RogueKiller V12.11.26.0 (x64) [Nov 27 2017] (Gratuit) par Adlice Software email : http://www.adlice.com/fr/contact/ Remontées : https://forum.adlice.com Site web : http://www.adlice.com/fr/download/roguekiller/ Blog : http://www.adlice.com/fr/ Système d'exploitation : Windows 10 (10.0.16299) 64 bits version Démarré en : Mode normal Utilisateur : famille Goeusse [Administrateur] Démarré depuis : C:\Program Files\RogueKiller\RogueKiller64.exe Mode : Scan -- Date : 12/04/2017 08:51:52 (Durée : 01:11:47) ¤¤¤ Processus : 0 ¤¤¤ ¤¤¤ Registre : 13 ¤¤¤ [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\esihdrv (\??\C:\Users\FAMILL~1\AppData\Local\Temp\esihdrv.sys) -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {8E67A183-2D92-40BB-A54C-6438678A36D2} : v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\famille Goeusse\AppData\Local\Temp\7zS58FD\HPDiagnosticCoreUI.exe|Name=HPSAPS| [x] -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {0FE5D9AF-2497-4988-AC61-413ABB8F279D} : v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\famille Goeusse\AppData\Local\Temp\7zS58FD\HPDiagnosticCoreUI.exe|Name=HPSAPS| [x] -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {6EABC72A-37AE-447B-8616-258FF42BDB12} : v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\famille Goeusse\AppData\Local\Temp\7zS59B4\HPDiagnosticCoreUI.exe|Name=HPSAPS| [x] -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {80BF3BE0-195C-4A65-B9FE-B32769E25A94} : v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\famille Goeusse\AppData\Local\Temp\7zS59B4\HPDiagnosticCoreUI.exe|Name=HPSAPS| [x] -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {A60118EE-247F-474A-A83B-00309756DBFE} : v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\famille Goeusse\AppData\Local\Temp\7zS7CAA\HPDiagnosticCoreUI.exe|Name=HPSAPS| [x] -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {24A02CA8-9319-4ABA-99DB-AF8872355D3C} : v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\famille Goeusse\AppData\Local\Temp\7zS7CAA\HPDiagnosticCoreUI.exe|Name=HPSAPS| [x] -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {A504EEC9-EECB-4A74-AC6B-BF1F354956B1} : v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\famille Goeusse\AppData\Local\Temp\7zS0BAA\HPDiagnosticCoreUI.exe|Name=HPSAPS| [x] -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {028521B3-6CC1-4113-B8D6-4D3EC0356798} : v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\famille Goeusse\AppData\Local\Temp\7zS0BAA\HPDiagnosticCoreUI.exe|Name=HPSAPS| [x] -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {F419F7C7-31ED-4830-B89A-4F7F5C4C1895} : v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\famille Goeusse\AppData\Local\Temp\7zS1E08\HPDiagnosticCoreUI.exe|Name=HPSAPS| [x] -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {4676C879-23EC-4C17-8529-8EE724BD4E8C} : v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\famille Goeusse\AppData\Local\Temp\7zS1E08\HPDiagnosticCoreUI.exe|Name=HPSAPS| [x] -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {E8E37D02-0511-452B-8105-D9CAC26855B2} : v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\famille Goeusse\AppData\Local\Temp\7zS6F43\HPDiagnosticCoreUI.exe|Name=HPSAPS| [x] -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {5BAA473D-4752-40D2-B4A4-34E15B18326D} : v2.27|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\famille Goeusse\AppData\Local\Temp\7zS6F43\HPDiagnosticCoreUI.exe|Name=HPSAPS| [x] -> Trouvé(e) ¤¤¤ Tâches : 0 ¤¤¤ ¤¤¤ Fichiers : 0 ¤¤¤ ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Fichier Hosts : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤ ¤¤¤ Navigateurs web : 0 ¤¤¤ ¤¤¤ Vérification MBR : ¤¤¤ +++++ PhysicalDrive0: WDC WD1001FAES-60Z2A0 +++++ --- User --- [MBR] 98ca6ef3efaa0b12519c6302911fdb3a [BSP] d4c71704035b2713ef028f9127f25e37 : HP MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 940526 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1927325696 | Size: 12791 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK User = LL2 ... OK +++++ PhysicalDrive1: Generic- SD/MMC USB Device +++++ Error reading User MBR! ([15] Le périphérique n?est pas prêt. ) Error reading LL1 MBR! NOT VALID! Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. ) +++++ PhysicalDrive2: Generic- Compact Flash USB Device +++++ Error reading User MBR! ([15] Le périphérique n?est pas prêt. ) Error reading LL1 MBR! NOT VALID! Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. ) +++++ PhysicalDrive3: Generic- SM/xD-Picture USB Device +++++ Error reading User MBR! ([15] Le périphérique n?est pas prêt. ) Error reading LL1 MBR! NOT VALID! Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. ) +++++ PhysicalDrive4: Generic- MS/MS-Pro USB Device +++++ Error reading User MBR! ([15] Le périphérique n?est pas prêt. ) Error reading LL1 MBR! NOT VALID! Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )