Verni,
voici le rapport option 4 roguekiller:
RogueKiller V6.2.0 [12/12/2011] par Tigzy
mail: tigzyRK<at>gmail<dot>com
Remontees:
http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Blog:
http://tigzyrk.blogspot.com
Systeme d'exploitation: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Demarrage : Mode normal
Utilisateur: Famille Venet [Droits d'admin]
Mode: Proxy RAZ -- Date : 20/12/2011 23:37:27
¤¤¤ Processus malicieux: 0 ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Entrees de registre: 1 ¤¤¤
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer () -> DELETED
Termine : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
-------------------------------------------------------------------------------------------------------
Voici le rapport gmer:
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-12-20 23:59:44
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3200826AS rev.3.03
Running: st88m4rd.exe; Driver: D:\DOCUME~1\FAMILL~1\LOCALS~1\Temp\kwddikoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF26E1576]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF26E1432]
SSDT \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys ZwCreateSection [0xF7A96700]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF26E1910]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF26E100A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF26E150C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF26E0F4A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF26E0FAE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF26E162C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF26E15EC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF26E176C]
---- Kernel code sections - GMER 1.0.15 ----
.text afd.sys F2794000 24 Bytes [79, F2, 6A, 00, FF, 73, 0C, ...]
.text afd.sys F2794019 59 Bytes [C1, C1, E9, 02, F3, A5, 8B, ...]
.text afd.sys F2794055 19 Bytes [C0, EB, 3D, 8B, 45, DC, 80, ...]
.text afd.sys F2794069 123 Bytes [EB, 45, C7, 45, E4, 0D, 00, ...]
.text afd.sys F27940E5 24 Bytes [8B, DA, 8B, F1, 89, 75, E0, ...]
.text ...
? C:\WINDOWS\System32\drivers\afd.sys suspicious PE modification
? C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys Le fichier spécifié est introuvable. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[908] ntdll.dll!NtProtectVirtualMemory 7C91D6EE 5 Bytes JMP 00D9000A
.text C:\WINDOWS\System32\svchost.exe[908] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 5 Bytes JMP 00DA000A
.text C:\WINDOWS\System32\svchost.exe[908] ntdll.dll!KiUserExceptionDispatcher 7C91E47C 5 Bytes JMP 00D8000C
.text C:\WINDOWS\System32\ping.exe[3920] ntdll.dll!NtCreateProcess 7C91D14E 5 Bytes JMP 00B4000A
.text C:\WINDOWS\System32\ping.exe[3920] ntdll.dll!NtCreateProcessEx 7C91D15E 5 Bytes JMP 00B5000A
.text C:\WINDOWS\System32\ping.exe[3920] ntdll.dll!NtProtectVirtualMemory 7C91D6EE 5 Bytes JMP 009F000A
.text C:\WINDOWS\System32\ping.exe[3920] ntdll.dll!NtWriteVirtualMemory 7C91DFAE 5 Bytes JMP 00A0000A
.text C:\WINDOWS\System32\ping.exe[3920] ntdll.dll!KiUserExceptionDispatcher 7C91E47C 5 Bytes JMP 009E000C
.text C:\WINDOWS\System32\ping.exe[3920] USER32.dll!GetCursorPos 7E39BD76 5 Bytes JMP 00B8000A
.text C:\WINDOWS\System32\ping.exe[3920] USER32.dll!WindowFromPoint 7E39BD8E 5 Bytes JMP 00B9000A
.text C:\WINDOWS\System32\ping.exe[3920] USER32.dll!GetForegroundWindow 7E39BE4B 5 Bytes JMP 00BA000A
.text C:\WINDOWS\System32\ping.exe[3920] ole32.dll!CoCreateInstance 774BFAC3 5 Bytes JMP 00B7000A
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[600] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[600] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\prodrv06 \Device\ProDrv06 E185D008
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort0 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort2 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort3 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort4 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort5 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP5T0L0-14 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\prohlp02 \Device\ProHlp02 E158E320
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Modules - GMER 1.0.15 ----
Module (noname) (*** hidden *** ) F27B5000-F27CF000 (106496 bytes)
----------------------------------------------------------------------------------------------------
Voici les liens pour les 2 fichiers text via OTL :
http://cjoint.com/?ALvacdFHXde (OTL)
http://cjoint.com/?ALvacMOO5WV (Extras)
http://www.malekal.com/2011/10/07/superantispyware-et-spybot-vs-malwarebyte/