Bonsoir Gabriel (même prénom que mon loupiot !!),
j'ai fait comme tu me disais mais après la suppression j'ai refait un scan parce que je ne trouvais pas le rapport. Donc je te poste 2 rapports, avant et après la suppression. Merci.
RogueKiller V8.6.4 [Jul 29 2013] par Tigzy
mail : tigzyRKgmailcom
Remontees :
http://www.adlice.com/forum/
Site Web :
http://www.sur-la-toile.com/RogueKiller/
Blog :
http://tigzyrk.blogspot.com/
Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Demarrage : Mode normal
Utilisateur : Ordi [Droits d'admin]
Mode : Suppression -- Date : 08/01/2013 20:37:46
| ARK || FAK || MBR |
€€€ Processus malicieux : 0 €€€
€€€ Entrees de registre : 10 €€€
[RUN][SUSP PATH] HKCU\[...]\Run : SSync ("C:\Users\Ordi\AppData\Roaming\SSync\SSync.exe" [-]) - SUPPRIMÉ
[RUN][SUSP PATH] HKCU\[...]\Run : DataMgr ("C:\Users\Ordi\AppData\Roaming\DataMgr\DataMgr.exe" [-]) - SUPPRIMÉ
[RUN][SUSP PATH] HKCU\[...]\Run : SCheck ("C:\Users\Ordi\AppData\Roaming\SCheck\SCheck.exe" check [-]) - SUPPRIMÉ
[RUN][SUSP PATH] HKCU\[...]\Run : Intermediate ("C:\Users\Ordi\AppData\Roaming\Intermediate\Intermediate.exe" [-]) - SUPPRIMÉ
[RUN][SUSP PATH] HKUS\S-1-5-21-1250087251-3262539119-1891612278-1000\[...]\Run : SSync ("C:\Users\Ordi\AppData\Roaming\SSync\SSync.exe" [-]) - [0x2] Le fichier spécifié est introuvable.
[RUN][SUSP PATH] HKUS\S-1-5-21-1250087251-3262539119-1891612278-1000\[...]\Run : DataMgr ("C:\Users\Ordi\AppData\Roaming\DataMgr\DataMgr.exe" [-]) - [0x2] Le fichier spécifié est introuvable.
[RUN][SUSP PATH] HKUS\S-1-5-21-1250087251-3262539119-1891612278-1000\[...]\Run : SCheck ("C:\Users\Ordi\AppData\Roaming\SCheck\SCheck.exe" check [-]) - [0x2] Le fichier spécifié est introuvable.
[RUN][SUSP PATH] HKUS\S-1-5-21-1250087251-3262539119-1891612278-1000\[...]\Run : Intermediate ("C:\Users\Ordi\AppData\Roaming\Intermediate\Intermediate.exe" [-]) - [0x2] Le fichier spécifié est introuvable.
[HJ DESK] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) - REMPLACÉ (0)
[HJ DESK] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) - REMPLACÉ (0)
€€€ Tâches planifiées : 0 €€€
€€€ Entrées Startup : 0 €€€
€€€ Navigateurs web : 0 €€€
€€€ Fichiers / Dossiers particuliers: €€€
€€€ Driver : [CHARGE] €€€
[Address] SSDT[84] : NtCreateSection @ 0x8306804D - HOOKED (Unknown @ 0x90AAF84E)
[Address] SSDT[299] : NtRequestWaitReplyPort @ 0x83082A43 - HOOKED (Unknown @ 0x90AAF858)
[Address] SSDT[316] : NtSetContextThread @ 0x83122755 - HOOKED (Unknown @ 0x90AAF853)
[Address] SSDT[347] : NtSetSecurityObject @ 0x8304671E - HOOKED (Unknown @ 0x90AAF85D)
[Address] SSDT[368] : NtSystemDebugControl @ 0x830CA6BC - HOOKED (Unknown @ 0x90AAF862)
[Address] SSDT[370] : NtTerminateProcess @ 0x8309FBCD - HOOKED (Unknown @ 0x90AAF7EF)
[Address] Shadow SSDT[585] : NtUserSetWindowsHookEx - HOOKED (Unknown @ 0x90AAF876)
[Address] Shadow SSDT[588] : NtUserSetWinEventHook - HOOKED (Unknown @ 0x90AAF87B)
[Address] IRP[IRP_MJ_CREATE] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
[Address] IRP[IRP_MJ_CLOSE] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
[Address] IRP[IRP_MJ_DEVICE_CONTROL] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
[Address] IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
[Address] IRP[IRP_MJ_POWER] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
[Address] IRP[IRP_MJ_SYSTEM_CONTROL] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
[Address] IRP[IRP_MJ_PNP] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
€€€ Ruches Externes: €€€
€€€ Infection : €€€
€€€ Fichier HOSTS: €€€
-- %SystemRoot%\System32\drivers\etc\hosts
€€€ MBR Verif: €€€
+++++ PhysicalDrive0: ST2000DM001-1CH164 ATA Device +++++
--- User ---
[MBR] 0086f36f0b7bc8b257f89fc226376c3d
[BSP] 9e3b3c473b1db0daa516427cdae6e1cc : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097151 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: ST2000DM001-1CH164 ATA Device +++++
--- User ---
[MBR] cf464959265be5fd3a779b9471d55b32
[BSP] 996eaf4934c38edb819361d3a262ede6 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 10001 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 20482875 | Size: 66307 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive2: ST2000DM001-1CH164 ATA Device +++++
--- User ---
[MBR] a77dfce52993a32b336340adade86097
[BSP] 3bfeecd26998e7176276ecc5a42696b6 : Linux MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 104970 Mo
2 - [XXXXXX] EXTEN (0x05) [VISIBLE] Offset (sectors): 215187454 | Size: 371867 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive3: ST2000DM001-1CH164 ATA Device +++++
--- User ---
[MBR] 0e4c9ddc2e115b00c9b32fe0a026e1be
[BSP] b90a771ee7f8e60cc019b021fe71ec3c : MBR Code unknown
Partition table:
0 - [XXXXXX] FAT16-LBA (0x0e) [VISIBLE] Offset (sectors): 8064 | Size: 1896 Mo
User = LL1 ... OK!
