Scan complete : voilou :
GMER 2.1.19357 -
http://www.gmer.net
Rootkit scan 2014-06-02 21:00:15
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk1\DR1 - \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HDS721010CLA332 rev.JP4OA3EA 931,51GB
Running: pfkcvx9w.exe; Driver: C:\Users\OPOSSU~1\AppData\Local\Temp\ffkoipoc.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000153f00 7 bytes [00, 98, F3, FF, 01, A6, F0]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff96000153f08 3 bytes [C0, 06, 02]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Trend Micro\RUBotted\RUBotSrv.exe[2600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075511465 2 bytes [51, 75]
.text C:\Program Files (x86)\Trend Micro\RUBotted\RUBotSrv.exe[2600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000755114bb 2 bytes [51, 75]
.text ... * 2
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075511465 2 bytes [51, 75]
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000755114bb 2 bytes [51, 75]
.text ... * 2
---- Kernel IAT/EAT - GMER 2.1 ----
IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [fffff88001024e94] \SystemRoot\System32\Drivers\sptd.sys [.text]
IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [fffff88001024c38] \SystemRoot\System32\Drivers\sptd.sys [.text]
IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [fffff88001025614] \SystemRoot\System32\Drivers\sptd.sys [.text]
IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUlong] [fffff88001025a10] \SystemRoot\System32\Drivers\sptd.sys [.text]
IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [fffff8800102586c] \SystemRoot\System32\Drivers\sptd.sys [.text]
---- Devices - GMER 2.1 ----
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 fffffa80066e12c0
Device \Driver\atapi \Device\Ide\IdePort0 fffffa80066e12c0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-5 fffffa80066e12c0
Device \Driver\atapi \Device\Ide\IdePort1 fffffa80066e12c0
Device \Driver\atapi \Device\Ide\IdePort2 fffffa80066e12c0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-2 fffffa80066e12c0
Device \Driver\atapi \Device\Ide\IdePort3 fffffa80066e12c0
Device \FileSystem\Ntfs \Ntfs fffffa80066e72c0
Device \Driver\NetBT \Device\NetBT_Tcpip_{74F7EA67-75FA-4560-8FD9-27DE3D2C3548} fffffa8007ebd2c0
Device \Driver\usbehci \Device\USBPDO-1 fffffa8007e002c0
Device \Driver\cdrom \Device\CdRom0 fffffa8007eb72c0
Device \Driver\cdrom \Device\CdRom1 fffffa8007eb72c0
Device \Driver\usbehci \Device\USBFDO-0 fffffa8007e002c0
Device \Driver\dtsoftbus01 \Device\DTSoftBusCtl fffffa80078a52c0
Device \Driver\usbehci \Device\USBFDO-1 fffffa8007e002c0
Device \Driver\NetBT \Device\NetBt_Wins_Export fffffa8007ebd2c0
Device \Driver\usbehci \Device\USBPDO-0 fffffa8007e002c0
Device \Driver\atapi \Device\ScsiPort1 fffffa80066e12c0
Device \Driver\atapi \Device\ScsiPort2 fffffa80066e12c0
Device \Driver\atapi \Device\ScsiPort3 fffffa80066e12c0
Device \Driver\atapi \Device\ScsiPort4 fffffa80066e12c0
Device \Driver\dtsoftbus01 \Device\0000006e fffffa80078a52c0
---- Trace I/O - GMER 2.1 ----
Trace ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys UNKNOWN [0xfffffa80066e12c0]Trace 1 nt!IofCallDriver - \Device\Harddisk1\DR1[0xfffffa8007811060] fffffa8007811060
Trace 3 CLASSPNP.SYS[fffff88001b1c43f] - nt!IofCallDriver - [0xfffffa8007538520] fffffa8007538520
Trace 5 ACPI.sys[fffff8800114b7a1] - nt!IofCallDriver - \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8007515060] fffffa8007515060
Trace \Driver\atapi[0xfffffa80074f7550] - IRP_MJ_CREATE - 0xfffffa80066e12c0 fffffa80066e12c0
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x88 0x26 0xA5 0x6E ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x77 0x89 0x02 0x7C ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD0 0x25 0xFC 0x35 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF1 0x44 0x73 0x12 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3A 0xF3 0xE8 0x6F ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice@Progid WMP11.AssocFile.WMD
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice@Progid WMP11.AssocFile.WMS
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice@Progid ChromeHTML
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice@Progid ChromeHTML
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C81AFF6B-B37B-6772-FF3B-550CAEA4BE22}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C81AFF6B-B37B-6772-FF3B-550CAEA4BE22}@oahdahiepepknkajcpgihdhnpoddal 0x6A 0x61 0x61 0x6D ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C81AFF6B-B37B-6772-FF3B-550CAEA4BE22}@pancniheimdeckfagnidmehiehbonhkl 0x6A 0x61 0x61 0x6D ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C81AFF6B-B37B-6772-FF3B-550CAEA4BE22}@oahdahiepepknkajcpgihdhnbpnbpi 0x6A 0x61 0x61 0x6D ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C81AFF6B-B37B-6772-FF3B-550CAEA4BE22}@oappghdbeicgfellmcmkkgbnnilpfh 0x66 0x61 0x6B 0x61 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C81AFF6B-B37B-6772-FF3B-550CAEA4BE22}@nanagpimnkankicgjmmpcdpgpapa 0x66 0x61 0x70 0x63 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C81AFF6B-B37B-6772-FF3B-550CAEA4BE22}@abkampkjacjcbpipejifgohhangfbbgmlg 0x64 0x62 0x6B 0x62 ...
---- EOF - GMER 2.1 ----