Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e) (modifié)

mmmh aussi j'ai une question, ce virus peut 'il affecter mon internet (au niveau de la vitesse de naviguation) ?

 

PS: j'y pense, est ce que ce genre de virus ne se cache pas dans les fichiers de restauration systeme?

Modifié par Dju188

Posté(e)

Bonsoir, c'est juste pour prevenir que je serai pas la durant 2/3 jours, donc ne soit pas ettonné si tu ne reçois psa de reponses...

 

Encor merci de t'occupé de moi et deolé de te prendre autant de temps

Posté(e) (modifié)

salut :P

PS: je peux toujours essayer de refaire la reparation ? (avec la console?)

La réparation du secteur de boot avec la commande fixmbr tu veux dire ? si ca n'a pas fonctionné la première fois, je ne pense pas que ca marchera malheureusement.

mmmh aussi j'ai une question, ce virus peut 'il affecter mon internet (au niveau de la vitesse de naviguation) ?

 

PS: j'y pense, est ce que ce genre de virus ne se cache pas dans les fichiers de restauration systeme?

La réponse est non aux deux questions.

 

On va réutiliser mbr.exe comme ceci une dernière fois >>

 

1°) Déplace le fichier mbr.exe qui est sur ton Bureau et met le dans le répertoire C:\

 

Passe par Démarrer > Exécuter et tape cmd puis valide en appuyant sur la touche [Entrée].

Une fenêtre noire s'ouvre (l'invite de commandes).

Copie/colle ces commandes >>

cd \

Valide ensuite en cliquant sur la touche [Entrée]

mbr.exe -f

Valide ensuite en cliquant sur la touche [Entrée]

Un rapport mbr.log va se créer dans le même dossier, dans C:\

Poste ce rapport stp.

 

2°) Configuration d'Antivir >>

 

Dans le rapport du précédent scan avec Antivir, on peux voir ceci dans la configuration >

Search for rootkits..............: off

Tu vas modifier ce paramètre comme ceci >

 

Fais un clic droit sur l'icône d'Antivir dans la barre des tâches et choisis Configure Antivir

Dans la fenêtre, coche la case Expert Mode

Juste en dessous, clique sur le menu Scanner

Sur le panneau de droite, coche la case Search for Rootkits before scan

Ca doit ressembler à ceci >>

rd3y9mywab.gif

Clique sur le bouton OK pour valider en bas de page.

Ferme la fenêtre après ca.

 

3°) Redémarre le PC, impérativement en mode sans échec.

  • Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement.
  • Tapote par alternance les touches [F8] et [F5] jusqu'à l'affichage du menu des options avancées de Windows.
  • Sélectionne "Mode sans échec" et appuie sur la touche [Entrée].
  • Choisis ton compte usuel, et non Administrateur.
  • >> En images ici<<

4°) Scan Antivir en mode sans échec >>

  • Pour démarrer un scan, il suffit de cliquer sur l'onglet Scanner
  • Choisis les éléments à scanner > choisis Local Drivers
  • Clique sur l'icône antivir_icone_scan.pngpour démarrer le scan.
  • Lorsqu'une infection est détectée, clique sur le bouton Move to quarantine puis coche la case Apply selection to all following detections > cilque sur [ok] pour valider.
  • Une fois le scan terminé, clique sur le bouton report > un rapport va être créé : enregistre le sur le bureau.

Poste stp les deux rapports (celui d'antivir et le mbr.log) :P

Bonsoir, c'est juste pour prevenir que je serai pas la durant 2/3 jours, donc ne soit pas ettonné si tu ne reçois psa de reponses...

 

Encor merci de t'occupé de moi et deolé de te prendre autant de temps

Pas de souci, je suis ton topic :P

Modifié par Thanos
Posté(e)

Re, (desolé pour l'attente)

 

je suis de nouveau la!

J'ai commencé ce que tu m'a dit, le scan mbr a ete fait , et jle posterais plus tard, j'ai redemarer en mode sans echec, j'ai lancé le scan de "local drivers", mis quand il detectent le fameux BOO/sinowal.a, il ( antivir) ne me propose que 2 choix, "DELETE" ou "IGNORE", et tu te doute bien que ce virus ne peut etre DELETE sinon je ne serais pas ici^^

 

 

enfin bref, voila j'ai comme meme lancé un scan on vera ce qu'il me dira dans le rapport qu'antivir va me fournir ^^

 

Sur ce je retourne a mon scan!