Error reading LL2 MBR!
Termine :
RKreport[0]_S_07312013_220609.txt;RKreport[0]_S_08012013_203737.txt
Rapport second après suppression :
RogueKiller V8.6.4 [Jul 29 2013] par Tigzy
mail : tigzyRKgmailcom
Remontees :
http://www.adlice.com/forum/
Site Web :
http://www.sur-la-toile.com/RogueKiller/
Blog :
http://tigzyrk.blogspot.com/
Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Demarrage : Mode normal
Utilisateur : Ordi [Droits d'admin]
Mode : Recherche -- Date : 08/01/2013 20:40:48
| ARK || FAK || MBR |
€€€ Processus malicieux : 0 €€€
€€€ Entrees de registre : 0 €€€
€€€ Tâches planifiées : 0 €€€
€€€ Entrées Startup : 0 €€€
€€€ Navigateurs web : 0 €€€
€€€ Fichiers / Dossiers particuliers: €€€
€€€ Driver : [CHARGE] €€€
[Address] SSDT[84] : NtCreateSection @ 0x8306804D - HOOKED (Unknown @ 0x90AAF84E)
[Address] SSDT[299] : NtRequestWaitReplyPort @ 0x83082A43 - HOOKED (Unknown @ 0x90AAF858)
[Address] SSDT[316] : NtSetContextThread @ 0x83122755 - HOOKED (Unknown @ 0x90AAF853)
[Address] SSDT[347] : NtSetSecurityObject @ 0x8304671E - HOOKED (Unknown @ 0x90AAF85D)
[Address] SSDT[368] : NtSystemDebugControl @ 0x830CA6BC - HOOKED (Unknown @ 0x90AAF862)
[Address] SSDT[370] : NtTerminateProcess @ 0x8309FBCD - HOOKED (Unknown @ 0x90AAF7EF)
[Address] Shadow SSDT[585] : NtUserSetWindowsHookEx - HOOKED (Unknown @ 0x90AAF876)
[Address] Shadow SSDT[588] : NtUserSetWinEventHook - HOOKED (Unknown @ 0x90AAF87B)
[Address] IRP[IRP_MJ_CREATE] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
[Address] IRP[IRP_MJ_CLOSE] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
[Address] IRP[IRP_MJ_DEVICE_CONTROL] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
[Address] IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
[Address] IRP[IRP_MJ_POWER] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
[Address] IRP[IRP_MJ_SYSTEM_CONTROL] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
[Address] IRP[IRP_MJ_PNP] : C:\Windows\System32\drivers\mountmgr.sys - HOOKED ([Address] Unknown @ 0x854EA1E8)
€€€ Ruches Externes: €€€
€€€ Infection : €€€
€€€ Fichier HOSTS: €€€
-- %SystemRoot%\System32\drivers\etc\hosts
€€€ MBR Verif: €€€
+++++ PhysicalDrive0: ST2000DM001-1CH164 ATA Device +++++
--- User ---
[MBR] 0086f36f0b7bc8b257f89fc226376c3d
[BSP] 9e3b3c473b1db0daa516427cdae6e1cc : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097151 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: ST2000DM001-1CH164 ATA Device +++++
--- User ---
[MBR] cf464959265be5fd3a779b9471d55b32
[BSP] 996eaf4934c38edb819361d3a262ede6 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 10001 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 20482875 | Size: 66307 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive2: ST2000DM001-1CH164 ATA Device +++++
--- User ---
[MBR] a77dfce52993a32b336340adade86097
[BSP] 3bfeecd26998e7176276ecc5a42696b6 : Linux MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 104970 Mo
2 - [XXXXXX] EXTEN (0x05) [VISIBLE] Offset (sectors): 215187454 | Size: 371867 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive3: ST2000DM001-1CH164 ATA Device +++++
--- User ---
[MBR] 0e4c9ddc2e115b00c9b32fe0a026e1be
[BSP] b90a771ee7f8e60cc019b021fe71ec3c : MBR Code unknown
Partition table:
0 - [XXXXXX] FAT16-LBA (0x0e) [VISIBLE] Offset (sectors): 8064 | Size: 1896 Mo
User = LL1 ... OK!
Error reading LL2 MBR!
Termine :
RKreport[0]_D_08012013_203746.txt;RKreport[0]_S_07312013_220609.txt;RKreport[0]_S_08012013_203737.txt