Rootkit sur mon ordi
Résolu/Fermé
Shaadow
-
17 juil. 2009 à 18:58
fix200 Messages postés 3243 Date d'inscription dimanche 28 décembre 2008 Statut Contributeur sécurité Dernière intervention 7 février 2011 - 18 juil. 2009 à 11:17
fix200 Messages postés 3243 Date d'inscription dimanche 28 décembre 2008 Statut Contributeur sécurité Dernière intervention 7 février 2011 - 18 juil. 2009 à 11:17
A voir également:
- Rootkit sur mon ordi
- Mon ordi rame que faire - Guide
- Comment reinitialiser un ordi - Guide
- Ordi scrabble - Télécharger - Jeux vidéo
- Ordi bloque - Guide
- Plus de son sur mon ordi - Guide
33 réponses
Utilisateur anonyme
17 juil. 2009 à 22:24
17 juil. 2009 à 22:24
@Shaadow
laisse tomber pour le moment je corrige le beug du prog
tu peux supprimer celui que tu as telechargé
@fix
vois si tu peux faire autre chose en attendant
laisse tomber pour le moment je corrige le beug du prog
tu peux supprimer celui que tu as telechargé
@fix
vois si tu peux faire autre chose en attendant
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
fix200
Messages postés
3243
Date d'inscription
dimanche 28 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
7 février 2011
158
17 juil. 2009 à 23:25
17 juil. 2009 à 23:25
Je suis entrain de faire le scan. Par contre, je pense faire un formatage de mon ordinateur, cependant je me demande si mon disque dur externe n'est pas infecté aussi...
Et voilà :
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-17 18:31:23
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xF35CF36E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xF35CFA86]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xF35D060C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xF35D0B40]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateFile [0xF35CFD78]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xF35CE460]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xF35D0A18]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xF35CDD0A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xF35D08D4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xF35CF102]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xF35D0C72]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xF35D240E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateThread [0xF35CF886]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xF35D0976]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteKey [0xF35CEA20]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteValueKey [0xF35CECF8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xF35D021C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xF35D2980]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xF35CEE3A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xF35CEEE4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xF35D0016]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadDriver [0xF35D1EA6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xF35CE43C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xF35CE44E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xF35CF030]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xF35D0BE2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenFile [0xF35CFB08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenKey [0xF35CE604]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xF35D0AB0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenProcess [0xF35CF56E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSection [0xF35D2438]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xF35D0D14]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenThread [0xF35CF492]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xF35CEF8E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xF35CEBB6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xF35CE8BC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueueApcThread [0xF35D2128]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xF35CEB34]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xF35CE0C2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xF35D109E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xF35D0F64]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xF35D1C30]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xF35CE224]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xF35D2860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xF35CDEC4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSecureConnectPort [0xF35D0312]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetContextThread [0xF35CF984]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xF35D15F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xF35D1FA0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSystemInformation [0xF35D24C2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetValueKey [0xF35CE744]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xF35D25A6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xF35D26D2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xF35D1DD2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateProcess [0xF35CF6EA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xF35CF63C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xF35CF7C8]
INT 0x63 ? 86367BF8
INT 0x73 ? 86367BF8
INT 0x73 ? 86367BF8
INT 0x73 ? 85ED0BF8
INT 0x73 ? 86367BF8
INT 0x82 ? 86367BF8
INT 0xA4 ? 85ED0BF8
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2C54 80503A28 13 Bytes [02, F1, 5C, F3, 72, 0C, 5D, ...]
.text ntkrnlpa.exe!ZwCallbackReturn + 2C88 80503A5C 4 Bytes JMP 321EF35C
.text ntkrnlpa.exe!ZwCallbackReturn + 2D10 80503AE4 12 Bytes [A6, 1E, 5D, F3, 3C, E4, 5C, ...]
.text ntkrnlpa.exe!ZwCallbackReturn + 2D74 80503B48 2 Bytes [6E, F5] {OUTSB ; CMC }
.text ntkrnlpa.exe!ZwCallbackReturn + 2D8C 80503B60 2 Bytes [92, F4] {XCHG EDX, EAX; HLT }
.text ...