 

Une derniere chose?, dis moi qu'il y a encor de l'espoire ^^

 

Cordialement Julien

 

PS: j'espere pour toi Manos, que tu trouvera une solution a ton probleme, mais je crois qu'il voudrait mieu que tu crée un topic pour ton probleme, car j'ai appris que toutes les infections (mm si elles sont due au meme virus, sont diferentes les unes des autres, ) donc va crer un topic, les Zebuloniens seront ravis de t'aider (enfin j'espere pour toi)

Posté(e)

voila les deux rapport,

 

 

 

Avira AntiVir Personal

Report file date: dimanche 29 juin 2008 12:43

 

Scanning for 1355845 virus strains and unwanted programs.

 

Licensed to: Avira AntiVir PersonalEdition Classic

Serial number: 0000149996-ADJIE-0001

Platform: Windows XP

Windows version: (Service Pack 2) [5.1.2600]

Boot mode: Save mode

Username: Julien

Computer name: CELERON

 

Version information:

BUILD.DAT : 8.1.0.308 16478 Bytes 28/05/2008 17:03:00

AVSCAN.EXE : 8.1.2.12 311553 Bytes 20/04/2008 16:08:16

AVSCAN.DLL : 8.1.1.0 53505 Bytes 20/04/2008 16:08:16

LUKE.DLL : 8.1.2.9 151809 Bytes 20/04/2008 16:08:16

LUKERES.DLL : 8.1.2.1 12033 Bytes 20/04/2008 16:08:17

ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15

ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 7/03/2008 21:19:13

ANTIVIR2.VDF : 7.0.4.195 2546176 Bytes 14/06/2008 08:00:51

ANTIVIR3.VDF : 7.0.4.241 331264 Bytes 23/06/2008 15:59:10

Engineversion : 8.1.0.59

AEVDF.DLL : 8.1.0.5 102772 Bytes 20/04/2008 16:08:17

AESCRIPT.DLL : 8.1.0.44 278907 Bytes 21/06/2008 16:01:55

AESCN.DLL : 8.1.0.22 119157 Bytes 21/06/2008 16:01:53

AERDL.DLL : 8.1.0.20 418165 Bytes 25/04/2008 18:37:28

AEPACK.DLL : 8.1.1.6 364918 Bytes 21/06/2008 16:01:50

AEOFFICE.DLL : 8.1.0.20 192891 Bytes 21/06/2008 16:01:45

AEHEUR.DLL : 8.1.0.32 1274231 Bytes 21/06/2008 16:01:43

AEHELP.DLL : 8.1.0.15 115063 Bytes 31/05/2008 13:56:33

AEGEN.DLL : 8.1.0.29 307573 Bytes 21/06/2008 16:01:37

AEEMU.DLL : 8.1.0.6 430451 Bytes 8/05/2008 15:27:47

AECORE.DLL : 8.1.0.31 168310 Bytes 6/06/2008 16:00:14

AVWINLL.DLL : 1.0.0.7 14593 Bytes 20/04/2008 16:08:16

AVPREF.DLL : 8.0.0.1 25857 Bytes 20/04/2008 16:08:16

AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24

AVREG.DLL : 8.0.0.0 30977 Bytes 20/04/2008 16:08:16

AVARKT.DLL : 1.0.0.23 307457 Bytes 20/04/2008 16:08:16

AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 20/04/2008 16:08:16

SQLITE3.DLL : 3.3.17.1 339968 Bytes 20/04/2008 16:08:17

SMTPLIB.DLL : 1.2.0.19 28929 Bytes 20/04/2008 16:08:17

NETNT.DLL : 8.0.0.1 7937 Bytes 20/04/2008 16:08:17

RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 20/04/2008 16:08:11

RCTEXT.DLL : 8.0.32.0 86273 Bytes 20/04/2008 16:08:11

 

Configuration settings for the scan:

Jobname..........................: Local Drives

Configuration file...............: c:\program files\avira\antivir personaledition classic\alldrives.avp

Logging..........................: low

Primary action...................: interactive

Secondary action.................: ignore

Scan master boot sector..........: on

Scan boot sector.................: on

Boot sectors.....................: C:, D:, A:, E:, F:, G:, H:, I:, J:, V:,

Scan memory......................: on

Process scan.....................: on

Scan registry....................: on

Search for rootkits..............: on

Scan all files...................: All files

Scan archives....................: on

Recursion depth..................: 20

Smart extensions.................: on

Macro heuristic..................: on

File heuristic...................: medium

 

Start of the scan: dimanche 29 juin 2008 12:43

 

Starting search for hidden objects.

