Re: virus win32 rootkit-gen
le 23 Jan 2010 11:45
voila le rapport
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Ndisuio]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"Tag"=dword:0000000f
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,64,00,69,00,73,00,75,00,69,\
00,6f,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="NDIS mode utilisateur E/S Protocole"
"Group"="NDIS"
"Description"="NDIS mode utilisateur E/S Protocole"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Ndisuio\Linkage]
"Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,46,00,36,\
00,34,00,30,00,41,00,46,00,46,00,36,00,2d,00,34,00,43,00,41,00,45,00,2d,00,\
34,00,42,00,46,00,45,00,2d,00,39,00,36,00,35,00,32,00,2d,00,42,00,46,00,35,\
00,35,00,35,00,43,00,37,00,35,00,32,00,38,00,33,00,34,00,7d,00,00,00,5c,00,\
44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,36,00,31,00,36,00,35,00,37,\
00,36,00,41,00,32,00,2d,00,38,00,31,00,36,00,33,00,2d,00,34,00,32,00,35,00,\
36,00,2d,00,42,00,46,00,41,00,46,00,2d,00,41,00,43,00,33,00,46,00,41,00,35,\
00,39,00,30,00,32,00,46,00,35,00,37,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\
69,00,63,00,65,00,5c,00,7b,00,39,00,32,00,44,00,30,00,37,00,38,00,41,00,34,\
00,2d,00,33,00,35,00,32,00,37,00,2d,00,34,00,35,00,36,00,38,00,2d,00,42,00,\
35,00,31,00,44,00,2d,00,46,00,44,00,45,00,30,00,45,00,46,00,30,00,33,00,35,\
00,38,00,39,00,32,00,7d,00,00,00,00,00
"Route"=hex(7):22,00,7b,00,46,00,36,00,34,00,30,00,41,00,46,00,46,00,36,00,2d,\
00,34,00,43,00,41,00,45,00,2d,00,34,00,42,00,46,00,45,00,2d,00,39,00,36,00,\
35,00,32,00,2d,00,42,00,46,00,35,00,35,00,35,00,43,00,37,00,35,00,32,00,38,\
00,33,00,34,00,7d,00,22,00,00,00,22,00,7b,00,36,00,31,00,36,00,35,00,37,00,\
36,00,41,00,32,00,2d,00,38,00,31,00,36,00,33,00,2d,00,34,00,32,00,35,00,36,\
00,2d,00,42,00,46,00,41,00,46,00,2d,00,41,00,43,00,33,00,46,00,41,00,35,00,\
39,00,30,00,32,00,46,00,35,00,37,00,7d,00,22,00,00,00,22,00,7b,00,39,00,32,\
00,44,00,30,00,37,00,38,00,41,00,34,00,2d,00,33,00,35,00,32,00,37,00,2d,00,\
34,00,35,00,36,00,38,00,2d,00,42,00,35,00,31,00,44,00,2d,00,46,00,44,00,45,\
00,30,00,45,00,46,00,30,00,33,00,35,00,38,00,39,00,32,00,7d,00,22,00,00,00,\
00,00
"Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,\
00,73,00,75,00,69,00,6f,00,5f,00,7b,00,46,00,36,00,34,00,30,00,41,00,46,00,\
46,00,36,00,2d,00,34,00,43,00,41,00,45,00,2d,00,34,00,42,00,46,00,45,00,2d,\
00,39,00,36,00,35,00,32,00,2d,00,42,00,46,00,35,00,35,00,35,00,43,00,37,00,\
35,00,32,00,38,00,33,00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,\
00,65,00,5c,00,4e,00,64,00,69,00,73,00,75,00,69,00,6f,00,5f,00,7b,00,36,00,\
31,00,36,00,35,00,37,00,36,00,41,00,32,00,2d,00,38,00,31,00,36,00,33,00,2d,\
00,34,00,32,00,35,00,36,00,2d,00,42,00,46,00,41,00,46,00,2d,00,41,00,43,00,\
33,00,46,00,41,00,35,00,39,00,30,00,32,00,46,00,35,00,37,00,7d,00,00,00,5c,\
00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,00,73,00,75,00,\
69,00,6f,00,5f,00,7b,00,39,00,32,00,44,00,30,00,37,00,38,00,41,00,34,00,2d,\
00,33,00,35,00,32,00,37,00,2d,00,34,00,35,00,36,00,38,00,2d,00,42,00,35,00,\
31,00,44,00,2d,00,46,00,44,00,45,00,30,00,45,00,46,00,30,00,33,00,35,00,38,\
00,39,00,32,00,7d,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Ndisuio\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Ndisuio\Enum]
"0"="Root\\LEGACY_NDISUIO\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001