Bonjour Did80 !
Voici le rapport Roguekiller suite suppression :
RogueKiller V8.0.4 [19/09/2012] par Tigzy
mail: tigzyRK<at>gmail<dot>com
Remontees:
http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Blog:
http://tigzyrk.blogspot.com
Systeme d'exploitation: Windows 7 (6.1.7600 ) 32 bits version
Demarrage : Mode normal
Utilisateur : Laure [Droits d'admin]
Mode : Suppression -- Date : 21/09/2012 09:37:16
€€€ Processus malicieux : 0 €€€
€€€ Entrees de registre : 4 €€€
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REMPLACÉ (2)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REMPLACÉ (1)
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REMPLACÉ (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REMPLACÉ (0)
€€€ Fichiers / Dossiers particuliers: €€€
€€€ Driver : [CHARGE] €€€
SSDT[13] : NtAlertResumeThread @ 0x81CFA069 -> HOOKED (Unknown @ 0x8C9F5F90)
SSDT[14] : NtAlertThread @ 0x81CA7DC6 -> HOOKED (Unknown @ 0x8C9ED2C0)
SSDT[19] : NtAllocateVirtualMemory @ 0x81C6943B -> HOOKED (Unknown @ 0x8C9EDC38)
SSDT[22] : NtAlpcConnectPort @ 0x81C70E4D -> HOOKED (Unknown @ 0x8A8A7648)
SSDT[43] : NtAssignProcessToJobObject @ 0x81C14816 -> HOOKED (Unknown @ 0x8C9F56C8)
SSDT[74] : NtCreateMutant @ 0x81C9C2C3 -> HOOKED (Unknown @ 0x8C9F5CE0)
SSDT[86] : NtCreateSymbolicLinkObject @ 0x81C2C4BD -> HOOKED (Unknown @ 0x8C9F53E8)
SSDT[87] : NtCreateThread @ 0x81CF829A -> HOOKED (Unknown @ 0x8C9F48A8)
SSDT[88] : NtCreateThreadEx @ 0x81C56371 -> HOOKED (Unknown @ 0x8C9F54D8)
SSDT[96] : NtDebugActiveProcess @ 0x81CCD85A -> HOOKED (Unknown @ 0x8C9F57A8)
SSDT[111] : NtDuplicateObject @ 0x81C99770 -> HOOKED (Unknown @ 0x8C9F4570)
SSDT[131] : NtFreeVirtualMemory @ 0x81AD096D -> HOOKED (Unknown @ 0x8C9ED9F0)
SSDT[145] : NtImpersonateAnonymousToken @ 0x81C10048 -> HOOKED (Unknown @ 0x8C9F5DD0)
SSDT[147] : NtImpersonateThread @ 0x81C75CB3 -> HOOKED (Unknown @ 0x8C9F5EB0)
SSDT[155] : NtLoadDriver @ 0x81BBE313 -> HOOKED (Unknown @ 0x87DAB938)
SSDT[168] : NtMapViewOfSection @ 0x81C9C585 -> HOOKED (Unknown @ 0x8C9ED8F0)
SSDT[177] : NtOpenEvent @ 0x81C9EC15 -> HOOKED (Unknown @ 0x8C9F5C00)
SSDT[190] : NtOpenProcess @ 0x81C9EBDF -> HOOKED (Unknown @ 0x8C9F4750)
SSDT[191] : NtOpenProcessToken @ 0x81C59F11 -> HOOKED (Unknown @ 0x8C9F4490)
SSDT[194] : NtOpenSection @ 0x81C9C868 -> HOOKED (Unknown @ 0x8C9F5A40)
SSDT[198] : NtOpenThread @ 0x81C9D536 -> HOOKED (Unknown @ 0x8C9F4660)
SSDT[215] : NtProtectVirtualMemory @ 0x81C9D2EF -> HOOKED (Unknown @ 0x8C9F55D8)
SSDT[304] : NtResumeThread @ 0x81C8F67D -> HOOKED (Unknown @ 0x8C9ED3A0)
SSDT[316] : NtSetContextThread @ 0x81CF9B17 -> HOOKED (Unknown @ 0x8C9ED640)
SSDT[333] : NtSetInformationProcess @ 0x81C6AA35 -> HOOKED (Unknown @ 0x8C9ED720)
SSDT[350] : NtSetSystemInformation @ 0x81CA84A3 -> HOOKED (Unknown @ 0x8C9F58F8)
SSDT[366] : NtSuspendProcess @ 0x81CF9FA3 -> HOOKED (Unknown @ 0x8C9F5B20)
SSDT[367] : NtSuspendThread @ 0x81CB6D04 -> HOOKED (Unknown @ 0x8C9ED480)
SSDT[370] : NtTerminateProcess @ 0x81C7F1B5 -> HOOKED (Unknown @ 0x8C9F49A8)
SSDT[371] : NtTerminateThread @ 0x81C91F92 -> HOOKED (Unknown @ 0x8C9ED560)
SSDT[385] : NtUnmapViewOfSection @ 0x81C9938A -> HOOKED (Unknown @ 0x8C9ED810)
SSDT[399] : NtWriteVirtualMemory @ 0x81CA4C63 -> HOOKED (Unknown @ 0x8C9EDAE0)
S_SSDT[318] : Unknown -> HOOKED (Unknown @ 0x8CD02618)
S_SSDT[402] : Unknown -> HOOKED (Unknown @ 0x8A851AD8)
S_SSDT[434] : Unknown -> HOOKED (Unknown @ 0x8A851A18)
S_SSDT[436] : Unknown -> HOOKED (Unknown @ 0x8A896508)
S_SSDT[448] : Unknown -> HOOKED (Unknown @ 0x8CBBB3D8)
S_SSDT[490] : Unknown -> HOOKED (Unknown @ 0x8A85EFC0)
S_SSDT[508] : Unknown -> HOOKED (Unknown @ 0x8A851948)
S_SSDT[509] : Unknown -> HOOKED (Unknown @ 0x8A851878)
S_SSDT[585] : Unknown -> HOOKED (Unknown @ 0x8A850820)
S_SSDT[588] : Unknown -> HOOKED (Unknown @ 0x8A851BF8)
€€€ Infection : €€€
€€€ Fichier HOSTS: €€€
--> C:\Windows\system32\drivers\etc\hosts
€€€ MBR Verif: €€€
+++++ PhysicalDrive0: ST9250410AS +++++
--- User ---
[MBR] 746c1147545d393f07cbd86200d8e272
[BSP] 71e0ee929205644931e66c29945ee9a9 : Windows Vista/7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 220235 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 451450880 | Size: 17936 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 488183808 | Size: 103 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Termine : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Merci !
LLaw