Voilà le scan a été effectué. Il n'y a pas de lignes rouges, donc rien à supprimer ?
GMER 1.0.14.14536 -
http://www.gmer.net
Rootkit scan 2008-10-22 14:20:02
Windows 6.0.6000
---- System - GMER 1.0.14 ----
INT 0x62 ? 87217F00
INT 0x72 ? 84E5BBF8
INT 0x82 ? 84E5BBF8
INT 0x92 ? 85C18BF8
INT 0xA2 ? 87217F00
INT 0xA2 ? 87217F00
INT 0xA2 ? 87217F00
INT 0xB3 ? 87217F00
---- Kernel code sections - GMER 1.0.14 ----
? System32Driversspou.sys Le fichier spécifié est introuvable. !
PAGE ataport.SYS!DllUnload 8063DAF4 5 Bytes JMP 84E5B1D8
.text USBPORT.SYS!DllUnload 8AF04FEB 5 Bytes JMP 872174E0
.text ata8y8kl.SYS 8C1A3000 22 Bytes [ 1A, 72, FA, 81, 04, 71, FA, ... ]
.text ata8y8kl.SYS 8C1A3017 181 Bytes [ 00, 99, 07, 48, 80, A4, 05, ... ]
.text ata8y8kl.SYS 8C1A30CE 10 Bytes [ 00, 00, 00, 00, 00, 00, 66, ... ]
.text ata8y8kl.SYS 8C1A30DA 12 Bytes [ 00, 00, 02, 00, 00, 00, 25, ... ]
.text ata8y8kl.SYS 8C1A30E7 714 Bytes [ 00, F0, 0E, 00, 00, 00, 00, ... ]
.text ...
---- User code sections - GMER 1.0.14 ----
.text C:WindowsExplorer.EXE[1556] SHELL32.dll!SHFileOperationW 764A8B35 5 Bytes JMP 10001102 C:Program FilesUnlockerUnlockerHook.dll
.text C:Program FilesWindows LiveMessengermsnmsgr.exe[2508] kernel32.dll!SetUnhandledExceptionFilter 75A2D187 5 Bytes JMP 0056DBBD C:Program FilesWindows LiveMessengermsnmsgr.exe (Windows Live Messenger/Microsoft Corporation)
.text C:Program FilesCamera Assistant Software for ToshibaCEC_MAIN.exe[2860] ntdll.dll!DbgBreakPoint 77132EA8 1 Byte [ 90 ]
.text C:UsersSebbieDesktopgmer.exe[5508] ntdll.dll!NtCreateFile + 3 7714F417 2 Bytes [ F0, FA ]
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT SystemRootsystem32driversatapi.sys[ataport.SYS!AtaPortWritePortUchar] [807026D2] SystemRootSystem32Driversspou.sys
IAT SystemRootsystem32driversatapi.sys[ataport.SYS!AtaPortReadPortUchar] [80702040] SystemRootSystem32Driversspou.sys
IAT SystemRootsystem32driversatapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [807027FC] SystemRootSystem32Driversspou.sys
IAT SystemRootsystem32driversatapi.sys[ataport.SYS!AtaPortReadPortUshort] [807020BE] SystemRootSystem32Driversspou.sys
IAT SystemRootsystem32driversatapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8070213C] SystemRootSystem32Driversspou.sys
IAT SystemRootsystem32DRIVERSi8042prt.sys[HAL.dll!READ_PORT_UCHAR] [80712048] SystemRootSystem32Driversspou.sys
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortNotification] 24488B66
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortWritePortUchar] E84D8966
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortWritePortUlong] 83E84D8B
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 896602C1
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 488BEA4D
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortGetScatterGatherList] 8DC80320
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortReadPortUchar] 57500845
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortStallExecution] F0458D57
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortGetParentBusType] 00006850
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortRequestCallback] 458DB002
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 35FF50E8
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortGetUnCachedExtension] [8C1C8FBC] SystemRootSystem32Driversata8y8kl.SYS (ATAPI IDE Miniport Driver/Microsoft Corporation)
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortCompleteRequest] 57EC4D89
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 01F045C7
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] E8000000
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortMoveMemory] 0001E4E4
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortReadPortUshort] 4675C73B
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortReadPortBufferUshort] 1C8FC8A1
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 8D526A8C
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortInitialize] 00009A88
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortGetDeviceBase] 48C08300
IAT SystemRootSystem32Driversata8y8kl.SYS[ataport.SYS!AtaPortDeviceStateChange] 8D076A50
---- Devices - GMER 1.0.14 ----
