Hooks IAT RogueKiller

deadpools Messages postés 27 Date d'inscription   Statut Membre Dernière intervention   -  
deadpools Messages postés 27 Date d'inscription   Statut Membre Dernière intervention   -
Bonjour, après avoir fait un scan RogueKiller il m'as trouvé des Hook IAT, comment m'en débarrasser ?
voici le rapport
RogueKiller V10.9.4.0 (x64) [Jul 30 2015] par Adlice Software
email : https://www.adlice.com/contact/
Remontées : https://forum.adlice.com/
Site web : https://www.adlice.com/fr/roguekiller/
Blog : https://www.adlice.com/

Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Démarré en : Mode normal
Utilisateur : Tanguy [Administrateur]
Démarré depuis : C:\Program Files\RogueKiller\RogueKiller.exe
Mode : Suppression -- Date : 08/04/2015 23:14:25

¤¤¤ Processus : 0 ¤¤¤

¤¤¤ Registre : 2 ¤¤¤
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0DE1962F-A782-4339-AC0A-D32F8DEBB684} | NameServer : 217.78.6.191,37.59.72.228 ([IRELAND (IE)][(Unknown Country?) (XX)]) -> Remplacé(e) ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{0DE1962F-A782-4339-AC0A-D32F8DEBB684} | NameServer : 217.78.6.191,37.59.72.228 ([IRELAND (IE)][(Unknown Country?) (XX)]) -> Remplacé(e) ()

