cjoint

Publicité


Publicité

Format du document : application/octet-stream

Prévisualisation

RogueKiller V10.8.2.0 [Jun 9 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7600 ) 64 bits version
Démarré en : Mode normal
Utilisateur : ACER [Administrateur]
Démarré depuis : C:\Users\ACER\Desktop\RogueKiller.exe
Mode : Scan -- Date : 06/10/2015 00:25:40

¤¤¤ Processus : 2 ¤¤¤
[Suspicious.Path] DrvUpdater.exe(1096) -- C:\Users\ACER\AppData\Roaming\DRPSu\DrvUpdater.exe[-] VT(2) -> Tué(e) [TermProc]
[PUP] (SVC) APNMCP -- "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe"[-] -> Arrêté(e)

¤¤¤ Registre : 22 ¤¤¤
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | ApnTBMon : "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [-] -> Trouvé(e)
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3100134264-3495081747-105967624-1000\Software\Microsoft\Windows\CurrentVersion\Run | DrvUpdater : C:\Users\ACER\AppData\Roaming\DRPSu\DrvUpdater.exe /hide [-][x] -> Trouvé(e)
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3100134264-3495081747-105967624-1000\Software\Microsoft\Windows\CurrentVersion\Run | DrvUpdater : C:\Users\ACER\AppData\Roaming\DRPSu\DrvUpdater.exe /hide [-][x] -> Trouvé(e)
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\APNMCP ("C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe") -> Trouvé(e)
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\APNMCP ("C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe") -> Trouvé(e)
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\APNMCP ("C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe") -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.linkzb.com -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3100134264-3495081747-105967624-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.linkzb.com -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3100134264-3495081747-105967624-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.linkzb.com -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2DF95552-22ED-4432-A1FF-F031E7119FAA} | NameServer : 212.217.0.12 212.217.1.12 [-][MOROCCO (MA)] -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2FC1044B-6578-42F2-917E-A5187B3D4639} | NameServer : 212.217.0.12 212.217.1.12 [-][MOROCCO (MA)] -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D229D8A-7874-44B3-9982-AA7603B3329F} | NameServer : 62.251.230.241 212.217.1.1 [MOROCCO (MA)][-] -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E9144440-8C83-4CC4-9025-8BA6CEC80A5D} | NameServer : 62.251.230.241 212.217.1.1 [MOROCCO (MA)][-] -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{2DF95552-22ED-4432-A1FF-F031E7119FAA} | NameServer : 212.217.0.12 212.217.1.12 [-][MOROCCO (MA)] -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{2FC1044B-6578-42F2-917E-A5187B3D4639} | NameServer : 212.217.0.12 212.217.1.12 [-][MOROCCO (MA)] -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{3D229D8A-7874-44B3-9982-AA7603B3329F} | NameServer : 62.251.230.241 212.217.1.1 [MOROCCO (MA)][-] -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{E9144440-8C83-4CC4-9025-8BA6CEC80A5D} | NameServer : 62.251.230.241 212.217.1.1 [MOROCCO (MA)][-] -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{2DF95552-22ED-4432-A1FF-F031E7119FAA} | NameServer : 212.217.0.12 212.217.1.12 [-][MOROCCO (MA)] -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{2FC1044B-6578-42F2-917E-A5187B3D4639} | NameServer : 212.217.0.12 212.217.1.12 [-][MOROCCO (MA)] -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{E9144440-8C83-4CC4-9025-8BA6CEC80A5D} | NameServer : 62.251.230.241 212.217.1.1 [MOROCCO (MA)][-] -> Trouvé(e)
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Trouvé(e)
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Trouvé(e)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Non chargé [0xc000036b]) ¤¤¤

¤¤¤ Navigateurs web : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] h8vr849w.default : user_pref("browser.startup.homepage", "http://www.linkzb.com"); -> Trouvé(e)

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 393160d7aed5182832fba54ce1abb03a
[BSP] 4e1c6a7fa4c397f4d65ee221f6717d69 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 99900 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 204802048 | Size: 205243 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User != LL2 ... KO!
--- LL2 ---
[MBR] 393160d7aed5182832fba54ce1abb03a
[BSP] 4e1c6a7fa4c397f4d65ee221f6717d69 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 99900 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 204802048 | Size: 205243 MB [Error reading VBR! ([1] Fonction incorrecte. )]

+++++ PhysicalDrive1: +++++
Error reading User MBR! ([15] Le périphérique n?est pas prêt. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )


Publicité


Signaler le contenu de ce document

Publicité