bonsoir,
J'ai lancé Gmer.
il n'y a eu aucun message concernant des rootkits.
voici le rapport :
GMER 2.1.19357 -
http://www.gmer.net
Rootkit scan 2014-05-04 22:06:23
Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 - \Device\Ide\IAAStorageDevice-1 ST925082 rev.3.AH 232,89GB
Running: qel20by9.exe; Driver: C:\Users\LA4771~1\AppData\Local\Temp\ugliypob.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0x906F8A9C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x906F957A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0x907055C4]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0x90705610]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x907057AA]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0x90705532]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateSection [0x90C0F59A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x9070557A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0x906F9AB0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0x90705764]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x906FA368]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x906F8B02]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0x906FDB3C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0x906F86EE]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0x90C0F67A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x906F8B68]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x906FDF32]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x906FAE50]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0x907055EE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0x90705632]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x907057CE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0x90705558]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0x906FD436]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0x907056E2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x907055A2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0x906FD81E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0x90705788]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x90C0F41E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0x906FACC4]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThread [0x906FA81A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x906F8BCE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0x906F8C34]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwSetContextThread [0x90C0F776]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x906F8788]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x906F895A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0x906F88E8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0x906FA532]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0x906FA694]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x906F89E2]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwTerminateProcess [0x90C0F4EC]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0x906FA1C2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0x906F8C9A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0x906F95D6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThreadEx [0x906F9CCC]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!KeSetEvent + 10D 822C8758 4 Bytes [9C, 8A, 6F, 90] {PUSHF ; MOV CH, [EDI-0x70]}
.text ntkrnlpa.exe!KeSetEvent + 191 822C87DC 4 Bytes [7A, 95, 6F, 90] {JP 0xffffff97; OUTS DX, DWORD [ESI]; NOP }
.text ntkrnlpa.exe!KeSetEvent + 1D1 822C881C 8 Bytes [C4, 55, 70, 90, 10, 56, 70, ...] {LES EDX, [EBP+0x70]; NOP ; ADC [ESI+0x70], DL; NOP }
.text ntkrnlpa.exe!KeSetEvent + 1DD 822C8828 4 Bytes [AA, 57, 70, 90] {STOSB ; PUSH EDI; JO 0xffffff94}
.text ntkrnlpa.exe!KeSetEvent + 1F5 822C8840 4 Bytes [32, 55, 70, 90] {XOR DL, [EBP+0x70]; NOP }
.text ...
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110 8245600F 4 Bytes CALL 906FB513 \SystemRoot\system32\drivers\aswSnx.sys
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121 82459C83 4 Bytes CALL 906FB529 \SystemRoot\system32\drivers\aswSnx.sys
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\taskeng.exe[592] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[600] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\system32\csrss.exe[624] KERNEL32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\system32\wininit.exe[676] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\system32\csrss.exe[688] KERNEL32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text ...
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[1260] kernel32.dll!SetUnhandledExceptionFilter 75E9A9BD 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[1260] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\system32\AUDIODG.EXE[1316] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1352] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\system32\conime.exe[1360] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1404] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text ...
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1860] kernel32.dll!SetUnhandledExceptionFilter 75E9A9BD 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1860] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[1904] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\Explorer.EXE[1940] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\system32\WLANExt.exe[1948] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2220] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text ...
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3416] ntdll.dll!LdrLoadDll 777D9378 5 Bytes JMP 000601F8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3416] ntdll.dll!LdrUnloadDll 777EB680 5 Bytes JMP 000603FC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3416] ntdll.dll!NtMapViewOfSection + 6 778149BA 4 Bytes [18, 00, 20, 6C]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3416] ntdll.dll!NtMapViewOfSection + B 778149BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3416] KERNEL32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[3500] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Program Files\HP\HP Photosmart 5510d series\Bin\ScanToPCActivationApp.exe[3508] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\ehome\ehtray.exe[3524] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Program Files\HP\QuickPlay\QPService.exe[3604] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text ...