? spqx.sys Le fichier spécifié est introuvable. !
.text USBPORT.SYS!DllUnload F694862C 5 Bytes JMP 85ED01D8
.text auiiw736.SYS F663C386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text auiiw736.SYS F663C3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text auiiw736.SYS F663C3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text auiiw736.SYS F663C3C9 1 Byte [30]
.text auiiw736.SYS F663C3C9 11 Bytes [30, 00, 00, 00, 5C, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESP; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- User code sections - GMER 1.0.15 ----
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[600] C:\WINDOWS\system32\ntdll.dll time/date stamp mismatch;
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[600] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[600] USER32.dll!VRipOutput + FFFA4DE7 7E392A78 4 Bytes [70, 11, 32, 6D]
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[824] C:\WINDOWS\system32\ntdll.dll time/date stamp mismatch;
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[824] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[824] USER32.dll!VRipOutput + FFFA4DE7 7E392A78 4 Bytes [70, 11, 32, 6D]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7430042] spqx.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F743013E] spqx.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74300C0] spqx.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F7430800] spqx.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74306D6] spqx.sys
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!KfAcquireSpinLock] 0C8D1C46
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!READ_PORT_UCHAR] B08B8932
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!KeGetCurrentIrql] 89000001
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!KfRaiseIrql] 0001BC83
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!KfLowerIrql] 24468B00
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!HalGetInterruptVector] 89820C8D
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!HalTranslateBusAddress] D18BF84D
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!KeStallExecutionProcessor] 860F1639
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!KfReleaseSpinLock] 000000BD
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 0208B389
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 7400067E
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!WRITE_PORT_UCHAR] 89D60320
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[WMILIB.SYS!WmiSystemControl] 8D168B00
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[WMILIB.SYS!WmiCompleteRequest] F0003284
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F743FE9C] spqx.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 863D71F8
AttachedDevice \FileSystem\Ntfs \Ntfs bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)
Device \FileSystem\Fastfat \FatCdrom 84F13500
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
Device \Driver\usbohci \Device\USBPDO-0 85ECF1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 863D91F8
Device \Driver\dmio \Device\DmControl\DmConfig 863D91F8
Device \Driver\dmio \Device\DmControl\DmPnP 863D91F8
Device \Driver\dmio \Device\DmControl\DmInfo 863D91F8
Device \Driver\usbehci \Device\USBPDO-1 85EC31F8
Device \Driver\sptd \Device\2117051010 spqx.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 863681F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 863681F8
Device \Driver\Cdrom \Device\CdRom0 85EB7500
Device \Driver\atapi \Device\Ide\IdePort0 863671F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-5 863671F8
Device \Driver\atapi \Device\Ide\IdePort1 863671F8
Device \Driver\atapi \Device\Ide\IdePort2 863671F8
Device \Driver\atapi \Device\Ide\IdePort3 863671F8
Device \Driver\atapi \Device\Ide\IdePort4 863671F8
Device \Driver\atapi \Device\Ide\IdePort5 863671F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-16 863671F8
Device \Driver\Cdrom \Device\CdRom1 85EB7500
Device \Driver\Ftdisk \Device\HarddiskVolume3 863681F8
Device \Driver\Ftdisk \Device\HarddiskVolume4 863681F8
Device \Driver\Ftdisk \Device\HarddiskVolume5 863681F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8598E500
Device \Driver\usbstor \Device\00000084 851281F8
Device \Driver\NetBT \Device\NetbiosSmb 8598E500
Device \Driver\usbstor \Device\00000085 851281F8
Device \Driver\usbstor \Device\00000086 851281F8
Device \Driver\usbstor \Device\00000087 851281F8
Device \Driver\PCI_PNP9760 \Device\0000004e spqx.sys
Device \Driver\usbstor \Device\00000088 851281F8
Device \Driver\usbstor \Device\00000089 851281F8
Device \Driver\usbohci \Device\USBFDO-0 85ECF1F8
Device \Driver\usbehci \Device\USBFDO-1 85EC31F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8512F1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8512F1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{6F15533F-DDE6-4BBB-88B5-FFA5299F38F8} 8598E500
Device \Driver\usbstor \Device\0000007d 851281F8
Device \Driver\Ftdisk \Device\FtControl 863681F8
Device \Driver\usbstor \Device\0000007e 851281F8
Device \Driver\usbstor \Device\0000008c 851281F8
Device \Driver\auiiw736 \Device\Scsi\auiiw7361 85E1C1F8
Device \Driver\auiiw736 \Device\Scsi\auiiw7361Port6Path0Target0Lun0 85E1C1F8
Device \FileSystem\Fastfat \Fat 84F13500
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)
Device \FileSystem\Cdfs \Cdfs 84F56500
---- Threads - GMER 1.0.15 ----
Thread System [4:324] B938030C
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main@aid 10002
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main@sid 0
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main\delete
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main\injector
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main\tasks
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main.REN