The driver could not be initialized.

 

The scan of running processes will be started

Scan process 'avscan.exe' - '1' Module(s) have been scanned

Scan process 'avcenter.exe' - '1' Module(s) have been scanned

Scan process 'explorer.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'aawservice.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'lsass.exe' - '1' Module(s) have been scanned

Scan process 'services.exe' - '1' Module(s) have been scanned

Scan process 'winlogon.exe' - '1' Module(s) have been scanned

Scan process 'csrss.exe' - '1' Module(s) have been scanned

Scan process 'smss.exe' - '1' Module(s) have been scanned

12 processes with 12 modules were scanned

 

Starting master boot sector scan:

Master boot sector HD0

[iNFO] No virus was found!

Master boot sector HD1

[DETECTION] Contains detection pattern of the boot sector virus BOO/Sinowal.A

[WARNING] The boot sector cannot be repaired! You can find more information in the help

 

Start scanning boot sectors:

Boot sector 'C:\'

[iNFO] No virus was found!

Boot sector 'D:\'

[iNFO] No virus was found!

Boot sector 'A:\'

[iNFO] In the drive 'A:\' no data medium is inserted!

 

Starting to scan the registry.

 

The registry was scanned ( '25' files ).

 

 

Starting the file scan:

 

Begin scan in 'C:\' <Maxtor160Gb>

C:\pagefile.sys

[WARNING] The file could not be opened!

C:\WINDOWS\system32\drivers\sptd.sys

[WARNING] The file could not be opened!

Begin scan in 'D:\' <IBM20Gb>

Begin scan in 'A:\'

Search path A:\ could not be opened!

Le périphérique n'est pas prêt.

 

Begin scan in 'E:\'

Search path E:\ could not be opened!

Le périphérique n'est pas prêt.

 

Begin scan in 'F:\'

Search path F:\ could not be opened!

Le périphérique n'est pas prêt.

 

Begin scan in 'G:\'

Search path G:\ could not be opened!

Le périphérique n'est pas prêt.

 

Begin scan in 'H:\'

Search path H:\ could not be opened!

Le périphérique n'est pas prêt.

 

Begin scan in 'I:\'

Search path I:\ could not be opened!

Le périphérique n'est pas prêt.

 

Begin scan in 'J:\'

Search path J:\ could not be opened!

Le périphérique n'est pas prêt.

 

Begin scan in 'V:\' <COD2DVD>

 

 

End of the scan: dimanche 29 juin 2008 14:39

Used time: 1:56:15 min

 

The scan has been done completely.

 

5897 Scanning directories

306503 Files were scanned

1 viruses and/or unwanted programs were found

0 Files were classified as suspicious:

0 files were deleted

0 files were repaired

0 files were moved to quarantine

0 files were renamed

2 Files cannot be scanned

306501 Files not concerned

2007 Archives were scanned

3 Warnings

0 Notes

 

 

 

et le mbr (dans C:\)

 

Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net

 

device: opened successfully

user: MBR read successfully

kernel: MBR read successfully

user & kernel MBR OK

malicious code @ sector 0x1314ffd8 size 0x1e4 !

copy of MBR has been found in sector 62 !

 

 

voila

 

Julien

Posté(e)

Bon et bien voila les deux rapports demandés:

 

le rapport de drweb: (jlai mis en *.txt)

 

RegUBP2b-Julien.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Supprimé.;

ComboFix.exe\327882R2FWJFW\psexec.cfexe;C:\Documents and Settings\Julien\Bureau\ComboFix.exe;Program.PsExec.171;;

ComboFix.exe;C:\Documents and Settings\Julien\Bureau;L'archive contient des éléments infectés;Quarantaine.;

Process.exe;C:\SDFix\apps;Tool.Prockill;Quarantaine.;

A0072289.exe;C:\System Volume Information\_restore{49EAA784-2039-4FAC-8D75-C2F601053DE5}\RP191;Program.FPort.20;Quarantaine.;

A0072299.exe;C:\System Volume Information\_restore{49EAA784-2039-4FAC-8D75-C2F601053DE5}\RP191;Program.PsList.126;Quarantaine.;

