Thanks for the reply.
In the report I did notice many (63) IAT/EAT hooks with unknown modules; orange.
RogueKiller V10.2.0.0 (x64) [Jan 19 2015] by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
http://forum.adlice.comWebsite :
http://www.adlice.com/softwares/roguekiller/Blog :
http://www.adlice.comOperating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : NetUser [Administrator]
Mode : Delete -- Date : 01/19/2015 12:10:10
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 0 ¤¤¤
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 1 ¤¤¤
[File.Forged][File] DgivEcp.sys -- C:\Windows\System32\drivers\DgivEcp.sys -> ERROR [32]
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 63 (Driver: Loaded) ¤¤¤
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - PeekMessageW : Unknown @ 0x23c0000 (push dword 0x23c0000|ret )
[IAT:Inl(Hook.IEAT)] (iexplore.exe) ntdll.dll - NtMapViewOfSection : Unknown @ 0x71a0003c (jmp 0xfffffffffa3303d2|jmp dword near [0x719f001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) KERNEL32.dll - SetUnhandledExceptionFilter : Unknown @ 0x71a4003c (push dword 0x71a30022|ret |jmp dword near [0x71a3001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - GetMessageA : Unknown @ 0x710e003c (push dword 0x710d0022|ret |jmp dword near [0x710d001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - GetMessageW : Unknown @ 0x710a003c (push dword 0x71090022|ret |jmp dword near [0x7109001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - TranslateMessage : Unknown @ 0x716a003c (push dword 0x71690022|ret |jmp dword near [0x7169001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - PeekMessageW : Unknown @ 0x719c003c (push dword 0x719b0022|ret |jmp dword near [0x719b001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - GetClipboardData : Unknown @ 0x7170003c (push dword 0x716f0022|ret |jmp dword near [0x716f001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - CreateWindowExW : c:\program files (x86)\trusteer\rapport\bin\rooksbas.dll @ 0x6a7c97e0 (jmp dword near [0x7195001e]|jmp 0x10|jmp 0xfffffffff8e697a0)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) GDI32.dll - BitBlt : Unknown @ 0x7182003c (push dword 0x71810022|ret |jmp dword near [0x7181001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WINTRUST.dll - WinVerifyTrust : Unknown @ 0x7122003c (push dword 0x71210022|ret |jmp dword near [0x7121001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) KERNEL32.dll - QueueUserWorkItem : Unknown @ 0x7106003c (push dword 0x71050022|ret |jmp dword near [0x7105001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - RegisterClassA : Unknown @ 0x718a003c (push dword 0x71890022|ret |jmp dword near [0x7189001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - DdeInitializeW : Unknown @ 0x7174003c (push dword 0x71730022|ret |jmp dword near [0x7173001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WS2_32.dll - getaddrinfo : Unknown @ 0x7113003c (jmp 0xfffffffffba1bd8c|jmp dword near [0x7112001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetGetCookieExW : Unknown @ 0x713a003c (push dword 0x71390022|ret |jmp dword near [0x7139001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetConnectW : Unknown @ 0x7142003c (push dword 0x71410022|ret |jmp dword near [0x7141001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetOpenW : Unknown @ 0x7132003c (push dword 0x71310022|ret |jmp dword near [0x7131001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetSetStatusCallbackA : Unknown @ 0x712a003c (push dword 0x71290022|ret |jmp dword near [0x7129001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetQueryDataAvailable : Unknown @ 0x712e003c (push dword 0x712d0022|ret |jmp dword near [0x712d001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - HttpOpenRequestW : Unknown @ 0x715e003c (push dword 0x715d0022|ret |jmp dword near [0x715d001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - HttpSendRequestExW : Unknown @ 0x7152003c (push dword 0x71510022|ret |jmp dword near [0x7151001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - HttpSendRequestW : Unknown @ 0x714e003c (push dword 0x714d0022|ret |jmp dword near [0x714d001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetWriteFile : Unknown @ 0x7126003c (push dword 0x71250022|ret |jmp dword near [0x7125001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetCloseHandle : Unknown @ 0x714a003c (push dword 0x71490022|ret |jmp dword near [0x7149001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WS2_32.dll - GetAddrInfoExW : Unknown @ 0x711d003c (jmp 0xfffffffffbab2e38|jmp dword near [0x711c001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - HttpAddRequestHeadersA : Unknown @ 0x7166003c (push dword 0x71650022|ret |jmp dword near [0x7165001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) urlmon.dll - CoInternetCombineUrlEx : Unknown @ 0x717a003c (push dword 0x71790022|ret |jmp dword near [0x7179001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - HttpSendRequestA : Unknown @ 0x715a003c (push dword 0x71590022|ret |jmp dword near [0x7159001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - HttpOpenRequestA : Unknown @ 0x7162003c (push dword 0x71610022|ret |jmp dword near [0x7161001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetOpenA : Unknown @ 0x7136003c (push dword 0x71350022|ret |jmp dword near [0x7135001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetConnectA : Unknown @ 0x7146003c (push dword 0x71450022|ret |jmp dword near [0x7145001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) ntdll.dll - NtMapViewOfSection : Unknown @ 0x71a0003c (jmp 0xfffffffffa3303d2|jmp dword near [0x719f001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) KERNEL32.dll - SetUnhandledExceptionFilter : Unknown @ 0x71a4003c (push dword 0x71a30022|ret |jmp dword near [0x71a3001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - GetMessageA : Unknown @ 0x710e003c (push dword 0x710d0022|ret |jmp dword near [0x710d001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - GetMessageW : Unknown @ 0x710a003c (push dword 0x71090022|ret |jmp dword near [0x7109001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - TranslateMessage : Unknown @ 0x716a003c (push dword 0x71690022|ret |jmp dword near [0x7169001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - PeekMessageW : Unknown @ 0x719c003c (push dword 0x719b0022|ret |jmp dword near [0x719b001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - GetClipboardData : Unknown @ 0x7170003c (push dword 0x716f0022|ret |jmp dword near [0x716f001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - CreateWindowExW : c:\program files (x86)\trusteer\rapport\bin\rooksbas.dll @ 0x6a7c97e0 (jmp dword near [0x7195001e]|jmp 0x10|jmp 0xfffffffff8e697a0)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) GDI32.dll - BitBlt : Unknown @ 0x7182003c (push dword 0x71810022|ret |jmp dword near [0x7181001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WINTRUST.dll - WinVerifyTrust : Unknown @ 0x7122003c (push dword 0x71210022|ret |jmp dword near [0x7121001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) KERNEL32.dll - QueueUserWorkItem : Unknown @ 0x7106003c (push dword 0x71050022|ret |jmp dword near [0x7105001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - RegisterClassA : Unknown @ 0x718a003c (push dword 0x71890022|ret |jmp dword near [0x7189001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) USER32.dll - DdeInitializeW : Unknown @ 0x7174003c (push dword 0x71730022|ret |jmp dword near [0x7173001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WS2_32.dll - getaddrinfo : Unknown @ 0x7113003c (jmp 0xfffffffffba1bd8c|jmp dword near [0x7112001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetGetCookieExW : Unknown @ 0x713a003c (push dword 0x71390022|ret |jmp dword near [0x7139001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetConnectW : Unknown @ 0x7142003c (push dword 0x71410022|ret |jmp dword near [0x7141001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetOpenW : Unknown @ 0x7132003c (push dword 0x71310022|ret |jmp dword near [0x7131001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetSetStatusCallbackA : Unknown @ 0x712a003c (push dword 0x71290022|ret |jmp dword near [0x7129001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetQueryDataAvailable : Unknown @ 0x712e003c (push dword 0x712d0022|ret |jmp dword near [0x712d001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - HttpOpenRequestW : Unknown @ 0x715e003c (push dword 0x715d0022|ret |jmp dword near [0x715d001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - HttpSendRequestExW : Unknown @ 0x7152003c (push dword 0x71510022|ret |jmp dword near [0x7151001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - HttpSendRequestW : Unknown @ 0x714e003c (push dword 0x714d0022|ret |jmp dword near [0x714d001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetWriteFile : Unknown @ 0x7126003c (push dword 0x71250022|ret |jmp dword near [0x7125001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetCloseHandle : Unknown @ 0x714a003c (push dword 0x71490022|ret |jmp dword near [0x7149001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WS2_32.dll - GetAddrInfoExW : Unknown @ 0x711d003c (jmp 0xfffffffffbab2e38|jmp dword near [0x711c001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - HttpAddRequestHeadersA : Unknown @ 0x7166003c (push dword 0x71650022|ret |jmp dword near [0x7165001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) urlmon.dll - CoInternetCombineUrlEx : Unknown @ 0x717a003c (push dword 0x71790022|ret |jmp dword near [0x7179001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - HttpSendRequestA : Unknown @ 0x715a003c (push dword 0x71590022|ret |jmp dword near [0x7159001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - HttpOpenRequestA : Unknown @ 0x7162003c (push dword 0x71610022|ret |jmp dword near [0x7161001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetOpenA : Unknown @ 0x7136003c (push dword 0x71350022|ret |jmp dword near [0x7135001e]|jmp 0x10)
[IAT:Inl(Hook.IEAT)] (iexplore.exe) WININET.dll - InternetConnectA : Unknown @ 0x7146003c (push dword 0x71450022|ret |jmp dword near [0x7145001e]|jmp 0x10)
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: Volume0 +++++
--- User ---
[MBR] 909f2dd56199fefe9037ca74866f2053
[BSP] 83c18d2e04eb08d97fa47a02d855e0ea : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 853115 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1747181568 | Size: 99999 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([57] The parameter is incorrect. )
+++++ PhysicalDrive1: Seagate Expansion Desk USB Device +++++
Error reading User MBR! ([57] The parameter is incorrect. )
Error reading LL1 MBR! ([79] The semaphore timeout period has expired. )
Error reading LL2 MBR! ([32] The request is not supported. )
+++++ PhysicalDrive2: Seagate Backup+ Desk USB Device +++++
Error reading User MBR! ([57] The parameter is incorrect. )
Error reading LL1 MBR! ([79] The semaphore timeout period has expired. )
Error reading LL2 MBR! ([32] The request is not supported. )
============================================
RKreport_DEL_01082015_104743.log - RKreport_DEL_01082015_105205.log - RKreport_DEL_01122015_154155.log - RKreport_DEL_01122015_155513.log
RKreport_DEL_01132015_114842.log - RKreport_DEL_01132015_144742.log - RKreport_DEL_01132015_181217.log - RKreport_DEL_12092014_163128.log
RKreport_SCN_01082015_100743.log - RKreport_SCN_01082015_105112.log - RKreport_SCN_01122015_152016.log - RKreport_SCN_01132015_114139.log
RKreport_SCN_01132015_123242.log - RKreport_SCN_01132015_181149.log - RKreport_SCN_01152015_162241.log - RKreport_SCN_12092014_161227.log
RKreport_SCN_01192015_120344.log