Bonjour,
tout est dans le sujet ...
Ayant été précédemment invité à coller ici un autre log de RK, je me permets de récidiver sans demander l'autorisation ; on voudra bien me pardonner si la procédure n'est pas conforme aux usages du Forum.
Voici le log, et merci à celle ou celui qui voudra bien l'examiner :
RogueKiller V10.5.5.0 [Mar 16 2015] par Adlice Software
email :
http://www.adlice.com/contact/Remontées :
http://forum.adlice.comSite web :
http://www.adlice.com/fr/logiciels/roguekiller/Blog :
http://www.adlice.comSystème d'exploitation : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Démarré en : Mode normal
Utilisateur : xp [Administrateur]
Démarré depuis : C:\Documents and Settings\xp\Bureau\RogueKiller_001.exe
Mode : Scan -- Date : 03/16/2015 20:00:30
¤¤¤ Processus : 1 ¤¤¤
[Suspicious.Path] explorer.exe(2468) -- C:\Documents and Settings\xp\Application Data\Orange\OrangeInside\OIExt.dll[-] -> Déchargé(e)
¤¤¤ Registre : 12 ¤¤¤
[Suspicious.Path] HKEY_USERS\S-1-5-21-1202660629-879983540-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run | SanDiskSecureAccess_Manager.exe : :C:\Documents and Settings\xp\Application Data\SanDisk\SanDiskSecureAccess_Manager.exe -> Trouvé(e)
[Suspicious.Path] HKEY_USERS\S-1-5-21-1202660629-879983540-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run | orangeinside : :C:\Documents and Settings\xp\Application Data\Orange\OrangeInside\one\OrangeInside.exe -> Trouvé(e)
[Hidden.From.SCM] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FontCache3.0.0.0 (C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe) -> Trouvé(e)
[PUM.HomePage] HKEY_USERS\S-1-5-21-1202660629-879983540-1801674531-1003\Software\Microsoft\Internet Explorer\Main | Start Page :
http://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage_IE -> Trouvé(e)
[PUM.StartMenu] HKEY_USERS\RK_admin_ON_F_81ED\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Trouvé(e)
[PUM.StartMenu] HKEY_USERS\RK_JPL2_ON_F_2591\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Trouvé(e)
[PUM.StartMenu] HKEY_USERS\RK_TEMP_ON_F_F186\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Trouvé(e)
[PUM.StartMenu] HKEY_USERS\S-1-5-21-1202660629-879983540-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 0 -> Trouvé(e)
[PUM.DesktopIcons] HKEY_USERS\RK_JPL2_ON_F_2591\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\RK_Software_ON_F_0AD3\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\RK_Software_ON_F_0AD3\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Trouvé(e)
[PUM.DesktopIcons] HKEY_USERS\RK_JPL2_ON_F_2591\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Trouvé(e)
¤¤¤ Tâches : 0 ¤¤¤
¤¤¤ Fichiers : 0 ¤¤¤
¤¤¤ Fichier Hosts : 1 ¤¤¤
[C:\WINDOWS\system32\drivers\etc\hosts] 127.0.0.1 localhost
¤¤¤ Antirootkit : 9 (Driver: Chargé) ¤¤¤
[Filter(Kernel.Filter)] \Driver\atapi @ Unknown : \Driver\mrdd @ \Device\mrdd3 (sfhlp02.sys)
[Filter(Kernel.Filter)] \Driver\atapi @ Unknown : \Driver\mrdd @ \Device\mrdd2 (sfhlp02.sys)
[Filter(Kernel.Filter)] \Driver\atapi @ Unknown : \Driver\mrdd @ \Device\mrdd1 (sfhlp02.sys)
[Filter(Kernel.Filter)] \Driver\atapi @ Unknown : \Driver\mrdd @ \Device\mrdd0 (sfhlp02.sys)
[Filter(Kernel.Filter)] \Driver\Disk @ Unknown : \Driver\mrdd @ \Device\mrdd4 (sfhlp02.sys)
[Filter(Kernel.Filter)] \Driver\Disk @ Unknown : \Driver\mrdd @ \Device\mrdd3 (sfhlp02.sys)
[Filter(Kernel.Filter)] \Driver\Disk @ Unknown : \Driver\mrdd @ \Device\mrdd2 (sfhlp02.sys)
[Filter(Kernel.Filter)] \Driver\Disk @ Unknown : \Driver\mrdd @ \Device\mrdd1 (sfhlp02.sys)
[Filter(Kernel.Filter)] \Driver\Disk @ Unknown : \Driver\mrdd @ \Device\mrdd0 (sfhlp02.sys)
¤¤¤ Navigateurs web : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] 0ye9xuki.default-1361453917250 : user_pref("browser.startup.homepage", "
http://www.orange.fr/portail"); -> Trouvé(e)
¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD1003FZEX-00MK2A0 +++++
--- User ---
[MBR] 4c72690344133ee29a94b694abdf42cc
[BSP] 12d5baad53fbea101f305cbe9aa5b8fc : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 238466 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 488380416 | Size: 238466 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 976758784 | Size: 238466 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
3 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 1465137152 | Size: 238469 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: Samsung SSD 840 PRO Series +++++
--- User ---
[MBR] e9778272c4cd92a6f501be00db0184da
[BSP] 7fb4cba73a31958717deb39fa082ebcd : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 122102 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive2: WDC WD3000GLFS-01F8U0 +++++
--- User ---
[MBR] 39b612d0f79842821e8d2703d8784d95
[BSP] 1f074a2ff3f92dc274777fed7cec023e : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 149997 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 307194930 | Size: 136168 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive3: WDC WD6400AAKS-00A7B0 +++++
--- User ---
[MBR] b4c6f068fa1b325c696a384b033af526
[BSP] ba876e68135e4392cf6f2abf7110c88e : Empty MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 159998 MB [Windows XP Bootstrap | Windows XP Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 327677805 | Size: 159998 MB [Windows XP Bootstrap | Windows XP Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 655355610 | Size: 159998 MB [Windows XP Bootstrap | Windows XP Bootloader]
3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 983033415 | Size: 130481 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive4: WD My Book 1230 USB Device +++++
Error reading User MBR! ([57] Paramètre incorrect. )
Error reading LL1 MBR! ([79] Le délai de temporisation de sémaphore a expiré. )
Error reading LL2 MBR! ([32] Cette demande n'est pas prise en charge. )