A0076730.reg;C:\System Volume Information\_restore{49EAA784-2039-4FAC-8D75-C2F601053DE5}\RP220;Trojan.StartPage.1505;Supprimé.;

A0082828.reg;C:\System Volume Information\_restore{49EAA784-2039-4FAC-8D75-C2F601053DE5}\RP229;Trojan.StartPage.1505;Supprimé.;

A0084809.reg;C:\System Volume Information\_restore{49EAA784-2039-4FAC-8D75-C2F601053DE5}\RP236;Trojan.StartPage.1505;Supprimé.;

A0086022.reg;C:\System Volume Information\_restore{49EAA784-2039-4FAC-8D75-C2F601053DE5}\RP239;Trojan.StartPage.1505;Supprimé.;

A0088226.reg;C:\System Volume Information\_restore{49EAA784-2039-4FAC-8D75-C2F601053DE5}\RP240;Trojan.StartPage.1505;Supprimé.;

A0088227.exe\327882R2FWJFW\psexec.cfexe;C:\System Volume Information\_restore{49EAA784-2039-4FAC-8D75-C2F601053DE5}\RP240\A0088227.exe;Program.PsExec.171;;

A0088227.exe;C:\System Volume Information\_restore{49EAA784-2039-4FAC-8D75-C2F601053DE5}\RP240;L'archive contient des éléments infectés;Quarantaine.;

 

 

et le mbr log ( dans c:\)

 

Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net

 

device: opened successfully

user: MBR read successfully

kernel: MBR read successfully

user & kernel MBR OK

malicious code @ sector 0x1314ffd8 size 0x1e4 !

copy of MBR has been found in sector 62 !

 

 

 

 

 

Voila, a aussi une chose a tt hasard j'ai lancé une analyse antivir, il n'a pas detecté le virus !!!!!! (fini, mon ordi est gueri?)

 

Merci encor de ton aide, qui m'a ete fort precieuse...

 

Cordialement Julien

Posté(e) (modifié)

Alors voila les deux rapports demandés

 

 

 

Avira AntiVir Personal

Report file date: mercredi 2 juillet 2008 16h12

 

Scanning for 1372783 virus strains and unwanted programs.

 

Licensed to: Avira AntiVir PersonalEdition Classic

Serial number: 0000149996-ADJIE-0001

Platform: Windows XP

Windows version: (Service Pack 2) [5.1.2600]

Boot mode: Normally booted

Username: SYSTEM

Computer name: CELERON

 

Version information:

BUILD.DAT : 8.1.0.308 16478 Bytes 28/05/2008 17:03:00

AVSCAN.EXE : 8.1.2.12 311553 Bytes 20/04/2008 16:08:16

AVSCAN.DLL : 8.1.1.0 53505 Bytes 20/04/2008 16:08:16

LUKE.DLL : 8.1.2.9 151809 Bytes 20/04/2008 16:08:16

LUKERES.DLL : 8.1.2.1 12033 Bytes 20/04/2008 16:08:17

ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15

ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 12:58:34

ANTIVIR2.VDF : 7.0.5.20 142336 Bytes 30/06/2008 10:33:58

ANTIVIR3.VDF : 7.0.5.34 62976 Bytes 2/07/2008 10:47:25

Engineversion : 8.1.0.59

AEVDF.DLL : 8.1.0.5 102772 Bytes 20/04/2008 16:08:17

AESCRIPT.DLL : 8.1.0.44 278907 Bytes 21/06/2008 16:01:55

AESCN.DLL : 8.1.0.22 119157 Bytes 21/06/2008 16:01:53

AERDL.DLL : 8.1.0.20 418165 Bytes 25/04/2008 18:37:28

AEPACK.DLL : 8.1.1.6 364918 Bytes 21/06/2008 16:01:50

AEOFFICE.DLL : 8.1.0.20 192891 Bytes 21/06/2008 16:01:45

AEHEUR.DLL : 8.1.0.32 1274231 Bytes 21/06/2008 16:01:43

AEHELP.DLL : 8.1.0.15 115063 Bytes 31/05/2008 13:56:33

AEGEN.DLL : 8.1.0.29 307573 Bytes 21/06/2008 16:01:37

AEEMU.DLL : 8.1.0.6 430451 Bytes 8/05/2008 15:27:47

AECORE.DLL : 8.1.0.31 168310 Bytes 6/06/2008 16:00:14

AVWINLL.DLL : 1.0.0.7 14593 Bytes 20/04/2008 16:08:16

AVPREF.DLL : 8.0.0.1 25857 Bytes 20/04/2008 16:08:16

AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24

AVREG.DLL : 8.0.0.0 30977 Bytes 20/04/2008 16:08:16

AVARKT.DLL : 1.0.0.23 307457 Bytes 20/04/2008 16:08:16

AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 20/04/2008 16:08:16

SQLITE3.DLL : 3.3.17.1 339968 Bytes 20/04/2008 16:08:17

SMTPLIB.DLL : 1.2.0.19 28929 Bytes 20/04/2008 16:08:17

NETNT.DLL : 8.0.0.1 7937 Bytes 20/04/2008 16:08:17

RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 20/04/2008 16:08:11

RCTEXT.DLL : 8.0.32.0 86273 Bytes 20/04/2008 16:08:11

 

Configuration settings for the scan:

Jobname..........................: Complete system scan

Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp

Logging..........................: low

Primary action...................: interactive

Secondary action.................: ignore

Scan master boot sector..........: on

Scan boot sector.................: on

Boot sectors.....................: C:, D:,

Scan memory......................: on

Process scan.....................: on

Scan registry....................: on

Search for rootkits..............: on

Scan all files...................: All files

Scan archives....................: on

Recursion depth..................: 20

Smart extensions.................: on

Macro heuristic..................: on

File heuristic...................: medium

 

Start of the scan: mercredi 2 juillet 2008 16h12

 

Starting search for hidden objects.

'38216' objects were checked, '0' hidden objects were found.

 

The scan of running processes will be started

Scan process 'avscan.exe' - '1' Module(s) have been scanned

Scan process 'avcenter.exe' - '1' Module(s) have been scanned

Scan process 'wuauclt.exe' - '1' Module(s) have been scanned

Scan process 'usnsvc.exe' - '1' Module(s) have been scanned

Scan process 'firefox.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned

Scan process 'StarWindServiceAE.exe' - '1' Module(s) have been scanned

Scan process 'SMAgent.exe' - '1' Module(s) have been scanned

Scan process 'PnkBstrA.exe' - '1' Module(s) have been scanned

Scan process 'PhotoshopElementsDeviceConnect.exe' - '1' Module(s) have been scanned

Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned

Scan process 'imapi.exe' - '1' Module(s) have been scanned

Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned

Scan process 'sched.exe' - '1' Module(s) have been scanned

Scan process 'msmsgs.exe' - '1' Module(s) have been scanned

Scan process 'alg.exe' - '1' Module(s) have been scanned

Scan process 'PStrip.exe' - '1' Module(s) have been scanned

Scan process 'avgnt.exe' - '1' Module(s) have been scanned

Scan process 'rundll32.exe' - '1' Module(s) have been scanned

Scan process 'PhotoshopElementsFileAgent.exe' - '1' Module(s) have been scanned

Scan process 'reader_sl.exe' - '1' Module(s) have been scanned

Scan process 'SMax4.exe' - '1' Module(s) have been scanned

Scan process 'SMax4PNP.exe' - '1' Module(s) have been scanned

Scan process 'explorer.exe' - '1' Module(s) have been scanned

Scan process 'avguard.exe' - '1' Module(s) have been scanned

Scan process 'spoolsv.exe' - '1' Module(s) have been scanned

Scan process 'aawservice.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'lsass.exe' - '1' Module(s) have been scanned

Scan process 'services.exe' - '1' Module(s) have been scanned

Scan process 'winlogon.exe' - '1' Module(s) have been scanned

Scan process 'csrss.exe' - '1' Module(s) have been scanned

Scan process 'smss.exe' - '1' Module(s) have been scanned

38 processes with 38 modules were scanned

 

Starting master boot sector scan:

Master boot sector HD0

[iNFO] No virus was found!

Master boot sector HD1

[iNFO] No virus was found!

Master boot sector HD2

[iNFO] No virus was found!

[WARNING] Paramètre incorrect.

 

Start scanning boot sectors:

Boot sector 'C:\'

[iNFO] No virus was found!

Boot sector 'D:\'

[iNFO] No virus was found!

 

Starting to scan the registry.

The registry was scanned ( '22' files ).

 

 

Starting the file scan:

 

Begin scan in 'C:\' <Maxtor160Gb>

C:\hiberfil.sys

[WARNING] The file could not be opened!

C:\pagefile.sys

[WARNING] The file could not be opened!

C:\WINDOWS\system32\drivers\sptd.sys

[WARNING] The file could not be opened!

Begin scan in 'D:\' <IBM20Gb>

 

 

End of the scan: mercredi 2 juillet 2008 16h57

Used time: 44:45 min

 

The scan has been done completely.

 

6204 Scanning directories

341267 Files were scanned

0 viruses and/or unwanted programs were found

0 Files were classified as suspicious:

0 files were deleted

0 files were repaired

0 files were moved to quarantine

0 files were renamed

3 Files cannot be scanned

341267 Files not concerned

3633 Archives were scanned

4 Warnings

0 Notes

38216 Objects were scanned with rootkit scan

0 Hidden objects were found

 

 

 

 

et le rapport de gmer

 

 

GMER 1.0.14.14536 - http://www.gmer.net

Rootkit scan 2008-07-03 10:48:02

Windows 5.1.2600 Service Pack 2

 

 

---- System - GMER 1.0.14 ----

 

SSDT spvt.sys ZwCreateKey [0xF74D90E0]

SSDT B9F768F4 ZwCreateThread

SSDT spvt.sys ZwEnumerateKey [0xF74F6CA2]

SSDT spvt.sys ZwEnumerateValueKey [0xF74F7030]

SSDT spvt.sys ZwOpenKey [0xF74D90C0]

SSDT B9F768E0 ZwOpenProcess

SSDT B9F768E5 ZwOpenThread

SSDT spvt.sys ZwQueryKey [0xF74F7108]

SSDT spvt.sys ZwQueryValueKey [0xF74F6F88]

SSDT spvt.sys ZwSetValueKey [0xF74F719A]

SSDT B9F768EF ZwTerminateProcess

SSDT B9F768EA ZwWriteVirtualMemory

 

INT 0x62 ? 898AABF8

INT 0x73 ? 89789BF8

INT 0x73 ? 89789BF8

INT 0x82 ? 898AABF8

INT 0x83 ? 898AABF8

INT 0x83 ? 898AABF8

INT 0x83 ? 89789BF8

INT 0x83 ? 898AABF8

INT 0xA4 ? 89789BF8

INT 0xB4 ? 89789BF8

 

---- Kernel code sections - GMER 1.0.14 ----

 

? spvt.sys Le fichier spécifié est introuvable. !

.text USBPORT.SYS!DllUnload BA31762C 5 Bytes JMP 897891D8

.text ah5039h9.SYS BA147384 1 Byte [ 20 ]

.text ah5039h9.SYS BA147386 35 Bytes [ 00, 68, 00, 00, 00, 00, 00, ... ]

.text ah5039h9.SYS BA1473AA 24 Bytes [ 00, 00, 20, 00, 00, E0, 00, ... ]

.text ah5039h9.SYS BA1473C4 3 Bytes [ 00, 00, 00 ]

.text ah5039h9.SYS BA1473C9 1 Byte [ 00 ]

.text ...

 

---- User code sections - GMER 1.0.14 ----

 

.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[452] kernel32.dll!SetUnhandledExceptionFilter 7C84467D 5 Bytes JMP 0056DBBD C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Windows Live Messenger/Microsoft Corporation)

 

---- Kernel IAT/EAT - GMER 1.0.14 ----

 

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 899182D8

IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F74FF6D0] spvt.sys

IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7503708] spvt.sys

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74DA046] spvt.sys

IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74DA142] spvt.sys

IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74DA0C4] spvt.sys

IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74DA7CE] spvt.sys

IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74DA6A4] spvt.sys

IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 897892D8

IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74E5D7A] spvt.sys

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!RtlInitUnicodeString] DD000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!swprintf] 74000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeSetEvent] 1F000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 4B000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoGetConfigurationInformation] BD000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 8B000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmFreeMappingAddress] 8A000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 70000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 3E000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmUnmapIoSpace] B5000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 66000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IofCompleteRequest] 48000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 03000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IofCallDriver] F6000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 0E000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 61000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoConnectInterrupt] 35000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoDetachDevice] 57000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeWaitForSingleObject] B9000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeInitializeEvent] 86000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] C1000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!RtlInitAnsiString] 1D000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 9E000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoQueueWorkItem] E1000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmMapIoSpace] F8000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 98000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoReportDetectedDevice] 11000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoReportResourceForDetection] 69000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] D9000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!NlsMbCodePageTag] 8E000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!PoRequestPowerIrp] 94000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 9B000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 1E000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!sprintf] 87000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] E9000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!ObfDereferenceObject] CE000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 55000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 28000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!ZwClose] DF000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] 8C000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] A1000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 89000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 0D000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!PoCallDriver] [bF000000] \SystemRoot\System32\drivers\dxg.sys (DirectX Graphics Driver/Microsoft Corporation)

