cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

ÿþRogueKiller V12.9.1.0 (x64) [Jan 2 2017] (Premium) par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/download/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Démarré en : Mode normal
Utilisateur : Saad [Administrateur]
Démarré depuis : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 01/04/2017 21:20:08 (Durée : 00:29:12)

¤¤¤ Processus : 0 ¤¤¤

¤¤¤ Registre : 8 ¤¤¤
[Suspicious.Path] (X64) HKEY_CLASSES_ROOT\CLSID\{5F51FFFE-7463-4220-B711-E5B9ACB8EDFE} (C:\ProgramData\igfxDH.dll) -> Trouvé(e)
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks | {5F51FFFE-7463-4220-B711-E5B9ACB8EDFE} : (C:\ProgramData\igfxDH.dll) [x] -> Trouvé(e)
[Suspicious.Path|VT.Worm:Win32/Forbix.A] (X64) HKEY_USERS\S-1-5-21-808140718-620506771-1689824220-1000\Software\Microsoft\Windows\CurrentVersion\Run | SysinfY2X : C:\WINDOWS\system32\cmd.exe /c start wscript /e:VBScript.Encode %temp%\SysinfY2X.db [x][x][-] -> Trouvé(e)
[Suspicious.Path|VT.Worm:Win32/Forbix.A] (X86) HKEY_USERS\S-1-5-21-808140718-620506771-1689824220-1000\Software\Microsoft\Windows\CurrentVersion\Run | SysinfY2X : C:\WINDOWS\system32\cmd.exe /c start wscript /e:VBScript.Encode %temp%\SysinfY2X.db [x][x][-] -> Trouvé(e)
[PUM.SEH] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer | EnableShellExecuteHooks : 1 -> Trouvé(e)
[PUM.SEH] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer | EnableShellExecuteHooks : 1 -> Trouvé(e)
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-808140718-620506771-1689824220-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Trouvé(e)
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-808140718-620506771-1689824220-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Trouvé(e)

¤¤¤ Tâches : 1 ¤¤¤
[Suspicious.Path|VT.Trojan-Downloader.VBS.Agent.aja] \Origin -- C:\Users\Saad\AppData\Roaming\Origin\update.vbe -> Trouvé(e)

¤¤¤ Fichiers : 15 ¤¤¤
[Hj.Shortcut][Fichier] C:\Users\Saad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk [LNK@] C:\PROGRA~1\INTERN~1\iexplore.exe http://qtipr.com/ -> Trouvé(e)
[Hj.Shortcut][Fichier] C:\Users\Saad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [LNK@] C:\PROGRA~2\INTERN~1\iexplore.exe http://qtipr.com/ -> Trouvé(e)
[Hj.Shortcut][Fichier] C:\Users\Saad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [LNK@] C:\PROGRA~2\Google\Chrome\APPLIC~1\chrome.exe --load-extension="C:\Users\Saad\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" http://qtipr.com/ -> Trouvé(e)
[Hj.Shortcut][Fichier] C:\Users\Saad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [LNK@] C:\PROGRA~2\INTERN~1\iexplore.exe http://qtipr.com/ -> Trouvé(e)
[Hj.Shortcut][Fichier] C:\Users\Saad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk [LNK@] C:\PROGRA~2\Google\Chrome\APPLIC~1\chrome.exe --load-extension="C:\Users\Saad\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" http://qtipr.com/ -> Trouvé(e)
[Hj.Shortcut][Fichier] C:\Users\Saad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk [LNK@] C:\PROGRA~2\MOZILL~1\firefox.exe http://qtipr.com/ -> Trouvé(e)
[Hidden.ADS][Flux] C:\Windows\System32\drivers:ucdrv-x64.sys -> Trouvé(e)
[Ads.Generic|Hidden.ADS][Flux] C:\Windows\System32\drivers:x86 -> Trouvé(e)
[Tr.Gen0][Fichier] C:\Users\Saad\AppData\Roaming\uTorrent\updates\3.4.9_42606\utorrentie.exe -> Trouvé(e)
[Tr.Gen0][Fichier] C:\Users\Saad\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe -> Trouvé(e)
[Tr.Gen0][Fichier] C:\Users\Saad\AppData\Roaming\uTorrent\updates\3.4.9_43085\utorrentie.exe -> Trouvé(e)
[Hj.Shortcut][Fichier] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [LNK@] C:\PROGRA~2\Google\Chrome\APPLIC~1\chrome.exe --load-extension="C:\Users\Saad\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" http://qtipr.com/ -> Trouvé(e)
[Hj.Shortcut][Fichier] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [LNK@] C:\PROGRA~2\MOZILL~1\firefox.exe http://qtipr.com/ -> Trouvé(e)
[Hj.Shortcut][Fichier] C:\Users\Saad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk [LNK@] C:\PROGRA~1\INTERN~1\iexplore.exe http://qtipr.com/ -> Trouvé(e)
[Hj.Shortcut][Fichier] C:\Users\Saad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [LNK@] C:\PROGRA~2\INTERN~1\iexplore.exe http://qtipr.com/ -> Trouvé(e)

¤¤¤ WMI : 1 ¤¤¤
[PUP.Yeahbests] instance (ActiveScriptEventConsumer) \ROOT\subscription:ActiveScriptEventConsumer.Name="ASEC" -> Trouvé(e)

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: ST500LT012-1DG142 ATA Device +++++
--- User ---
[MBR] 37ede52468b37a610b4c80239530952a
[BSP] 6c1e0ccdf40ce1b2883146db8d7e1a1c : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] FAT32 (0xb) [VISIBLE] Offset (sectors): 2048 | Size: 7993 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 32741376 | Size: 200952 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 444291072 | Size: 260000 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK


Publicité


Signaler le contenu de ce document

Publicité