GMER 1.0.15.15087 -
http://www.gmer.netRootkit scan 2009-10-01 15:43:33
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Wind\LOCALS~1\Temp\pxriiaob.sys
---- System - GMER 1.0.15 ----
SSDT F7CE380E ZwCreateKey
SSDT F7CE3804 ZwCreateThread
SSDT F7CE3813 ZwDeleteKey
SSDT F7CE381D ZwDeleteValueKey
SSDT spfh.sys ZwEnumerateKey [0xF74C8CA2]
SSDT spfh.sys ZwEnumerateValueKey [0xF74C9030]
SSDT F7CE3822 ZwLoadKey
SSDT \SystemRoot\system32\DRIVERS\kl1.sys (Kaspersky Unified Driver/Kaspersky Lab) ZwOpenFile [0xF2BA9000]
SSDT spfh.sys ZwOpenKey [0xF74AB0C0]
SSDT F7CE37F0 ZwOpenProcess
SSDT F7CE37F5 ZwOpenThread
SSDT spfh.sys ZwQueryKey [0xF74C9108]
SSDT spfh.sys ZwQueryValueKey [0xF74C8F88]
SSDT F7CE382C ZwReplaceKey
SSDT F7CE3827 ZwRestoreKey
SSDT F7CE3818 ZwSetValueKey
SSDT F7CE37FF ZwTerminateProcess
INT 0x62 ? 85B8CBF8
INT 0x82 ? 85B8CBF8
INT 0x83 ? 85A3CBF8
INT 0x83 ? 85A3CBF8
INT 0x83 ? 85A3CBF8
INT 0x83 ? 85A3CBF8
INT 0x83 ? 85A3CBF8
---- Kernel code sections - GMER 1.0.15 ----
? spfh.sys Le fichier spécifié est introuvable. !
.text USBPORT.SYS!DllUnload F650C8AC 5 Bytes JMP 85A3C1D8
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 85B902D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F74D16D0] spfh.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F74D5708] spfh.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74AC046] spfh.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74AC142] spfh.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74AC0C4] spfh.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74AC7CE] spfh.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74AC6A4] spfh.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 85A3C2D8
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74B7D7A] spfh.sys
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\wscntfy.exe[660] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [008E2F30] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wscntfy.exe[660] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [008E2CA0] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wscntfy.exe[660] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [008E2D00] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wscntfy.exe[660] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [008E2CD0] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1708] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [017D2F30] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1708] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [017D2CA0] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1708] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [017D2D00] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1708] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [017D2CD0] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe[2192] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003D2F30] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe[2192] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003D2CA0] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe[2192] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [003D2D00] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe[2192] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003D2CD0] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Wind\Bureau\gmer.exe[3376] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003B2F30] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Wind\Bureau\gmer.exe[3376] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003B2CA0] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Wind\Bureau\gmer.exe[3376] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [003B2D00] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Wind\Bureau\gmer.exe[3376] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003B2CD0] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wuauclt.exe[3904] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [008E2F30] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wuauclt.exe[3904] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [008E2CA0] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wuauclt.exe[3904] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [008E2D00] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wuauclt.exe[3904] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [008E2CD0] C:\Program Files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 85B8A1F8
Device \FileSystem\Fastfat \FatCdrom 8589C500
Device \Driver\usbuhci \Device\USBPDO-0 85A3B1F8
Device \Driver\usbuhci \Device\USBPDO-1 85A3B1F8
Device \Driver\usbuhci \Device\USBPDO-2 85A3B1F8
Device \Driver\usbehci \Device\USBPDO-3 85A191F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 85B8D1F8
Device \Driver\Cdrom \Device\CdRom0 85A0D1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 857801F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{B52A9579-8EA9-4DF4-98DA-84B8FA53BA28} 857801F8
Device \Driver\NetBT \Device\NetbiosSmb 857801F8
Device \Driver\usbuhci \Device\USBFDO-0 85A3B1F8
Device \Driver\usbuhci \Device\USBFDO-1 85A3B1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8575C500
Device \Driver\usbuhci \Device\USBFDO-2 85A3B1F8
Device \Driver\usbehci \Device\USBFDO-3 85A191F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8575C500
Device \Driver\Ftdisk \Device\FtControl 85B8D1F8
Device \FileSystem\Fastfat \Fat 8589C500
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 858FF500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xA3 0x89 0x2D 0xDB ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x18 0x00 0x53 0x14 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xA3 0x89 0x2D 0xDB ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x18 0x00 0x53 0x14 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xA3 0x89 0x2D 0xDB ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x18 0x00 0x53 0x14 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xA3 0x89 0x2D 0xDB ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x18 0x00 0x53 0x14 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{41E0ECDC-0C92-9310-20C8-8308B714ADB3}\InprocServer32@ C:\Documents and Settings\Delphine\Imesh\NCTAudioCompress3.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{41E0ECDC-0C92-9310-20C8-8308B714ADB3}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{41E0ECDC-0C92-9310-20C8-8308B714ADB3}\ProgID@ NCTAudioCompress3.AudioCompress3.1
Reg HKLM\SOFTWARE\Classes\CLSID\{41E0ECDC-0C92-9310-20C8-8308B714ADB3}\TypeLib@ {84B9B044-17C0-48FB-A300-C9747D5DF29C}
Reg HKLM\SOFTWARE\Classes\CLSID\{41E0ECDC-0C92-9310-20C8-8308B714ADB3}\VersionIndependentProgID@ NCTAudioCompress3.AudioCompress3
Reg HKLM\SOFTWARE\Classes\CLSID\{7185CBF9-8A0A-9464-777A-A2286D5F60AF}\InprocServer32@ C:\PROGRA~1\FICHIE~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7185CBF9-8A0A-9464-777A-A2286D5F60AF}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7185CBF9-8A0A-9464-777A-A2286D5F60AF}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{7185CBF9-8A0A-9464-777A-A2286D5F60AF}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{7185CBF9-8A0A-9464-777A-A2286D5F60AF}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{7185CBF9-8A0A-9464-777A-A2286D5F60AF}\ProgID@ OWC10.FieldList.10
Reg HKLM\SOFTWARE\Classes\CLSID\{7185CBF9-8A0A-9464-777A-A2286D5F60AF}\Programmable@
Reg HKLM\SOFTWARE\Classes\CLSID\{7185CBF9-8A0A-9464-777A-A2286D5F60AF}\TypeLib@ {0002E550-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{7185CBF9-8A0A-9464-777A-A2286D5F60AF}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{7185CBF9-8A0A-9464-777A-A2286D5F60AF}\VersionIndependentProgID@ OWC10.FieldList
Reg HKLM\SOFTWARE\Classes\CLSID\{7DF5D91B-78AE-169A-F538-EAE6A4E34D6B}\InProcServer32@ %SystemRoot%\system32\dsuiext.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{7DF5D91B-78AE-169A-F538-EAE6A4E34D6B}\InProcServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7DF5D91B-78AE-169A-F538-EAE6A4E34D6B}\ShellEx\MayChangeDefaultMenu
Reg HKLM\SOFTWARE\Classes\CLSID\{7DF5D91B-78AE-169A-F538-EAE6A4E34D6B}\ShellEx\MayChangeDefaultMenu@ 1
Reg HKLM\SOFTWARE\Classes\CLSID\{A6F0021F-075E-2677-2FD1-CE7D34EE46C8}\AutoConvertTo@ {00020821-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{A6F0021F-075E-2677-2FD1-CE7D34EE46C8}\DefaultIcon@ C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE,1
Reg HKLM\SOFTWARE\Classes\CLSID\{A6F0021F-075E-2677-2FD1-CE7D34EE46C8}\Insertable@
Reg HKLM\SOFTWARE\Classes\CLSID\{A6F0021F-075E-2677-2FD1-CE7D34EE46C8}\NotInsertable@
Reg HKLM\SOFTWARE\Classes\CLSID\{A6F0021F-075E-2677-2FD1-CE7D34EE46C8}\Ole1Class@ ExcelChart
Reg HKLM\SOFTWARE\Classes\CLSID\{A6F0021F-075E-2677-2FD1-CE7D34EE46C8}\ProgID@ ExcelChart
Reg HKLM\SOFTWARE\Classes\CLSID\{A6F0021F-075E-2677-2FD1-CE7D34EE46C8}\TreatAs@ {00020821-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{EB03CD95-7B8C-6EAE-5A94-E0EC5CBCD74B}\LocalServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\FINDER.EXE
Reg HKLM\SOFTWARE\Classes\CLSID\{EB03CD95-7B8C-6EAE-5A94-E0EC5CBCD74B}\LocalServer32@LocalServer32 *]gAVn-}f(ZXfeAR6.jiOUTLOOKNonBootFiles>yL7BHE-nf(y-A__qm]R2?
---- EOF - GMER 1.0.15 ----