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoCreateDevice] E6000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 42000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 68000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!ZwOpenKey] 41000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 99000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoStartTimer] 2D000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeInitializeTimer] 0F000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoInitializeTimer] B0000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeInitializeDpc] 54000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeInitializeSpinLock] BB000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoInitializeIrp] 16000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!ZwCreateKey] 00000052

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 00000009

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 0000006A

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!ZwSetValueKey] 000000D5

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeInsertQueueDpc] 00000030

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 00000036

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoStartPacket] 000000A5

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 00000038

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 000000BF

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoFreeMdl] 00000040

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmUnlockPages] 000000A3

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 0000009E

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 00000081

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 000000F3

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 000000D7

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeSynchronizeExecution] 000000FB

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoStartNextPacket] 0000007C

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeBugCheckEx] 000000E3

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 00000039

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeSetTimer] 00000082

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeCancelTimer] 0000009B

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!_allmul] 0000002F

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmProbeAndLockPages] 000000FF

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!_except_handler3] 00000087

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!PoSetPowerState] 00000034

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 0000008E

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 00000043

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!_aulldiv] 00000044

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!strstr] 000000C4

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!_strupr] 000000DE

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeQuerySystemTime] 000000E9

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 000000CB

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!KeTickCount] 00000054

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 0000007B

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoDeleteDevice] 00000094

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 00000032

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoAllocateWorkItem] 000000A6

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoAllocateIrp] 000000C2

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoAllocateMdl] 00000023

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 0000003D

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmLockPagableDataSection] 000000EE

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 0000004C

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 00000095

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!ExFreePoolWithTag] 0000000B

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoFreeIrp] 00000042

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!IoFreeWorkItem] 000000FA

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!InitSafeBootMode] 000000C3

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!RtlCompareMemory] 0000004E

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 00000008

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!memmove] 0000002E

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[ntoskrnl.exe!MmHighestUserAddress] 000000A1

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!KfAcquireSpinLock] 6C000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!READ_PORT_UCHAR] 56000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!KeGetCurrentIrql] F4000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!KfRaiseIrql] EA000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!KfLowerIrql] 65000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!HalGetInterruptVector] 7A000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!HalTranslateBusAddress] AE000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!KeStallExecutionProcessor] 08000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!KfReleaseSpinLock] [bA000000] \SystemRoot\system32\DRIVERS\rdpdr.sys (Microsoft RDP Device redirector/Microsoft Corporation)

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 78000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!READ_PORT_USHORT] 25000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 2E000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[HAL.dll!WRITE_PORT_UCHAR] 1C000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[WMILIB.SYS!WmiSystemControl] B4000000

IAT \SystemRoot\System32\Drivers\ah5039h9.SYS[WMILIB.SYS!WmiCompleteRequest] C6000000

 

---- Devices - GMER 1.0.14 ----

 

