cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

RogueKiller V8.8.7 [Feb 11 2014] par Tigzy
mail : tigzyRKgmailcom
Remontees : http://forum.adlice.com
Site Web : http://www.sur-la-toile.com/RogueKiller/
Blog : http://www.adlice.com

Systeme d'exploitation : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Demarrage : Mode normal
Utilisateur : bernadette [Droits d'admin]
Mode : Recherche -- Date : 02/13/2014 18:39:21
| ARK || FAK || MBR |

¤¤¤ Processus malicieux : 0 ¤¤¤

¤¤¤ Entrees de registre : 12 ¤¤¤
[DNS][PUM] HKLM\[...]\CCSet\[...]\{5DE09E3B-16BF-4FB1-BFA9-BA1DC5A0CD84} : NameServer (8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 [UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - PHILIPPINES (PH) - UNITED STATES (US)]) -> TROUVÉ
[DNS][PUM] HKLM\[...]\CS001\[...]\{5DE09E3B-16BF-4FB1-BFA9-BA1DC5A0CD84} : NameServer (8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 [UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - PHILIPPINES (PH) - UNITED STATES (US)]) -> TROUVÉ
[DNS][PUM] HKLM\[...]\CS003\[...]\{5DE09E3B-16BF-4FB1-BFA9-BA1DC5A0CD84} : NameServer (8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 [UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - PHILIPPINES (PH) - UNITED STATES (US)]) -> TROUVÉ
[HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> TROUVÉ
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> TROUVÉ
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> TROUVÉ
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ

¤¤¤ Tâches planifiées : 0 ¤¤¤

¤¤¤ Entrées Startup : 0 ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Addons navigateur : 0 ¤¤¤

¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

¤¤¤ Driver : [CHARGE] ¤¤¤
[Inline] IAT @firefox.exe (GetModuleFileNameW) : KERNEL32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2930)
[Inline] IAT @firefox.exe (FreeLibrary) : KERNEL32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D29F0)
[Inline] IAT @firefox.exe (GetProcAddress) : KERNEL32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2A10)
[Inline] IAT @firefox.exe (LoadLibraryW) : KERNEL32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D28B0)
[Inline] IAT @firefox.exe (GetModuleHandleW) : KERNEL32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2970)
[Inline] IAT @firefox.exe (GetFileAttributesW) : KERNEL32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2430)
[Inline] IAT @firefox.exe (CreateFileW) : KERNEL32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D22B0)
[Inline] IAT @firefox.exe (CloseHandle) : KERNEL32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D24C0)
[Inline] IAT @firefox.exe (LoadLibraryExW) : KERNEL32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D28F0)
[Inline] EAT @firefox.exe (LdrLoadDll) : ntdll.dll -> HOOKED (C:\Program Files\Mozilla Firefox\mozglue.dll @ 0x6AE21FFD)
[Inline] EAT @firefox.exe (NtCreateFile) : ntdll.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697CD020)
[Inline] EAT @firefox.exe (NtOpenFile) : ntdll.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697CD040)
[Inline] EAT @firefox.exe (ZwCreateFile) : ntdll.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697CD020)
[Inline] EAT @firefox.exe (ZwOpenFile) : ntdll.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697CD040)
[Inline] EAT @firefox.exe (CloseHandle) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D24C0)
[Inline] EAT @firefox.exe (CopyFileA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D22D0)
[Inline] EAT @firefox.exe (CopyFileW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D22F0)
[Inline] EAT @firefox.exe (CreateFileA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2290)
[Inline] EAT @firefox.exe (CreateFileW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D22B0)
[Inline] EAT @firefox.exe (DeleteFileA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2390)
[Inline] EAT @firefox.exe (DeleteFileW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D23B0)
[Inline] EAT @firefox.exe (FindClose) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2FC0)
[Inline] EAT @firefox.exe (FindFirstFileA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2F00)
[Inline] EAT @firefox.exe (FindFirstFileExA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2F40)
[Inline] EAT @firefox.exe (FindFirstFileExW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2F60)
[Inline] EAT @firefox.exe (FindFirstFileW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2F20)
[Inline] EAT @firefox.exe (FindNextFileA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2F80)
[Inline] EAT @firefox.exe (FindNextFileW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2FA0)
[Inline] EAT @firefox.exe (FlushFileBuffers) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D24A0)
[Inline] EAT @firefox.exe (FreeLibrary) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D29F0)
[Inline] EAT @firefox.exe (GetFileAttributesA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2410)
[Inline] EAT @firefox.exe (GetFileAttributesExA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2450)
[Inline] EAT @firefox.exe (GetFileAttributesExW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2470)
[Inline] EAT @firefox.exe (GetFileAttributesW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2430)
[Inline] EAT @firefox.exe (GetModuleFileNameA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2910)
[Inline] EAT @firefox.exe (GetModuleFileNameW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2930)
[Inline] EAT @firefox.exe (GetModuleHandleA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2950)
[Inline] EAT @firefox.exe (GetModuleHandleExA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2990)
[Inline] EAT @firefox.exe (GetModuleHandleExW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D29C0)
[Inline] EAT @firefox.exe (GetModuleHandleW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2970)
[Inline] EAT @firefox.exe (GetProcAddress) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2A10)
[Inline] EAT @firefox.exe (LoadLibraryA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2890)
[Inline] EAT @firefox.exe (LoadLibraryExA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D28D0)
[Inline] EAT @firefox.exe (LoadLibraryExW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D28F0)
[Inline] EAT @firefox.exe (LoadLibraryW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D28B0)
[Inline] EAT @firefox.exe (MoveFileA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2310)
[Inline] EAT @firefox.exe (MoveFileExA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2350)
[Inline] EAT @firefox.exe (MoveFileExW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2370)
[Inline] EAT @firefox.exe (MoveFileW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2330)
[Inline] EAT @firefox.exe (OpenFile) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D2490)
[Inline] EAT @firefox.exe (ReplaceFile) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D23F0)
[Inline] EAT @firefox.exe (ReplaceFileA) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D23D0)
[Inline] EAT @firefox.exe (ReplaceFileW) : kernel32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x697D23F0)
[Inline] EAT @firefox.exe (CreateWindowExW) : USER32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x6979E350)
[Inline] EAT @firefox.exe (DestroyWindow) : USER32.dll -> HOOKED (C:\Program Files\Common Files\SpeedBit\SBUpdate\sbfi32.dll @ 0x6979E3B0)

¤¤¤ Ruches Externes: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ Fichier HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ MBR Verif: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Hitachi HTS543225L9A300 ATA Device +++++
--- User ---
[MBR] 4e41233979d897849d7a1ae27020ad7e
[BSP] dced40cec20388a1939b814156e5fc36 : Acer MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 10000 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 20482048 | Size: 114243 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 254451712 | Size: 114230 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Termine : << RKreport[0]_S_02132014_183921.txt >>





Publicité


Signaler le contenu de ce document

Publicité