Loaris trojan remover

Questions relatives à la sécurité de votre ordinateur sous Windows: résolution des problèmes liés aux virus, pare-feu, ...
breizhspotlight
Messages : 484
Enregistré le : dim. 25 sept. 2011 14:30
Etes vous un robot ? : Non
Localisation : Rennes, Bretagne, France

Re: Loaris trojan remover

Message par breizhspotlight »

Bonjour,

Excusez moi du terme, mais c'est une vraie merde ce truc, il détecte des éléments légitimes et les fait passer pour des menaces...

Regardez ce rapport :

Trojan Remover v.3.0.33
Report file date: 28/12/2017 11:36:44
Last update: --

Scanning for 238283 virus strains and unwanted programs.

Licensed: UNREGISTERED
Windows version: Windows 10 Pro x64 (version 6.3)
Username: Utilisateur
Computer name: CONFIGMATXCORSA
PC Brand: Gigabyte Technology Co., Ltd.

Starting the file scan:

Standard Scan started
Scanning process...
----- HKU\S-1-5-21-2641325022-1271978005-1310757773-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\akamaihd.net|akamaihd.net ---- Hijack Suspicious
Hijack.Edge.DOMStorage


----- HKU\S-1-5-21-2641325022-1271978005-1310757773-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\embedftv-a.akamaihd.net|embedftv-a.akamaihd.net ---- Hijack Suspicious
Hijack.Edge.DOMStorage


----- C:\Oem\AC\actual.exe ---- Task Suspicious
Task: [Actual Computer] Suspicious autostart
ProdVer: 1.0.0.0
FileVer: 1.0.0.0
Name: Lets4r.ActualComputer.Launcher.W8
Signature verification: False
.NET MVID: {0A5AA4B1-B35E-4B1E-850B-7032CB5D6674}
NAC: 051895802BFCBBEC4CA04F931F9AF200:33
MD5: CA131B226B5143298074188D0D826AB9:206336
RIC: 142524F655E3A6241C0850A3F4E4F049:97352
RFH: 1536:e9GJkGgcKKwvR+FcU3efO5GKLZd6UOZSRw6vpJ1ddQX5:e9GJkGlMo0Wr7BCa
SUBS: Win32 GUI
PE: x86
EP: FF25002040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
EPSEC: 0
EPRVA: 0001BB2E
IBASE: 00400000
SEC:
.text:60000020:DBCBCDA94C00A45B18FB4F7997EB3838:105472
.rsrc:40000040:289B4485ADCA33950378301C2D843F68:99840
.reloc:42000040:63DBCF53BBC2F3FEA55D79968DAB2785:512


----- "C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client" ---- Task Suspicious
Task: [UninstallSMB1ClientTask] Suspicious autostart
Arguments: -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client"


----- "C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server" ---- Task Suspicious
Task: [UninstallSMB1ServerTask] Suspicious autostart
Arguments: -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& %windir%\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server"


Scan completed

Scan result: 5 detected items
Scan completed in: Scan completed in 3 minute(s) 3 sec.
Files were scanned: 30965
C'est n'importe quoi...

@+
Image
En cas de problème constaté sur un sujet, contactez un modérateur par MP. N'intervenez pas vous-même. Merci
Image
Répondre