Author Topic: Pour instructions de désinfection  (Read 6286 times)

0 Members and 1 Guest are viewing this topic.

March 15, 2015, 01:59:06 PM

Procyon

  • Newbie

  • Offline
  • *

  • 5
  • Reputation:
    0
    • View Profile
Pour instructions de désinfection
« on: March 15, 2015, 01:59:06 PM »
Bonjour,
Tout est dans le sujet.
Je me permets de joindre le rapport obtenu
Merci beaucoup de me dire si je dois retirer les 3 lignes en rouge qui figurent dans le résultat.
Cordialement.

Reply #1March 16, 2015, 10:58:06 AM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Pour instructions de désinfection
« Reply #1 on: March 16, 2015, 10:58:06 AM »
Bonjour Procyon,

Bienvenue sur le forum Adlice.
Peux-tu refaire un scan avec la version 64-Bits de RogueKiller et copier/coller l'intégralité du rapport obtenu dans ta prochaine réponse ?

Meilleures salutations.

Reply #2March 16, 2015, 01:06:41 PM

Procyon

  • Newbie

  • Offline
  • *

  • 5
  • Reputation:
    0
    • View Profile
Re: Pour instructions de désinfection
« Reply #2 on: March 16, 2015, 01:06:41 PM »
Hello Curson, merci ...
Voici le rapport.
RogueKiller V10.5.5.0 (x64) [Mar 16 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Démarré en  : Mode normal
Utilisateur : JPL2 [Administrateur]
Démarré depuis : C:\Users\JPL2\Desktop\RogueKillerX64.exe
Mode : Scan -- Date : 03/16/2015  12:57:37

¤¤¤ Processus : 1 ¤¤¤
[Suspicious.Path] LOGI_MWX.EXE(3792) -- C:\Windows\LOGI_MWX.EXE[7] -> Tué(e) [TermProc]

¤¤¤ Registre : 29 ¤¤¤
[Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Logitech Utility : LOGI_MWX.EXE  -> Trouvé(e)
[Hj.Name] (X64) HKEY_USERS\RK_Default_ON_G_0B40\Software\Microsoft\Windows\CurrentVersion\RunOnce | mctadmin : C:\Windows\System32\mctadmin.exe  -> Trouvé(e)
[Hj.Name] (X86) HKEY_USERS\RK_Default_ON_G_0B40\Software\Microsoft\Windows\CurrentVersion\RunOnce | mctadmin : C:\Windows\System32\mctadmin.exe  -> Trouvé(e)
[PUM.HomePage] (X64) HKEY_USERS\RK_xp_ON_D_4531\Software\Microsoft\Internet Explorer\Main | Start Page : http://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage_IE  -> Trouvé(e)
[PUM.HomePage] (X86) HKEY_USERS\RK_xp_ON_D_4531\Software\Microsoft\Internet Explorer\Main | Start Page : http://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage_IE  -> Trouvé(e)
[PUM.StartMenu] (X64) HKEY_USERS\RK_admin_ON_G_8B8B\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Trouvé(e)
[PUM.StartMenu] (X86) HKEY_USERS\RK_admin_ON_G_8B8B\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Trouvé(e)
[PUM.StartMenu] (X64) HKEY_USERS\RK_TEMP_ON_G_8918\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Trouvé(e)
[PUM.StartMenu] (X86) HKEY_USERS\RK_TEMP_ON_G_8918\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Trouvé(e)
[PUM.StartMenu] (X64) HKEY_USERS\RK_xp_ON_D_4531\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 0  -> Trouvé(e)
[PUM.StartMenu] (X86) HKEY_USERS\RK_xp_ON_D_4531\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 0  -> Trouvé(e)
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1010\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Trouvé(e)
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1010\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Trouvé(e)
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1010-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Trouvé(e)
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1010-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Trouvé(e)
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1011.bak-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Trouvé(e)
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1011.bak-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1010\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1010\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1010-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1010-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1010\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1010\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1010-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-1734120708-240435509-2856458109-1010-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤

¤¤¤ Navigateurs web : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] z4u3mjfr.default : user_pref("browser.startup.homepage", "https://www.orange.fr/portail"); -> Trouvé(e)

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: Samsung SSD 840 PRO Series ATA Device +++++
--- User ---
[MBR] e9778272c4cd92a6f501be00db0184da
[BSP] 7fb4cba73a31958717deb39fa082ebcd : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 122102 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD3000GLFS-01F8U0 ATA Device +++++
--- User ---
[MBR] 39b612d0f79842821e8d2703d8784d95
[BSP] 1f074a2ff3f92dc274777fed7cec023e : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 149997 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 307194930 | Size: 136168 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: WDC WD1003FZEX-00MK2A0 ATA Device +++++
--- User ---
[MBR] 4c72690344133ee29a94b694abdf42cc
[BSP] 12d5baad53fbea101f305cbe9aa5b8fc : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 238466 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 488380416 | Size: 238466 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 976758784 | Size: 238466 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
3 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 1465137152 | Size: 238469 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive3: WDC WD6400AAKS-00A7B0 ATA Device +++++
--- User ---
[MBR] b4c6f068fa1b325c696a384b033af526
[BSP] ba876e68135e4392cf6f2abf7110c88e : Empty MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 159998 MB [Windows XP Bootstrap | Windows XP Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 327677805 | Size: 159998 MB [Windows XP Bootstrap | Windows XP Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 655355610 | Size: 159998 MB [Windows XP Bootstrap | Windows XP Bootloader]
3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 983033415 | Size: 130481 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive4: WD My Book 1230 USB Device +++++
Error reading User MBR! ([57] Paramètre incorrect. )
Error reading LL1 MBR! ([79] Le délai de temporisation de sémaphore a expiré. )
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )


============================================
RKreport_SCN_03152015_131620.log

Reply #3March 16, 2015, 06:57:16 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Pour instructions de désinfection
« Reply #3 on: March 16, 2015, 06:57:16 PM »
Bonsoir Procyon,

Ton rapport ne révèle aucun élément malicieux.

Meilleures salutations.

Reply #4March 16, 2015, 07:11:01 PM

Procyon

  • Newbie

  • Offline
  • *

  • 5
  • Reputation:
    0
    • View Profile
Re: Pour instructions de désinfection
« Reply #4 on: March 16, 2015, 07:11:01 PM »
Merci infiniment, Curson, pour ton aide précieuse.

Reply #5March 16, 2015, 07:20:42 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Pour instructions de désinfection
« Reply #5 on: March 16, 2015, 07:20:42 PM »
Bonsoir Procyon,

Au plaisir. :)