003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xffffffffbb9d3f19 (call 0x44003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xffffffff8c9d3f19 (call 0x15003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0x2c9d3f19 (call 0xb5003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0x1f9d3f19 (call 0xa8003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xffffffff8b9d3f19 (call 0x14003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xffffffffd39d3f19 (call 0x5c003f09)
[IAT:Inl(Hook.IEAT)] (chrome.exe) ntdll.dll - NlsAnsiCodePage : Unknown @ 0xffffffffca9d3f19 (call 0x53003f09)

¤¤¤ Navigateurs web : 1 ¤¤¤
[PUP][FIREFX:Addon] ir8xr7q9.default : Hotspot Shield Helper (Please allow this installation) [afurladvisor@anchorfree.com] -> Non sélectionné

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MK6476GSX ATA Device +++++
--- User ---
[MBR] 1a6b26332c0fa7ce902e04bbc3d709f7
[BSP] cd27ed3eb96aab5c994ff939e1f9cca6 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 316722 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8|VT.Unknown Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 648853504 | Size: 293656 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_SCN_07242014_013035.log - RKreport_DEL_07242014_013119.log - RKreport_SCN_07252014_000152.log - RKreport_DEL_07252014_000223.log
RKreport_SCN_06072015_102352.log - RKreport_SCN_06072015_103905.log

Publicité


Signaler le contenu de ce document

Publicité