cjoint

Publicité


Publicité

Format du document : application/octet-stream

Prévisualisation

[code]
HitmanPro 3.7.15.281
www.hitmanpro.com

Computer name . . . . : DJAMELEDDINE-PC
Windows . . . . . . . : 6.1.1.7601.X86/2
User name . . . . . . : djameleddine-PC\djamel eddine
UAC . . . . . . . . . : Enabled
License . . . . . . . : Trial (30 days left)

Scan date . . . . . . : 2017-01-07 15:55:41
Scan mode . . . . . . : Normal
Scan duration . . . . : 13m 14s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No

Threats . . . . . . . : 0
Traces . . . . . . . : 72

Objects scanned . . . : 1 550 017
Files scanned . . . . : 45 550
Remnants scanned . . : 666 863 files / 837 604 keys

Suspicious files ____________________________________________________________

C:\Program Files\Ralink\Common\RaUI.exe
Size . . . . . . . : 15 661 872 bytes
Age . . . . . . . : 266.0 days (2016-04-16 16:09:47)
Entropy . . . . . : 5.4
SHA-256 . . . . . : F79E3FD7F5582FEB8FE51B37E37DFC4AB58000E90AA049A5C7C6876E057153CF
Product . . . . . : RaUI Application
Publisher . . . . : Ralink Technology, Corp.
Description . . . : Ralink Wireless LAN Card Utility
Version . . . . . : 5.0.8.0
Copyright . . . . : (c) Copyright 2013, Ralink Technology, Inc. All rights reserved.
RSA Key Size . . . : 2048
Parent Name . . . : C:\Windows\Explorer.EXE
LanguageID . . . . : 1033
Authenticode . . . : Invalid
Running processes : 2740
Fuzzy . . . . . . : 24.0
Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
Uses the Startup folder in the Start Menu to run each time the user logs on.
Program is running but currently exposes no human-computer interface (GUI).
Program starts automatically without user intervention.
The file is in use by one or more active processes.
The file appears to be part of an installation package or setup program. This is typical for most programs.
Startup
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
References
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ralink Wireless\Ralink Wireless Utility.lnk

C:\Users\djamel eddine\AppData\Local\Microsoft\bass.dll
Size . . . . . . . : 110 719 bytes
Age . . . . . . . : 1.8 days (2017-01-05 20:52:35)
Entropy . . . . . : 7.9
SHA-256 . . . . . : 9E13670EBC8C284E28D85FB353EEFBB31CAE9A3E75361033533DA3AA40ECFF3F
Fuzzy . . . . . . : 24.0
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Program is running but currently exposes no human-computer interface (GUI).
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Program contains PE structure anomalies. This is not typical for most programs.
The file is in use by one or more active processes.
Forensic Cluster
-3.9s C:\Users\djamel eddine\AppData\Local\Temp\.iFunboxUpdated\
-3.1s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
-2.1s C:\Users\djamel eddine\AppData\Local\Temp\FXSAPIDebugLogFile.txt
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_fx.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basscd.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassenc.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmix.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basswma.dll
0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmidi.dll
0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_vst.dll
0.2s C:\Users\djamel eddine\AppData\Local\Microsoft\bassflac.dll
2.2s C:\Users\djamel eddine\AppData\Local\Microsoft\engine_vx.dll
2.5s C:\Users\djamel eddine\AppData\Local\Temp\iobit-db-license-tmp\
3.1s C:\Users\djamel eddine\AppData\Local\Microsoft\basswasapi.dll
3.9s C:\Users\djamel eddine\AppData\Local\Temp\datC1A9.tmp
4.4s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\
4.4s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\127.0.0[1].xml
4.6s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\
4.7s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\container.dat
6.5s C:\Windows\System32\config\systemprofile\AppData\Local\Avg\av16\temp\avg-f02f6e60-7c8c-4722-a612-62527bf89f3b.tmp
6.9s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\
6.9s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\ifbstore.appholly[1].xml
9.7s C:\Users\djamel eddine\AppData\Roaming\Microsoft\Windows\Cookies\U3AF8LI8.txt
9.7s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\
9.7s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\C8QR34PD\
12.1s C:\Users\djamel eddine\AppData\Local\Temp\~DF03076106F4AB47D8.TMP
19.3s C:\Users\djamel eddine\AppData\Local\Temp\BCGFDDF.tmp

C:\Users\djamel eddine\AppData\Local\Microsoft\bass_fx.dll
Size . . . . . . . : 34 392 bytes
Age . . . . . . . : 1.8 days (2017-01-05 20:52:35)
Entropy . . . . . : 7.8
SHA-256 . . . . . : 4F93174CE9C2857BAF7038849E1D914DE5F408C003133B72D095E339802BF8D9
Fuzzy . . . . . . : 24.0
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Program is running but currently exposes no human-computer interface (GUI).
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Program contains PE structure anomalies. This is not typical for most programs.
The file is in use by one or more active processes.
Forensic Cluster
-3.9s C:\Users\djamel eddine\AppData\Local\Temp\.iFunboxUpdated\
-3.1s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
-2.1s C:\Users\djamel eddine\AppData\Local\Temp\FXSAPIDebugLogFile.txt
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_fx.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basscd.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassenc.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmix.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basswma.dll
0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmidi.dll
0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_vst.dll
0.2s C:\Users\djamel eddine\AppData\Local\Microsoft\bassflac.dll
2.2s C:\Users\djamel eddine\AppData\Local\Microsoft\engine_vx.dll
2.5s C:\Users\djamel eddine\AppData\Local\Temp\iobit-db-license-tmp\
3.1s C:\Users\djamel eddine\AppData\Local\Microsoft\basswasapi.dll
3.9s C:\Users\djamel eddine\AppData\Local\Temp\datC1A9.tmp
4.4s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\
4.4s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\127.0.0[1].xml
4.6s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\
4.7s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\container.dat
6.5s C:\Windows\System32\config\systemprofile\AppData\Local\Avg\av16\temp\avg-f02f6e60-7c8c-4722-a612-62527bf89f3b.tmp
6.9s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\
6.9s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\ifbstore.appholly[1].xml
9.7s C:\Users\djamel eddine\AppData\Roaming\Microsoft\Windows\Cookies\U3AF8LI8.txt
9.7s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\
9.7s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\C8QR34PD\
12.1s C:\Users\djamel eddine\AppData\Local\Temp\~DF03076106F4AB47D8.TMP
19.3s C:\Users\djamel eddine\AppData\Local\Temp\BCGFDDF.tmp

C:\Users\djamel eddine\AppData\Local\Microsoft\basscd.dll
Size . . . . . . . : 19 008 bytes
Age . . . . . . . : 1.8 days (2017-01-05 20:52:35)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 0B80E510B7B6EEE8549AF9F2A7F9316B9E01D63EF95D4F402AC3B21E96BB0D19
Fuzzy . . . . . . : 24.0
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Program is running but currently exposes no human-computer interface (GUI).
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Program contains PE structure anomalies. This is not typical for most programs.
The file is in use by one or more active processes.
Forensic Cluster
-3.9s C:\Users\djamel eddine\AppData\Local\Temp\.iFunboxUpdated\
-3.1s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
-2.1s C:\Users\djamel eddine\AppData\Local\Temp\FXSAPIDebugLogFile.txt
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_fx.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basscd.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassenc.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmix.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basswma.dll
0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmidi.dll
0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_vst.dll
0.2s C:\Users\djamel eddine\AppData\Local\Microsoft\bassflac.dll
2.2s C:\Users\djamel eddine\AppData\Local\Microsoft\engine_vx.dll
2.5s C:\Users\djamel eddine\AppData\Local\Temp\iobit-db-license-tmp\
3.1s C:\Users\djamel eddine\AppData\Local\Microsoft\basswasapi.dll
3.9s C:\Users\djamel eddine\AppData\Local\Temp\datC1A9.tmp
4.4s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\
4.4s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\127.0.0[1].xml
4.6s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\
4.7s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\container.dat
6.5s C:\Windows\System32\config\systemprofile\AppData\Local\Avg\av16\temp\avg-f02f6e60-7c8c-4722-a612-62527bf89f3b.tmp
6.9s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\
6.9s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\ifbstore.appholly[1].xml
9.7s C:\Users\djamel eddine\AppData\Roaming\Microsoft\Windows\Cookies\U3AF8LI8.txt
9.7s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\
9.7s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\C8QR34PD\
12.1s C:\Users\djamel eddine\AppData\Local\Temp\~DF03076106F4AB47D8.TMP
19.3s C:\Users\djamel eddine\AppData\Local\Temp\BCGFDDF.tmp