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules@geyekrrk.sys \systemroot\system32\drivers\geyekrthylbgrq.sys
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules@geyekrcmd.dll \systemroot\system32\geyekrtlwxwyom.dll
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules@geyekrlog.dat \systemroot\system32\geyekrexwpnqll.dat
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules@geyekrwsp.dll \systemroot\system32\geyekrxolprrrd.dll
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules@geyekr.dat \systemroot\system32\geyekrhasfmqft.dat
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules.REN
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x3E 0xB1 0x6D 0x0F ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFD 0x2E 0x94 0xF3 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xE5 0xA9 0xFB 0xF3 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0.REN
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001.REN
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC.REN
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x3E 0xB1 0x6D 0x0F ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFD 0x2E 0x94 0xF3 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0.REN
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0.REN@hdf12 0x0E 0x28 0x56 0x61 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001.REN
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x3E 0xB1 0x6D 0x0F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFD 0x2E 0x94 0xF3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0.REN
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0.REN@hdf12 0x0E 0x28 0x56 0x61 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001.REN
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001.REN@a0 0x20 0x01 0x00 0x00 ...
---- EOF - GMER 1.0.15 ----
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-17 18:31:23
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xF35CF36E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xF35CFA86]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xF35D060C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xF35D0B40]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateFile [0xF35CFD78]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xF35CE460]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xF35D0A18]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xF35CDD0A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xF35D08D4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xF35CF102]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xF35D0C72]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xF35D240E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateThread [0xF35CF886]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xF35D0976]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteKey [0xF35CEA20]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteValueKey [0xF35CECF8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xF35D021C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xF35D2980]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xF35CEE3A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xF35CEEE4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xF35D0016]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadDriver [0xF35D1EA6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xF35CE43C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xF35CE44E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xF35CF030]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xF35D0BE2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenFile [0xF35CFB08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenKey [0xF35CE604]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xF35D0AB0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenProcess [0xF35CF56E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSection [0xF35D2438]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xF35D0D14]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenThread [0xF35CF492]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xF35CEF8E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xF35CEBB6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xF35CE8BC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueueApcThread [0xF35D2128]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xF35CEB34]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xF35CE0C2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xF35D109E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xF35D0F64]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xF35D1C30]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xF35CE224]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xF35D2860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xF35CDEC4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSecureConnectPort [0xF35D0312]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetContextThread [0xF35CF984]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xF35D15F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xF35D1FA0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSystemInformation [0xF35D24C2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetValueKey [0xF35CE744]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xF35D25A6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xF35D26D2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xF35D1DD2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateProcess [0xF35CF6EA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xF35CF63C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xF35CF7C8]
INT 0x63 ? 86367BF8
INT 0x73 ? 86367BF8
INT 0x73 ? 86367BF8
INT 0x73 ? 85ED0BF8
INT 0x73 ? 86367BF8
INT 0x82 ? 86367BF8
INT 0xA4 ? 85ED0BF8
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2C54 80503A28 13 Bytes [02, F1, 5C, F3, 72, 0C, 5D, ...]