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!LdrLoadDll 777D9378 5 Bytes JMP 004D01F8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!LdrUnloadDll 777EB680 5 Bytes JMP 004D03FC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtCreateFile + 6 7781426A 4 Bytes [28, 20, 28, 00] {SUB [EAX], AH; SUB [EAX], AL}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtCreateFile + B 7781426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtMapViewOfSection + 6 778149BA 4 Bytes [28, 23, 28, 00] {SUB [EBX], AH; SUB [EAX], AL}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtMapViewOfSection + B 778149BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenFile + 6 77814A4A 4 Bytes [68, 20, 28, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenFile + B 77814A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenProcess + 6 77814ACA 4 Bytes [A8, 21, 28, 00] {TEST AL, 0x21; SUB [EAX], AL}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenProcess + B 77814ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenProcessToken + 6 77814ADA 4 Bytes CALL 76817300 C:\Windows\system32\SHELL32.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenProcessToken + B 77814ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenProcessTokenEx + 6 77814AEA 4 Bytes [A8, 22, 28, 00] {TEST AL, 0x22; SUB [EAX], AL}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenProcessTokenEx + B 77814AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenThread + 6 77814B3A 4 Bytes [68, 21, 28, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenThread + B 77814B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenThreadToken + 6 77814B4A 4 Bytes [68, 22, 28, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenThreadToken + B 77814B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenThreadTokenEx + 6 77814B5A 4 Bytes CALL 76817381 C:\Windows\system32\SHELL32.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtOpenThreadTokenEx + B 77814B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtQueryAttributesFile + 6 77814BEA 4 Bytes [A8, 20, 28, 00] {TEST AL, 0x20; SUB [EAX], AL}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtQueryAttributesFile + B 77814BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtQueryFullAttributesFile + 6 77814C9A 4 Bytes CALL 768174BF C:\Windows\system32\SHELL32.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtQueryFullAttributesFile + B 77814C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtSetInformationFile + 6 7781517A 4 Bytes [28, 21, 28, 00] {SUB [ECX], AH; SUB [EAX], AL}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtSetInformationFile + B 7781517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtSetInformationThread + 6 778151CA 4 Bytes [28, 22, 28, 00] {SUB [EDX], AH; SUB [EAX], AL}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtSetInformationThread + B 778151CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtUnmapViewOfSection + 6 7781546A 4 Bytes [68, 23, 28, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] ntdll.dll!NtUnmapViewOfSection + B 7781546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4296] KERNEL32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\system32\rundll32.exe[4364] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[4592] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Program Files\iPod\bin\iPodService.exe[4708] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Windows\system32\wbem\wmiprvse.exe[4740] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text ...
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!LdrLoadDll 777D9378 5 Bytes JMP 00F101F8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!LdrUnloadDll 777EB680 5 Bytes JMP 00F103FC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtCreateFile + 6 7781426A 4 Bytes [28, F0, EB, 00] {SUB AL, DH; JMP 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtCreateFile + B 7781426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtMapViewOfSection + 6 778149BA 4 Bytes [28, F3, EB, 00] {SUB BL, DH; JMP 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtMapViewOfSection + B 778149BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenFile + 6 77814A4A 4 Bytes [68, F0, EB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenFile + B 77814A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenProcess + 6 77814ACA 4 Bytes [A8, F1, EB, 00] {TEST AL, 0xf1; JMP 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenProcess + B 77814ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenProcessToken + 6 77814ADA 4 Bytes CALL 768236D0 C:\Windows\system32\SHELL32.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenProcessToken + B 77814ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenProcessTokenEx + 6 77814AEA 4 Bytes [A8, F2, EB, 00] {TEST AL, 0xf2; JMP 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenProcessTokenEx + B 77814AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenThread + 6 77814B3A 4 Bytes [68, F1, EB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenThread + B 77814B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenThreadToken + 6 77814B4A 4 Bytes [68, F2, EB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenThreadToken + B 77814B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenThreadTokenEx + 6 77814B5A 4 Bytes CALL 76823751 C:\Windows\system32\SHELL32.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtOpenThreadTokenEx + B 77814B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtQueryAttributesFile + 6 77814BEA 4 Bytes [A8, F0, EB, 00] {TEST AL, 0xf0; JMP 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtQueryAttributesFile + B 77814BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtQueryFullAttributesFile + 6 77814C9A 4 Bytes CALL 7682388F C:\Windows\system32\SHELL32.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtQueryFullAttributesFile + B 77814C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtSetInformationFile + 6 7781517A 4 Bytes [28, F1, EB, 00] {SUB CL, DH; JMP 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtSetInformationFile + B 7781517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtSetInformationThread + 6 778151CA 4 Bytes [28, F2, EB, 00] {SUB DL, DH; JMP 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtSetInformationThread + B 778151CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtUnmapViewOfSection + 6 7781546A 4 Bytes [68, F3, EB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] ntdll.dll!NtUnmapViewOfSection + B 7781546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5252] KERNEL32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
.text C:\Program Files\HP\HP Photosmart 5510d series\Bin\HPNetworkCommunicator.exe[5692] kernel32.dll!GetBinaryTypeW + 70 75EC252F 1 Byte [62]
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.sys
AttachedDevice \Driver\tdx \Device\Udp aswTdi.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
merci
Eric