C:\Users\djamel eddine\AppData\Local\Microsoft\bassenc.dll
Size . . . . . . . : 16 448 bytes
Age . . . . . . . : 1.8 days (2017-01-05 20:52:35)
Entropy . . . . . : 7.5
SHA-256 . . . . . : 2463A9A159D4F921257FE9972AE87BDEB1B55A9ED2307321B04EA7E727848764
Fuzzy . . . . . . : 24.0
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Program is running but currently exposes no human-computer interface (GUI).
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Program contains PE structure anomalies. This is not typical for most programs.
The file is in use by one or more active processes.
Forensic Cluster
-3.9s C:\Users\djamel eddine\AppData\Local\Temp\.iFunboxUpdated\
-3.1s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
-2.1s C:\Users\djamel eddine\AppData\Local\Temp\FXSAPIDebugLogFile.txt
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_fx.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basscd.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassenc.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmix.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basswma.dll
0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmidi.dll
0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_vst.dll
0.2s C:\Users\djamel eddine\AppData\Local\Microsoft\bassflac.dll
2.2s C:\Users\djamel eddine\AppData\Local\Microsoft\engine_vx.dll
2.5s C:\Users\djamel eddine\AppData\Local\Temp\iobit-db-license-tmp\
3.1s C:\Users\djamel eddine\AppData\Local\Microsoft\basswasapi.dll
3.9s C:\Users\djamel eddine\AppData\Local\Temp\datC1A9.tmp
4.4s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\
4.4s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\127.0.0[1].xml
4.6s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\
4.7s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\container.dat
6.5s C:\Windows\System32\config\systemprofile\AppData\Local\Avg\av16\temp\avg-f02f6e60-7c8c-4722-a612-62527bf89f3b.tmp
6.9s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\
6.9s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\ifbstore.appholly[1].xml
9.7s C:\Users\djamel eddine\AppData\Roaming\Microsoft\Windows\Cookies\U3AF8LI8.txt
9.7s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\
9.7s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\C8QR34PD\
12.1s C:\Users\djamel eddine\AppData\Local\Temp\~DF03076106F4AB47D8.TMP
19.3s C:\Users\djamel eddine\AppData\Local\Temp\BCGFDDF.tmp

C:\Users\djamel eddine\AppData\Local\Microsoft\bassmidi.dll
Size . . . . . . . : 36 416 bytes
Age . . . . . . . : 1.8 days (2017-01-05 20:52:35)
Entropy . . . . . : 7.8
SHA-256 . . . . . : 8C58BC6C89772D0CD72C61E6CF982A3F51DEE9AAC946E076A0273CD3AAF3BE9D
Fuzzy . . . . . . : 24.0
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Program is running but currently exposes no human-computer interface (GUI).
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Program contains PE structure anomalies. This is not typical for most programs.
The file is in use by one or more active processes.
Forensic Cluster
-4.0s C:\Users\djamel eddine\AppData\Local\Temp\.iFunboxUpdated\
-3.2s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
-2.2s C:\Users\djamel eddine\AppData\Local\Temp\FXSAPIDebugLogFile.txt
-0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\bass.dll
-0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_fx.dll
-0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\basscd.dll
-0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\bassenc.dll
-0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmix.dll
-0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basswma.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmidi.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_vst.dll
0.1s C:\Users\djamel eddine\AppData\Local\Microsoft\bassflac.dll
2.1s C:\Users\djamel eddine\AppData\Local\Microsoft\engine_vx.dll
2.4s C:\Users\djamel eddine\AppData\Local\Temp\iobit-db-license-tmp\
3.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basswasapi.dll
3.8s C:\Users\djamel eddine\AppData\Local\Temp\datC1A9.tmp
4.3s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\
4.3s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\127.0.0[1].xml
4.6s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\
4.6s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\container.dat
6.4s C:\Windows\System32\config\systemprofile\AppData\Local\Avg\av16\temp\avg-f02f6e60-7c8c-4722-a612-62527bf89f3b.tmp
6.8s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\
6.8s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\ifbstore.appholly[1].xml
9.6s C:\Users\djamel eddine\AppData\Roaming\Microsoft\Windows\Cookies\U3AF8LI8.txt
9.6s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\
9.6s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\C8QR34PD\
12.0s C:\Users\djamel eddine\AppData\Local\Temp\~DF03076106F4AB47D8.TMP
19.2s C:\Users\djamel eddine\AppData\Local\Temp\BCGFDDF.tmp