.text ntkrnlpa.exe!ZwCallbackReturn + 2C88 80503A5C 4 Bytes JMP 321EF35C
.text ntkrnlpa.exe!ZwCallbackReturn + 2D10 80503AE4 12 Bytes [A6, 1E, 5D, F3, 3C, E4, 5C, ...]
.text ntkrnlpa.exe!ZwCallbackReturn + 2D74 80503B48 2 Bytes [6E, F5] {OUTSB ; CMC }
.text ntkrnlpa.exe!ZwCallbackReturn + 2D8C 80503B60 2 Bytes [92, F4] {XCHG EDX, EAX; HLT }
.text ...
? spqx.sys Le fichier spécifié est introuvable. !
.text USBPORT.SYS!DllUnload F694862C 5 Bytes JMP 85ED01D8
.text auiiw736.SYS F663C386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text auiiw736.SYS F663C3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text auiiw736.SYS F663C3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text auiiw736.SYS F663C3C9 1 Byte [30]
.text auiiw736.SYS F663C3C9 11 Bytes [30, 00, 00, 00, 5C, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESP; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- User code sections - GMER 1.0.15 ----
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[600] C:\WINDOWS\system32\ntdll.dll time/date stamp mismatch;
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[600] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[600] USER32.dll!VRipOutput + FFFA4DE7 7E392A78 4 Bytes [70, 11, 32, 6D]
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[824] C:\WINDOWS\system32\ntdll.dll time/date stamp mismatch;
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[824] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[824] USER32.dll!VRipOutput + FFFA4DE7 7E392A78 4 Bytes [70, 11, 32, 6D]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7430042] spqx.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F743013E] spqx.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74300C0] spqx.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F7430800] spqx.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74306D6] spqx.sys
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!KfAcquireSpinLock] 0C8D1C46
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!READ_PORT_UCHAR] B08B8932
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!KeGetCurrentIrql] 89000001
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!KfRaiseIrql] 0001BC83
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!KfLowerIrql] 24468B00
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!HalGetInterruptVector] 89820C8D
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!HalTranslateBusAddress] D18BF84D
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!KeStallExecutionProcessor] 860F1639
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!KfReleaseSpinLock] 000000BD
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 0208B389
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 7400067E
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[HAL.dll!WRITE_PORT_UCHAR] 89D60320
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[WMILIB.SYS!WmiSystemControl] 8D168B00
IAT \SystemRoot\System32\Drivers\auiiw736.SYS[WMILIB.SYS!WmiCompleteRequest] F0003284
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F743FE9C] spqx.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 863D71F8
AttachedDevice \FileSystem\Ntfs \Ntfs bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)
Device \FileSystem\Fastfat \FatCdrom 84F13500
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
Device \Driver\usbohci \Device\USBPDO-0 85ECF1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 863D91F8
Device \Driver\dmio \Device\DmControl\DmConfig 863D91F8
Device \Driver\dmio \Device\DmControl\DmPnP 863D91F8
Device \Driver\dmio \Device\DmControl\DmInfo 863D91F8
Device \Driver\usbehci \Device\USBPDO-1 85EC31F8
Device \Driver\sptd \Device\2117051010 spqx.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 863681F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 863681F8
Device \Driver\Cdrom \Device\CdRom0 85EB7500
Device \Driver\atapi \Device\Ide\IdePort0 863671F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-5 863671F8
Device \Driver\atapi \Device\Ide\IdePort1 863671F8
Device \Driver\atapi \Device\Ide\IdePort2 863671F8
Device \Driver\atapi \Device\Ide\IdePort3 863671F8
Device \Driver\atapi \Device\Ide\IdePort4 863671F8
Device \Driver\atapi \Device\Ide\IdePort5 863671F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-16 863671F8
Device \Driver\Cdrom \Device\CdRom1 85EB7500
Device \Driver\Ftdisk \Device\HarddiskVolume3 863681F8
Device \Driver\Ftdisk \Device\HarddiskVolume4 863681F8
Device \Driver\Ftdisk \Device\HarddiskVolume5 863681F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8598E500