Device FileSystemNtfs Ntfs 85C1B1F8
AttachedDevice Driverkbdclass DeviceKeyboardClass0 Wdf01000.sys (WDF dynamique/Microsoft Corporation)
AttachedDevice Driverkbdclass DeviceKeyboardClass1 Wdf01000.sys (WDF dynamique/Microsoft Corporation)
Device Drivervolmgr DeviceVolMgrControl 84E5D1F8
Device Driverusbuhci DeviceUSBPDO-0 871F51F8
Device Driverusbuhci DeviceUSBPDO-1 871F51F8
Device Driverusbehci DeviceUSBPDO-2 87204500
Device DriverPCI_PNP9358 Device 0000047 spou.sys
Device Driverusbuhci DeviceUSBPDO-3 871F51F8
Device Driver
etbt DeviceNetBT_Tcpip_{39FCA0E6-56C6-48D8-8611-98F9BA4E713D} 88D501F8
Device Driverusbuhci DeviceUSBPDO-4 871F51F8
Device Driverusbuhci DeviceUSBPDO-5 871F51F8
Device Driverusbehci DeviceUSBPDO-6 87204500
Device Drivervolmgr DeviceHarddiskVolume1 84E5D1F8
Device Drivervolmgr DeviceHarddiskVolume2 84E5D1F8
Device Drivercdrom DeviceCdRom0 872551F8
Device Driveratapi DeviceIdeIdeDeviceP0T0L0-0 85C191F8
Device Driveratapi DeviceIdeIdePort0 85C191F8
Device Driveratapi DeviceIdeIdePort1 85C191F8
Device Drivervolmgr DeviceHarddiskVolume3 84E5D1F8
Device Drivercdrom DeviceCdRom1 872551F8
Device Drivervolmgr DeviceHarddiskVolume4 84E5D1F8
Device Driver
etbt DeviceNetBt_Wins_Export 88D501F8
Device DriverSmb DeviceNetbiosSmb 88D44500
Device DriveriScsiPrt DeviceRaidPort0 872581F8
Device Driversptd Device942923377 spou.sys
Device Driverusbuhci DeviceUSBFDO-0 871F51F8
Device Driverusbuhci DeviceUSBFDO-1 871F51F8
Device Driver
etbt DeviceNetBT_Tcpip_{B6FAAD3D-4C31-47B8-BADF-CE722512100A} 88D501F8
Device Driverusbehci DeviceUSBFDO-2 87204500
Device Driverusbuhci DeviceUSBFDO-3 871F51F8
Device Driverusbuhci DeviceUSBFDO-4 871F51F8
Device Driverusbuhci DeviceUSBFDO-5 871F51F8
Device Driverusbehci DeviceUSBFDO-6 87204500
Device Driverata8y8kl DeviceScsiata8y8kl1Port4Path0Target0Lun0 8725A378
Device Driverata8y8kl DeviceScsiata8y8kl1 8725A378
Device FileSystemcdfs Cdfs 9337D1F8
---- Registry - GMER 1.0.14 ----
Reg HKLMSYSTEMControlSet001ServicessptdCfg19659239224E364682FA4BAF72C53EA4
Reg HKLMSYSTEMControlSet001ServicessptdCfg19659239224E364682FA4BAF72C53EA4@p0 C:Program FilesDAEMON Tools Lite
Reg HKLMSYSTEMControlSet001ServicessptdCfg19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLMSYSTEMControlSet001ServicessptdCfg19659239224E364682FA4BAF72C53EA4@khjeh 0x77 0xE6 0x18 0xB7 ...
Reg HKLMSYSTEMControlSet001ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001
Reg HKLMSYSTEMControlSet001ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLMSYSTEMControlSet001ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001@khjeh 0xA3 0xC2 0xD5 0x53 ...
Reg HKLMSYSTEMControlSet001ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40
Reg HKLMSYSTEMControlSet001ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40@khjeh 0x58 0x16 0xA5 0xEE ...
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg@s1 771343423
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg@s2 285507792
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg@h0 1
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4@p0 C:Program FilesDAEMON Tools Lite
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4@khjeh 0x77 0xE6 0x18 0xB7 ...
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001@khjeh 0xA3 0xC2 0xD5 0x53 ...
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40@khjeh 0x58 0x16 0xA5 0xEE ...
Reg HKLMSYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4
Reg HKLMSYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4@p0 C:Program FilesDAEMON Tools Lite
Reg HKLMSYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLMSYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4@khjeh 0x77 0xE6 0x18 0xB7 ...
Reg HKLMSYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001
Reg HKLMSYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLMSYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001@khjeh 0xA3 0xC2 0xD5 0x53 ...
Reg HKLMSYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40
Reg HKLMSYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40@khjeh 0x58 0x16 0xA5 0xEE ...
---- Files - GMER 1.0.14 ----
File C:UsersSebbieAppDataRoamingMicrosoftWindowsRecentvvv.jpg.lnk 0 bytes
---- EOF - GMER 1.0.14 ----