GMER 1.0.15.15163 - www.gmer.net…
Rootkit scan 2009-11-04 18:02:44
Windows 5.1.2600 Service Pack 1
Running: gmer.exe; Driver: C:\DOCUME~1\Tidus\LOCALS~1\Temp\ugdiiuod.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF40356B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF4035574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF4035A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF403514C]
SSDT sptd.sys ZwEnumerateKey [0xF7729FB2]
SSDT sptd.sys ZwEnumerateValueKey [0xF772A340]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF403564E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF403508C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF40350F0]
SSDT sptd.sys ZwQueryKey [0xF772A418]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF403576E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF403572E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF40358AE]
---- Kernel code sections - GMER 1.0.15 ----
? C:\WINDOWS\system32\drivers\sptd.sys Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
.text USBPORT.SYS!DllUnload F6A4BF88 5 Bytes JMP 864B31C8
? System32\Drivers\ath8x7kd.SYS Le chemin d’accès spécifié est introuvable. !
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!IoConnectInterrupt] [F773B06C] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F773B018] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F775D9AE] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F773B06C] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7724AD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F7724C1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F7724B9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F7725748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F772561E] sptd.sys
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F773A29A] sptd.sys
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[1276] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00510002
IAT C:\WINDOWS\system32\services.exe[1276] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00510000
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 867661E8
AttachedDevice \FileSystem\Ntfs \Ntfs avgntmgr.sys (Avira AntiVir File Filter Driver Manager/Avira GmbH)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBPDO-0 865571E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 867D81E8
Device \Driver\dmio \Device\DmControl\DmConfig 867D81E8
Device \Driver\dmio \Device\DmControl\DmPnP 867D81E8
Device \Driver\dmio \Device\DmControl\DmInfo 867D81E8
Device \Driver\usbuhci \Device\USBPDO-1 865571E8
Device \Driver\usbehci \Device\USBPDO-2 864991E8
Device \Driver\usbuhci \Device\USBPDO-3 865571E8
Device \Driver\usbuhci \Device\USBPDO-4 865571E8
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\NetBT \Device\NetBT_Tcpip_{1B3AA64B-F60E-4A9C-B706-3A0A80468A46} 86422790
Device \Driver\PCI_NTPNP3980 \Device\00000062 sptd.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 867681E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 867681E8
Device \Driver\Cdrom \Device\CdRom0 865341E8
Device \Driver\Cdrom \Device\CdRom1 865341E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7674510] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F7674510] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F7674510] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-e [F7674510] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Ftdisk \Device\HarddiskVolume3 867681E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{67C5EF35-5761-48B1-8BC4-68DE902AE1BB} 86422790
Device \Driver\Ftdisk \Device\HarddiskVolume4 867681E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 86422790
Device \Driver\NetBT \Device\NetbiosSmb 86422790
Device \Driver\NetBT \Device\NetBT_Tcpip_{AFE4C164-2A7B-49BF-BFA2-05851E524824} 86422790
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBFDO-0 865571E8
Device \Driver\usbuhci \Device\USBFDO-1 865571E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 86463548
Device \Driver\usbuhci \Device\USBFDO-2 865571E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 86463548
Device \Driver\usbuhci \Device\USBFDO-3 865571E8
Device \Driver\usbehci \Device\USBFDO-4 864991E8
Device \Driver\Ftdisk \Device\FtControl 867681E8
Device \Driver\ath8x7kd \Device\Scsi\ath8x7kd1 864661E8
Device \Driver\ath8x7kd \Device\Scsi\ath8x7kd1Port4Path0Target0Lun0 864661E8
Device \FileSystem\Cdfs \Cdfs 86405420
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 1305623533
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 358789191
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x3E 0xBD 0xB6 0xD5 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xD6 0x3A 0xED 0xD6 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x05 0x91 0xB2 0xF9 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x3E 0xBD 0xB6 0xD5 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xD6 0x3A 0xED 0xD6 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x05 0x91 0xB2 0xF9 …
---- EOF - GMER 1.0.15 ----