Author Topic: Needing some help  (Read 6623 times)

0 Members and 1 Guest are viewing this topic.

August 20, 2014, 12:45:36 AM

sebus

  • Guest
Needing some help
« on: August 20, 2014, 12:45:36 AM »
Hello everybody, and sorry for my English, I am French.

Well, just would like some help to analyse the report of Rogue Killer on my machine (Windows 7) and to know if you think I should delete some elements or not.
Thanks a lot, and wish you a nice day (I'll not hesitate to help in the future if I am able too).


Here the report, but sorry for the French words (I have a French version of Rogue), perhaps you'll just need to know that "TROUVÉ" means "FOUND" , "Tâches planifiées" means "planned tasks", "FICHIER" means "FILE", and "Processus malicieux" means "malicious process":

RogueKiller V9.2.8.0 (x64) [Jul 11 2014] par Adlice Software
Mail : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site Web : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Démarrage : Mode normal
Utilisateur : siming [Droits d'admin]
Mode : Recherche -- Date : 08/20/2014  00:20:29

¤¤¤ Processus malicieux : 0 ¤¤¤

¤¤¤ Entrées de registre : 28 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SASDIFSV -> TROUVÉ
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SASKUTIL -> TROUVÉ
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SASDIFSV -> TROUVÉ
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SASKUTIL -> TROUVÉ
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SASDIFSV -> TROUVÉ
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SASKUTIL -> TROUVÉ
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-705172274-1562741512-3896502494-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0  -> TROUVÉ
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-705172274-1562741512-3896502494-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0  -> TROUVÉ
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-705172274-1562741512-3896502494-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> TROUVÉ
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-705172274-1562741512-3896502494-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> TROUVÉ
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-705172274-1562741512-3896502494-500\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> TROUVÉ
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-705172274-1562741512-3896502494-500\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> TROUVÉ
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> TROUVÉ
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> TROUVÉ
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-705172274-1562741512-3896502494-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> TROUVÉ
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-705172274-1562741512-3896502494-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> TROUVÉ
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-705172274-1562741512-3896502494-500\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> TROUVÉ
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-705172274-1562741512-3896502494-500\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> TROUVÉ
[PUM.HomePage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : about:blank  -> TROUVÉ
[PUM.HomePage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : about:blank  -> TROUVÉ
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-705172274-1562741512-3896502494-1000\Software\Microsoft\Internet Explorer\Main | Start Page : about:blank  -> TROUVÉ
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-705172274-1562741512-3896502494-1000\Software\Microsoft\Internet Explorer\Main | Start Page : about:blank  -> TROUVÉ
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : about:blank  -> TROUVÉ
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : about:blank  -> TROUVÉ
[PUM.SearchPage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : about:blank  -> TROUVÉ
[PUM.SearchPage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : about:blank  -> TROUVÉ
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : about:blank  -> TROUVÉ
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : about:blank  -> TROUVÉ

¤¤¤ Tâches planifiées : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier HOSTS : 0 [Too big!] ¤¤¤

¤¤¤ Antirootkit : 1 (Driver: CHARGE) ¤¤¤
[Filter(Root.Keylogger)] \Driver\kbdclass @ \Device\KeyboardClass1 : \Driver\vmkbd @ Unknown (\SystemRoot\system32\DRIVERS\kbdhid.sys)

¤¤¤ Navigateurs web : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] 13huvt7l.default : user_pref("browser.startup.homepage", "http://www.google.fr"); -> TROUVÉ

¤¤¤ MBR Verif : ¤¤¤
+++++ PhysicalDrive0: Hitachi HDS721075CLA332 ATA Device +++++
--- User ---
[MBR] 20297782118df29163d4af0697a3b13a
[BSP] dcb9fa25f13fa570a20aa8451a5d6600 : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 510 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 1048576 | Size: 714892 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: Packard Bell Carbon USB Device +++++
--- User ---
[MBR] b62559f46143df9f267432bf617f61f8
[BSP] 4f4c9f53887ddd41321453638a41e9dc : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 953867 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )

+++++ PhysicalDrive2: WD Ext HDD 1021 USB Device +++++
Error reading User MBR! ([57] Paramètre incorrect. )
Error reading LL1 MBR! ([79] Le délai de temporisation de sémaphore a expiré. )
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )

+++++ PhysicalDrive3: Multi Flash Reader USB Device +++++
Error reading User MBR! ([15] Le périphérique n?est pas prêt. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )

« Last Edit: August 20, 2014, 12:51:22 AM by sebus »

Reply #1August 20, 2014, 08:23:12 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 956
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Needing some help
« Reply #1 on: August 20, 2014, 08:23:12 AM »
Hello
No need to remove anything.
Some are just false detections, and a lot of them are PUMs

Reply #2August 31, 2014, 06:23:47 PM

siming

  • Guest
Re: Needing some help
« Reply #2 on: August 31, 2014, 06:23:47 PM »
Hello,

Sorry for the delay, just wanted to thank you for your help.
Have a nice day.

Regards.

Sebastien