Device \FileSystem\Ntfs \Ntfs 898A91F8

Device \FileSystem\Fastfat \FatCdrom 894BC1F8

Device \FileSystem\Udfs \UdfsCdRom 892D21F8

Device \FileSystem\Udfs \UdfsDisk 892D21F8

Device \Driver\usbuhci \Device\USBPDO-0 897841F8

Device \Driver\dmio \Device\DmControl\DmIoDaemon 899161F8

Device \Driver\dmio \Device\DmControl\DmConfig 899161F8

Device \Driver\dmio \Device\DmControl\DmPnP 899161F8

Device \Driver\dmio \Device\DmControl\DmInfo 899161F8

Device \Driver\usbuhci \Device\USBPDO-1 897841F8

Device \Driver\usbuhci \Device\USBPDO-2 897841F8

Device \Driver\usbuhci \Device\USBPDO-3 897841F8

Device \Driver\PCI_PNP4386 \Device\00000047 spvt.sys

Device \Driver\PCI_PNP4386 \Device\00000047 spvt.sys

Device \Driver\usbehci \Device\USBPDO-4 8976D1F8

Device \Driver\USBSTOR \Device\00000070 894BA1F8

Device \Driver\Ftdisk \Device\HarddiskVolume1 898AB1F8

Device \Driver\USBSTOR \Device\00000071 894BA1F8

Device \Driver\Ftdisk \Device\HarddiskVolume2 898AB1F8

Device \Driver\Cdrom \Device\CdRom0 897671F8

Device \Driver\Cdrom \Device\CdRom1 897671F8

Device \Driver\atapi \Device\Ide\IdePort0 898AA1F8

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 898AA1F8

Device \Driver\atapi \Device\Ide\IdePort1 898AA1F8

Device \Driver\atapi \Device\Ide\IdePort2 898AA1F8

Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 898AA1F8

Device \Driver\atapi \Device\Ide\IdePort3 898AA1F8

Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1b 898AA1F8

Device \Driver\Cdrom \Device\CdRom2 897671F8

Device \Driver\Cdrom \Device\CdRom3 897671F8

Device \Driver\Cdrom \Device\CdRom4 897671F8

Device \Driver\Cdrom \Device\CdRom5 897671F8

Device \Driver\NetBT \Device\NetBT_Tcpip_{1D2BD588-ADBF-4987-87FE-D8C8995254CB} 892FE1F8

Device \Driver\NetBT \Device\NetBt_Wins_Export 892FE1F8

Device \Driver\Cdrom \Device\CdRom6 897671F8

Device \Driver\NetBT \Device\NetbiosSmb 892FE1F8

Device \Driver\sptd \Device\1122404386 spvt.sys

Device \Driver\usbuhci \Device\USBFDO-0 897841F8

Device \Driver\usbuhci \Device\USBFDO-1 897841F8

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 894B41F8

Device \Driver\usbuhci \Device\USBFDO-2 897841F8

Device \FileSystem\MRxSmb \Device\LanmanRedirector 894B41F8

Device \Driver\usbuhci \Device\USBFDO-3 897841F8

Device \Driver\usbehci \Device\USBFDO-4 8976D1F8

Device \Driver\Ftdisk \Device\FtControl 898AB1F8

Device \Driver\ah5039h9 \Device\Scsi\ah5039h91Port4Path0Target4Lun0 896AC500

Device \Driver\ah5039h9 \Device\Scsi\ah5039h91Port4Path0Target3Lun0 896AC500

Device \Driver\ah5039h9 \Device\Scsi\ah5039h91Port4Path0Target1Lun0 896AC500

Device \Driver\ah5039h9 \Device\Scsi\ah5039h91Port4Path0Target5Lun0 896AC500

Device \Driver\ah5039h9 \Device\Scsi\ah5039h91Port4Path0Target2Lun0 896AC500

Device \Driver\ah5039h9 \Device\Scsi\ah5039h91Port4Path0Target0Lun0 896AC500

Device \Driver\ah5039h9 \Device\Scsi\ah5039h91 896AC500

Device \FileSystem\Fastfat \Fat 894BC1F8

 

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

 

Device \FileSystem\Cdfs \Cdfs 892FC1F8

 

---- Registry - GMER 1.0.14 ----

 

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xED 0x02 0x0B 0xE1 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x75 0xA1 0x5C 0x7A ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xD1 0x68 0xFD 0xA6 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0xC9 0x19 0x27 0xC0 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42@ujdew 0xF2 0x0C 0x43 0xC9 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg43

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg43@ujdew 0xAB 0xC6 0x4F 0x85 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg44

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg44@ujdew 0x54 0x51 0xDA 0xC7 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg45

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg45@ujdew 0x54 0x51 0xDA 0xC7 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xED 0x02 0x0B 0xE1 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x75 0xA1 0x5C 0x7A ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xD1 0x68 0xFD 0xA6 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0xC9 0x19 0x27 0xC0 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42@ujdew 0xF2 0x0C 0x43 0xC9 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg43

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg43@ujdew 0xAB 0xC6 0x4F 0x85 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg44

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg44@ujdew 0x54 0x51 0xDA 0xC7 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg45

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg45@ujdew 0x54 0x51 0xDA 0xC7 ...

 

---- Disk sectors - GMER 1.0.14 ----

 

Disk \Device\Harddisk0\DR0 sector 61: malicious code @ sector 0x1314ffd8 size 0x1e4

Disk \Device\Harddisk0\DR0 sector 62: copy of MBR

 

---- EOF - GMER 1.0.14 ----

Modifié par Dju188
  • Tonton a modifié le titre en Boo/sinowal.a : virus, trojan ?

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...