Author Topic: problem with Antirootkit  (Read 4444 times)

0 Members and 1 Guest are viewing this topic.

July 28, 2014, 04:00:16 PM

fredf

  • Guest
problem with Antirootkit
« on: July 28, 2014, 04:00:16 PM »
Hello
sorry for my english first ( i'm french)
i have some redlignes in the anirootkit and i don't know how to manage it
please could you help me
i paste the report just below

RogueKiller V9.2.4.0 [Jul 11 2014] par Adlice Software
Mail : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site Web : http://www.surlatoile.org/RogueKiller/
Blog : http://www.adlice.com

Système d'exploitation : Windows Vista (6.0.6000 ) 32 bits version
Démarrage : Mode normal
Utilisateur : c [Droits d'admin]
Mode : Recherche -- Date : 07/28/2014  15:57:00

¤¤¤ Processus malicieux : 0 ¤¤¤

¤¤¤ Entrées de registre : 0 ¤¤¤

¤¤¤ Tâches planifiées : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier HOSTS : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1       localhost

¤¤¤ Antirootkit : 1 (Driver: CHARGE) ¤¤¤
[Filter(Root.Keylogger)] \Driver\kbdclass @ \Device\KeyboardClass0 : \Driver\eabfiltr @ Unknown (\SystemRoot\system32\DRIVERS\eabfiltr.sys)

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ MBR Verif : ¤¤¤
+++++ PhysicalDrive0: WDC WD1600BEVS-60RST0 +++++
--- User ---
[MBR] f85e5a86ffb7b3fbb9163078c80a14af
[BSP] 12830913e015e77ca4af50d8301b15b1 : HP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 145534 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 298053945 | Size: 7091 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_DEL_07272014_183502.log - RKreport_SCN_07272014_183013.log - RKreport_SCN_07272014_184050.log - RKreport_SCN_07282014_154342.log
RKreport_DEL_07282014_155218.log



thanks for all

Reply #1July 28, 2014, 06:01:12 PM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: problem with Antirootkit
« Reply #1 on: July 28, 2014, 06:01:12 PM »
Hello
Could you go in C:/Windows/System32/Drivers and right click on eabfiltr.sys , properties ?
What is the publisher? Could you upload it on Virus total?