C:\Users\djamel eddine\AppData\Local\Microsoft\bassmix.dll
Size . . . . . . . : 18 496 bytes
Age . . . . . . . : 1.8 days (2017-01-05 20:52:35)
Entropy . . . . . : 7.7
SHA-256 . . . . . : 34E0733CE8B61A2B8DFD9F569A0E052D1A45979945B5A894BCA2242BDF65BD72
Fuzzy . . . . . . : 24.0
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Program is running but currently exposes no human-computer interface (GUI).
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Program contains PE structure anomalies. This is not typical for most programs.
The file is in use by one or more active processes.
Forensic Cluster
-3.9s C:\Users\djamel eddine\AppData\Local\Temp\.iFunboxUpdated\
-3.1s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
-2.1s C:\Users\djamel eddine\AppData\Local\Temp\FXSAPIDebugLogFile.txt
-0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass.dll
-0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_fx.dll
-0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basscd.dll
-0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassenc.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmix.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basswma.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmidi.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_vst.dll
0.2s C:\Users\djamel eddine\AppData\Local\Microsoft\bassflac.dll
2.2s C:\Users\djamel eddine\AppData\Local\Microsoft\engine_vx.dll
2.4s C:\Users\djamel eddine\AppData\Local\Temp\iobit-db-license-tmp\
3.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basswasapi.dll
3.8s C:\Users\djamel eddine\AppData\Local\Temp\datC1A9.tmp
4.3s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\
4.4s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\127.0.0[1].xml
4.6s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\
4.6s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\container.dat
6.5s C:\Windows\System32\config\systemprofile\AppData\Local\Avg\av16\temp\avg-f02f6e60-7c8c-4722-a612-62527bf89f3b.tmp
6.9s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\
6.9s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\ifbstore.appholly[1].xml
9.6s C:\Users\djamel eddine\AppData\Roaming\Microsoft\Windows\Cookies\U3AF8LI8.txt
9.7s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\
9.7s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\C8QR34PD\
12.1s C:\Users\djamel eddine\AppData\Local\Temp\~DF03076106F4AB47D8.TMP
19.2s C:\Users\djamel eddine\AppData\Local\Temp\BCGFDDF.tmp

C:\Users\djamel eddine\AppData\Local\Microsoft\basswma.dll
Size . . . . . . . : 17 733 bytes
Age . . . . . . . : 1.8 days (2017-01-05 20:52:35)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 61EBD26043BFB155950D0D4B829F34E1AD6151B51BF9581E42ACF621DA1C1D86
Fuzzy . . . . . . : 24.0
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Program is running but currently exposes no human-computer interface (GUI).
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Program contains PE structure anomalies. This is not typical for most programs.
The file is in use by one or more active processes.
Forensic Cluster
-3.9s C:\Users\djamel eddine\AppData\Local\Temp\.iFunboxUpdated\
-3.1s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
-2.1s C:\Users\djamel eddine\AppData\Local\Temp\FXSAPIDebugLogFile.txt
-0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass.dll
-0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_fx.dll
-0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basscd.dll
-0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassenc.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmix.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basswma.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bassmidi.dll
0.0s C:\Users\djamel eddine\AppData\Local\Microsoft\bass_vst.dll
0.2s C:\Users\djamel eddine\AppData\Local\Microsoft\bassflac.dll
2.2s C:\Users\djamel eddine\AppData\Local\Microsoft\engine_vx.dll
2.4s C:\Users\djamel eddine\AppData\Local\Temp\iobit-db-license-tmp\
3.0s C:\Users\djamel eddine\AppData\Local\Microsoft\basswasapi.dll
3.8s C:\Users\djamel eddine\AppData\Local\Temp\datC1A9.tmp
4.3s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\
4.4s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\148RGN2E\127.0.0[1].xml
4.6s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\
4.6s C:\Users\djamel eddine\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017010520170106\container.dat
6.5s C:\Windows\System32\config\systemprofile\AppData\Local\Avg\av16\temp\avg-f02f6e60-7c8c-4722-a612-62527bf89f3b.tmp
6.9s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\
6.9s C:\Users\djamel eddine\AppData\Local\Microsoft\Internet Explorer\DOMStore\25B09JQ4\ifbstore.appholly[1].xml
9.6s C:\Users\djamel eddine\AppData\Roaming\Microsoft\Windows\Cookies\U3AF8LI8.txt
9.7s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\
9.7s C:\Users\djamel eddine\AppData\Roaming\Adobe\Flash Player\AssetCache\C8QR34PD\
12.1s C:\Users\djamel eddine\AppData\Local\Temp\~DF03076106F4AB47D8.TMP
19.2s C:\Users\djamel eddine\AppData\Local\Temp\BCGFDDF.tmp

