Author Topic: What should I do ?  (Read 7733 times)

0 Members and 1 Guest are viewing this topic.

January 07, 2015, 11:21:31 AM

flemanour

  • Newbie

  • Offline
  • *

  • 2
  • Reputation:
    0
    • View Profile
What should I do ?
« on: January 07, 2015, 11:21:31 AM »
Hello everyone !

Since monday I have a problem with my laptop on windows 8. Everything is very slow and the screen become white sometimes. I download the soft Roguekiller and did the analysis, find below the report :
RogueKiller V10.1.2.0 (x64) [Jan  7 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 8 (6.2.9200 ) 64 bits version
Démarré en  : Mode normal
Utilisateur : FLM [Administrateur]
Mode : Scan -- Date : 01/07/2015  10:54:12

¤¤¤ Processus : 2 ¤¤¤
[Suspicious.Path] nsq488.exe(4324) -- C:\ProgramData\nsq488.exe[-] -> Tué(e) [TermProc]
[Suspicious.Path] explorer.exe(4464) -- C:\Users\FLM.DOMMCA\AppData\Local\StartIsBack\StartIsBack64.dll[-] -> Déchargé(e)

¤¤¤ Registre : 13 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1231615023-3716862040-4185394283-1297\Software\Microsoft\Windows\CurrentVersion\Run | prefs : C:\ProgramData\nsq488.exe  -> Trouvé(e)
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1231615023-3716862040-4185394283-1297\Software\Microsoft\Windows\CurrentVersion\Run | prefs : C:\ProgramData\nsq488.exe  -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{99160B0F-C4B5-414B-9883-D818F8A5DB4C} | DhcpNameServer : 13.36.0.102 [UNITED STATES (US)]  -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{AEBA87E5-00CB-4A67-9771-6BFEC8F90A84} | DhcpNameServer : 172.20.10.1 [(Private Address) (XX)]  -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{99160B0F-C4B5-414B-9883-D818F8A5DB4C} | DhcpNameServer : 13.36.0.102 [UNITED STATES (US)]  -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{AEBA87E5-00CB-4A67-9771-6BFEC8F90A84} | DhcpNameServer : 172.20.10.1 [(Private Address) (XX)]  -> Trouvé(e)
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-1231615023-3716862040-4185394283-1297\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Trouvé(e)
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-1231615023-3716862040-4185394283-1297\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Trouvé(e)
[HJ.FileAsso] (X64) HKEY_CLASSES_ROOT\pezfile\shell\open\command | (default) : "C:\Program Files (x86)\Prezi\Prezi.exe" "%1"  -> Trouvé(e)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: LITEONIT LMT-256M3M mSATA 256GB +++++
--- User ---
[MBR] 0c2832d9cbd8af4d8a2eb23e85adfac0
[BSP] 77f3d1a676b0abaa586f63e719e2a467 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097152 MB
User = LL1 ... OK
User = LL2 ... OK

What should I do, thanks in advance for your help.

Reply #1January 07, 2015, 02:04:11 PM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: What should I do ?
« Reply #1 on: January 07, 2015, 02:04:11 PM »
Hello
remove everything. Even PUM entries.

Reply #2January 07, 2015, 05:01:35 PM

flemanour

  • Newbie

  • Offline
  • *

  • 2
  • Reputation:
    0
    • View Profile
Re: What should I do ?
« Reply #2 on: January 07, 2015, 05:01:35 PM »
Thank you very much for your help but the problem is still on my computer ... see below a new report :
RogueKiller V10.1.2.0 (x64) [Jan  7 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 8 (6.2.9200 ) 64 bits version
Démarré en  : Mode normal
Utilisateur : FLM [Administrateur]
Mode : Scan -- Date : 01/07/2015  16:58:23

¤¤¤ Processus : 1 ¤¤¤
[Suspicious.Path] explorer.exe(4668) -- C:\Users\FLM.DOMMCA\AppData\Local\StartIsBack\StartIsBack64.dll[-] -> Déchargé(e)

¤¤¤ Registre : 0 ¤¤¤

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: LITEONIT LMT-256M3M mSATA 256GB +++++
--- User ---
[MBR] 0c2832d9cbd8af4d8a2eb23e85adfac0
[BSP] 77f3d1a676b0abaa586f63e719e2a467 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097152 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_DEL_01072015_135128.log - RKreport_DEL_01072015_143028.log - RKreport_SCN_01072015_105412.log - RKreport_SCN_01072015_140744.log
RKreport_SCN_01072015_162153.log - RKreport_SCN_01072015_162524.log - RKreport_SCN_01072015_163055.log


Is there somethning else I can do ?


Reply #3January 08, 2015, 04:39:19 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: What should I do ?
« Reply #3 on: January 08, 2015, 04:39:19 PM »
Hello flemanour,
Quote
[Suspicious.Path] explorer.exe(4668) -- C:\Users\FLM.DOMMCA\AppData\Local\StartIsBack\StartIsBack64.dll[-] -> Déchargé(e)
This module is legit. It is related to StartIsBack software.

Are the problems you described on your first post still present ?

Regards.