Author Topic: I don't know what to remove ginger need helps ! ( a saoul to win )  (Read 4680 times)

0 Members and 1 Guest are viewing this topic.

May 13, 2015, 12:46:18 pm

Durix

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Please find below th report :

 RogueKiller V10.6.3.0 [May 11 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 8.1 (6.3.9200 ) 64 bits version
Démarré en  : Mode normal
Utilisateur : quentin [Administrateur]
Démarré depuis : C:\Users\quentin\Downloads\RogueKiller.exe
Mode : Scan -- Date : 05/13/2015  12:17:39

¤¤¤ Processus : 0 ¤¤¤

¤¤¤ Registre : 11 ¤¤¤
[Orphan] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}  -> Trouvé(e)
[Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}  -> Trouvé(e)
[Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> Trouvé(e)
[Orphan] (X64) HKEY_USERS\S-1-5-21-2835480536-3174729766-314767848-1002\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} :   -> Trouvé(e)
[Orphan] (X86) HKEY_USERS\S-1-5-21-2835480536-3174729766-314767848-1002\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} :   -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{F28504C9-D60C-422D-83F0-23F5B0A949FF} | DhcpNameServer : 172.168.0.2 [PAKISTAN (PK)]  -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{F28504C9-D60C-422D-83F0-23F5B0A949FF} | DhcpNameServer : 172.168.0.2 [PAKISTAN (PK)]  -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Trouvé(e)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Non chargé [0xc000036b]) ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] 5563ee86216a1c21e78cfa8297c1cea8
[BSP] 6a3125a7f090a24988d63ba5cae1a61d : Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 400 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 821248 | Size: 260 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1353728 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 1615872 | Size: 929086 MB
4 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1904384000 | Size: 450 MB
5 - [SYSTEM] Basic data partition | Offset (sectors): 1905305600 | Size: 23539 MB
User = LL1 ... OK
User = LL2 ... OK


Reply #1May 13, 2015, 12:48:55 pm

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2362
  • Reputation:
    82
    • View Profile
Hi Durix,

Welcome to Adlice.com Forum.

The report you posted was generated with the 32 bits version of RogueKiller.
Please download RogueKiller (64 bits version), redo a full scan and post the report obtained in your next reply.

Regards.

Reply #2May 13, 2015, 01:32:09 pm

Durix

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Hi,

I am back please find below the good report ! =)

RogueKiller V10.6.3.0 (x64) [May 11 2015] par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : http://www.adlice.com/fr/logiciels/roguekiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows 8.1 (6.3.9200 ) 64 bits version
Démarré en  : Mode normal
Utilisateur : quentin [Administrateur]
Démarré depuis : C:\Users\quentin\Downloads\RogueKillerX64 (1).exe
Mode : Scan -- Date : 05/13/2015  13:19:12

¤¤¤ Processus : 0 ¤¤¤

¤¤¤ Registre : 11 ¤¤¤
[Orphan] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}  -> Trouvé(e)
[Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}  -> Trouvé(e)
[Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> Trouvé(e)
[Orphan] (X64) HKEY_USERS\S-1-5-21-2835480536-3174729766-314767848-1002\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} :   -> Trouvé(e)
[Orphan] (X86) HKEY_USERS\S-1-5-21-2835480536-3174729766-314767848-1002\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} :   -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{F28504C9-D60C-422D-83F0-23F5B0A949FF} | DhcpNameServer : 172.168.0.2 [PAKISTAN (PK)]  -> Trouvé(e)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{F28504C9-D60C-422D-83F0-23F5B0A949FF} | DhcpNameServer : 172.168.0.2 [PAKISTAN (PK)]  -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Trouvé(e)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Trouvé(e)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Non chargé [0x20]) ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] 5563ee86216a1c21e78cfa8297c1cea8
[BSP] 6a3125a7f090a24988d63ba5cae1a61d : Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 400 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 821248 | Size: 260 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1353728 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 1615872 | Size: 929086 MB
4 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1904384000 | Size: 450 MB
5 - [SYSTEM] Basic data partition | Offset (sectors): 1905305600 | Size: 23539 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_SCN_05132015_121739.log

Reply #3May 15, 2015, 03:50:48 pm

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2362
  • Reputation:
    82
    • View Profile
Hi Durix,

Is your ISP located in Pakistan ?
Is the following key present in the registry ?
Quote
HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}

Regards.
« Last Edit: May 15, 2015, 04:47:14 pm by Curson »

Reply #4May 17, 2015, 05:37:31 pm

Durix

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Hi,

I don't really understand the question, I am living at Amsterdam for now and I am from France.
What is ISP ?

Reply #5May 19, 2015, 01:29:54 pm

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2362
  • Reputation:
    82
    • View Profile
Hi Durix,

ISP stands for Internet service provider.
Since you live in Amsterdam, your report is clean.  ;)

Regards.

Reply #6May 20, 2015, 01:39:02 pm

Durix

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
well well well thank you =)

Reply #7May 21, 2015, 12:32:15 am

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2362
  • Reputation:
    82
    • View Profile
Hi Durix,

You are very welcome.  :)

All the best.