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost

¤¤¤ Antirootkit : 80 (Driver: Chargé) ¤¤¤
[IAT:Inl(Hook.IEAT)] (explorer.exe) ADVAPI32.dll - RegCreateKeyW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) kernel32.dll - DelayLoadFailureHook : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) GDI32.dll - GetRgnBox : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) USER32.dll - CopyRect : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) msvcrt.dll - iswalpha : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) ntdll.dll - WinSqmSetString : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) SHLWAPI.dll - StrStrIW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) SHELL32.dll - SHCreateDataObject : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) ole32.dll - CoInitializeEx : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) UxTheme.dll - GetThemeBackgroundExtent : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) POWRPROF.dll - CallNtPowerInformation : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) dwmapi.dll - DwmEnableBlurBehindWindow : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) slc.dll - SLGetWindowsInformationDWORD : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) gdiplus.dll - GdipSetInterpolationMode : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) Secur32.dll - GetUserNameExW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) RPCRT4.dll - NdrClientCall3 : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe) PROPSYS.dll - PSCreateMemoryPropertyStore : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ kernel32.dll) KERNELBASE.dll - BaseReleaseProcessExePath : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ GDI32.dll) LPK.dll - LpkGetCharacterPlacement : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ LPK.dll) USP10.dll - ScriptRecordDigitSubstitution : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ EXPLORERFRAME.dll) DUser.dll - GetGadgetFocus : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ EXPLORERFRAME.dll) DUI70.dll - FlushThemeHandles : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ EXPLORERFRAME.dll) IMM32.dll - ImmReleaseContext : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ IMM32.dll) MSCTF.dll - CtfImeProcessCicHotkey : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ POWRPROF.dll) SETUPAPI.dll - SetupDiGetClassDevsW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ SETUPAPI.dll) CFGMGR32.dll - CM_Get_Class_Property_ExW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ SETUPAPI.dll) DEVOBJ.dll - DevObjOpenDeviceInterface : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ PROPSYS.dll) OLEAUT32.dll - BSTR_UserSize64 : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ SndVolSSO.DLL) HID.DLL - HidP_GetUsages : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ timedate.cpl) comctl32.dll - InitCommonControlsEx : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ gameux.dll) xmllite.dll - CreateXmlReader : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ gameux.dll) CRYPT32.dll - CertCloseStore : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ gameux.dll) wer.dll - WerReportSubmit : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ CRYPT32.dll) MSASN1.dll - ASN1BEREncEndOfContents : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ authui.dll) CRYPTUI.dll - CryptUIDlgViewCertificateW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ msiltcfg.dll) VERSION.dll - VerQueryValueW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ urlmon.dll) WININET.dll - DeleteUrlCacheContainerW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ wdmaud.drv) WINMM.dll - waveOutClose : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ wdmaud.drv) ksuser.dll - KsCreatePin : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ wdmaud.drv) AVRT.dll - AvSetMmThreadPriority : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ stobject.dll) BatMeter.dll - IsBatteryLevelLow : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ msacm32.drv) MSACM32.dll - acmStreamSize : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ prnfldr.dll) WINSPOOL.DRV - GetPrinterDataW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ dxp.dll) urlmon.dll - CoInternetParseUrl : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ dxp.dll) shdocvw.dll - DllRegisterWindowClasses : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ netshell.dll) IPHLPAPI.DLL - GetAdaptersAddresses : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ netshell.dll) nlaapi.dll - NlaCloseQuery : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ IPHLPAPI.DLL) NSI.dll - NsiSetParameter : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ IPHLPAPI.DLL) WINNSI.DLL - NsiRpcDeregisterChangeNotification : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ pnidui.dll) QUtil.dll - FreeIsolationInfo : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ pnidui.dll) wevtapi.dll - EvtSubscribe : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ cscobj.dll) USERENV.dll - ProcessGroupPolicyCompleted : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ credssp.dll) SSPICLI.DLL - RevertSecurityContext : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ fxsst.dll) FXSAPI.dll - FaxAccessCheckEx : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ RasMM.dll) RASAPI32.dll - RasGetEntryPropertiesW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ RASAPI32.dll) rasman.dll - RasGetUnicodeDeviceName : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ provsvc.dll) WS2_32.dll - WSALookupServiceBeginW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ WWanMM.dll) wwapi.dll - WwanAllocateMemory : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ Wlanapi.dll) wlanutil.dll - WlanStringToSsid : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ WlanMM.dll) wlanhlp.dll - WlanPrivateGetAvailableNetworkList : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ wlanhlp.dll) Wlanapi.dll - WlanSetSecuritySettings : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ wlanhlp.dll) OneX.DLL - OneXCreateDefaultProfile : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ wlanhlp.dll) eappcfg.dll - EapHostPeerConfigBlob2Xml : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ OneX.DLL) eappprxy.dll - EapHostPeerGetResponseAttributes : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ bcryptprimitives.dll) bcrypt.dll - BCryptFinishHash : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ ieframe.dll) PSAPI.DLL - GetProcessImageFileNameW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ ieframe.dll) OLEACC.dll - GetRoleTextW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ wscinterop.dll) WSCAPI.dll - WscRegisterForChanges : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ werconcpl.dll) wercplsupport.dll - WerComGetAdminStores : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ framedynos.dll) WTSAPI32.dll - WTSUnRegisterSessionNotification : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ mf.dll) MFPlat.DLL - MFCreateAlignedMemoryBuffer : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ shlext64.dll) MSIMG32.dll - AlphaBlend : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ syncui.dll) SYNCENG.dll - OpenBriefcase : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ SYNCENG.dll) LINKINFO.dll - CreateLinkInfoW : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ PhotoViewer.dll) d3d9.dll - Direct3DCreate9 : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ PhotoViewer.dll) WindowsCodecs.dll - WICMapGuidToShortName : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ d3d9.dll) d3d8thk.dll - OsThunkDdResetVisrgn : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ RASDLG.dll) MPRAPI.dll - MprConfigInterfaceGetHandle : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ RASDLG.dll) rtutils.dll - TraceDeregisterExA : Unknown @ 0x22d85e09 (call 0x20d85e07)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ acppage.dll) sfc.dll - SfcIsFileProtected : Unknown @ 0x22d85e09 (call 0x20d85e07)

¤¤¤ Navigateurs web : 0 ¤¤¤
A voir également:

1 réponse

Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 685
 
Salut,

Ce n'a pas pour source des malwares.
0
deadpools Messages postés 27 Date d'inscription   Statut Membre Dernière intervention  
 
Salut,
c'est pas dangereux pour mon ordi du coup ?
0