C:\Users\djamel eddine\Downloads\Programs\FRST.exe
Size . . . . . . . : 1 760 256 bytes
Age . . . . . . . : 1.0 days (2017-01-06 15:23:09)
Entropy . . . . . : 7.6
SHA-256 . . . . . : E34DCE488474F77F636B11B831F84512E3F73656A6D6FADAAA4DED8F2C22D34A
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.


Potential Unwanted Programs _________________________________________________

C:\Program Files\iRoot\ (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\ (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppCool.apk (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\ (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\116523_t01a2b3595fdb279415_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\163445_142248178f1_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\16950_143725eb9eb_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\16963_112853efb1e_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\171076_3df29142-fb66-4207-bd9c-b99a52fee708_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\197862_14394884920_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\206713_t0150bbd48f69acc2e1_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\20937_1139512cee9_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\2572_1427258e5ee_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\291215_093209d9d3e_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\3123_1430111d39c_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\321453_14381697a7e_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\473_142619ce3e7_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\475_14403823b3e_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\50861_1433225b780_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\522231_143623f2209_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\534_144119eeb2e_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\594285_1435053123e_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\602651_t01e60fba2b3b04e019_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\603152_143145e7c80_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\630001_11170652a4e_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\630002_111801b00c0_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\630003_111904cb58e_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\630004_112008f4b17_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\630005_113110a469f_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\630006_114453da5fb_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\6463_225040f5219_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\668_11423532187_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\6922_1435585415f_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppIcons\74250_14553292028_48.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppPhotos\ (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppPhotos\163445_1415482f7c4.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppPhotos\163445_1415552e8a4.jpg (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppPhotos\163445_141559bd9b1.jpg (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppPhotos\163445_141606ec3c6.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\AppPhotos\163445_1416117a1f1.png (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\Apps\ (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\Apps\com.supercleaner.apk (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\CleanMaster.apk (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\Download.mgy (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\globalconfig.mgy (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\kinguser.zip (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\onelocker.apk (iRoot) -> Deleted
C:\Users\djamel eddine\AppData\Roaming\mgyun\VRoot\RootRes.dll (iRoot) -> Deleted
Size . . . . . . . : 2 451 216 bytes
Age . . . . . . . : 53.1 days (2016-11-15 12:43:16)
Entropy . . . . . : 7.9
SHA-256 . . . . . : 9EDE3270F80148985BDF7DE87D879B80EAE91D89A0D23AA6DE09314FF5A4E670
Product . . . . . : Root'Y^
Publisher . . . . : ñm3WáOùXQÜ~ gP–lQøS
Description . . . : RootRes ¨R`þ”¥c“^
Version . . . . . : 1.0.9.21
RSA Key Size . . . : 2048
LanguageID . . . . : 2052
Authenticode . . . : Self-signed
Fuzzy . . . . . . : 14.0

HKLM\SOFTWARE\XinYi Network\VRoot\ (iRoot) -> Deleted
HKU\S-1-5-21-2930519674-3243175242-3379568120-1000\Software\XinYi Network\VRoot\ (iRoot) -> Deleted

Cookies _____________________________________________________________________

C:\Users\djamel eddine\AppData\Roaming\Microsoft\Windows\Cookies\8Z5Z72SX.txt
C:\Users\djamel eddine\AppData\Roaming\Microsoft\Windows\Cookies\CD4DJA0A.txt
C:\Users\djamel eddine\AppData\Roaming\Microsoft\Windows\Cookies\ZSEYFQC9.txt


[/code]

Publicité


Signaler le contenu de ce document

Publicité