Device \Driver\usbstor \Device\00000084 851281F8
Device \Driver\NetBT \Device\NetbiosSmb 8598E500
Device \Driver\usbstor \Device\00000085 851281F8
Device \Driver\usbstor \Device\00000086 851281F8
Device \Driver\usbstor \Device\00000087 851281F8
Device \Driver\PCI_PNP9760 \Device\0000004e spqx.sys
Device \Driver\usbstor \Device\00000088 851281F8
Device \Driver\usbstor \Device\00000089 851281F8
Device \Driver\usbohci \Device\USBFDO-0 85ECF1F8
Device \Driver\usbehci \Device\USBFDO-1 85EC31F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8512F1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8512F1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{6F15533F-DDE6-4BBB-88B5-FFA5299F38F8} 8598E500
Device \Driver\usbstor \Device\0000007d 851281F8
Device \Driver\Ftdisk \Device\FtControl 863681F8
Device \Driver\usbstor \Device\0000007e 851281F8
Device \Driver\usbstor \Device\0000008c 851281F8
Device \Driver\auiiw736 \Device\Scsi\auiiw7361 85E1C1F8
Device \Driver\auiiw736 \Device\Scsi\auiiw7361Port6Path0Target0Lun0 85E1C1F8
Device \FileSystem\Fastfat \Fat 84F13500
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)
Device \FileSystem\Cdfs \Cdfs 84F56500
---- Threads - GMER 1.0.15 ----
Thread System [4:324] B938030C
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main@aid 10002
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main@sid 0
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main\delete
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main\injector
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main\tasks
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\main.REN
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules@geyekrrk.sys \systemroot\system32\drivers\geyekrthylbgrq.sys
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules@geyekrcmd.dll \systemroot\system32\geyekrtlwxwyom.dll
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules@geyekrlog.dat \systemroot\system32\geyekrexwpnqll.dat
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules@geyekrwsp.dll \systemroot\system32\geyekrxolprrrd.dll
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules@geyekr.dat \systemroot\system32\geyekrhasfmqft.dat
Reg HKLM\SYSTEM\ControlSet001\Services\geyekrqjkduxdv\modules.REN
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x3E 0xB1 0x6D 0x0F ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFD 0x2E 0x94 0xF3 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xE5 0xA9 0xFB 0xF3 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0.REN
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001.REN
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC.REN
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x3E 0xB1 0x6D 0x0F ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFD 0x2E 0x94 0xF3 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0.REN
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0.REN@hdf12 0x0E 0x28 0x56 0x61 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001.REN
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x3E 0xB1 0x6D 0x0F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFD 0x2E 0x94 0xF3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0.REN
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0.REN@hdf12 0x0E 0x28 0x56 0x61 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001.REN
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001.REN@a0 0x20 0x01 0x00 0x00 ...
---- EOF - GMER 1.0.15 ----
Utilisateur anonyme
18 juil. 2009 à 01:56
18 juil. 2009 à 01:56
interessant ce gMEr
rhôôôôlalala je crois que je viens de comprendre comment l'avoir ^^
rhôôôôlalala je crois que je viens de comprendre comment l'avoir ^^
Merci beaucoup pour ton aide merci cela n'a pas marché. ^^
J'ai procédé à un formatage de mon ordinateur.
donc, sujet résolue ;)
J'ai procédé à un formatage de mon ordinateur.
donc, sujet résolue ;)
afideg
Messages postés
10517
Date d'inscription
lundi 10 octobre 2005
Statut
Contributeur sécurité
Dernière intervention
12 avril 2022
602
18 juil. 2009 à 08:50
18 juil. 2009 à 08:50
Zut alors !!!
fix200
Messages postés
3243
Date d'inscription
dimanche 28 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
7 février 2011
158
18 juil. 2009 à 11:17
18 juil. 2009 à 11:17
Bonjour ,
Au zuuuuuuuuuuuuuuuuuuut :(
Pour quoi formater , je peux t'aider pour t'en débarrasser du rootkit ...
Bref .. Bon surf :)
Au zuuuuuuuuuuuuuuuuuuut :(
Pour quoi formater , je peux t'aider pour t'en débarrasser du rootkit ...
Bref .. Bon surf :)