drugofighters
Utente Attivo
- Messaggi
- 317
- Reazioni
- 1
- Punteggio
- 39
Salve, facendo una scansione sia con Gmer che con avira anti-rootkit mi sono stati segnalati dei rootkit.Ecco il report delle due scansioni:
GMER 1.0.15.15640 - GMER - Rootkit Detector and Remover
Rootkit quick scan 2011-06-04 15:53:01
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 Nikimi_NIK-XV400A rev.A93.0500
Running: yowniu0n.exe; Driver: C:\DOCUME~1\gilberto\IMPOST~1\Temp\kgayrpoc.sys
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 MBR read error
Disk \Device\Harddisk0\DR0 MBR BIOS signature not found 0
---- System - GMER 1.0.15 ----
SSDT spro.sys ZwEnumerateKey [0xF75AAE4C]
SSDT spro.sys ZwEnumerateValueKey [0xF75AB1DA]
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 [F74E4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F74E4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F74E4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F74E4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F74E4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \FileSystem\Ntfs \Ntfs 82B711F8
Device \FileSystem\Fastfat \Fat 829C6470
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
Avira AntiRootkit Tool (1.3.0.1)
========================================================================================================
- Scan started sabato 4 giugno 2011 - 15.31.38
========================================================================================================
--------------------------------------------------------------------------------------------------------
Configuration:
--------------------------------------------------------------------------------------------------------
- [X] Scan files
- [X] Scan registry
- [X] Scan processes
- [ ] Fast scan
- Working disk total size : 37.27 GB
- Working disk free size : 29.86 GB (80 %)
--------------------------------------------------------------------------------------------------------
Results:
Value data length mismatch (16 <> 20): HKEY_USERS\S-1-5-21-1060284298-839522115-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs -> mrulistex
Value data mismatch : HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> parseautoexec
Hidden value : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc\Config\Standalone -> drivelist
--------------------------------------------------------------------------------------------------------
Files: 0/13501
Registry items: 3/194265
Processes: 0/34
Scan time: 00:06:36
--------------------------------------------------------------------------------------------------------
Active processes:
- System (PID 4)
- winlogon.exe (PID 528)
- svchost.exe (PID 908)
- svchost.exe (PID 1928)
- iexplore.exe (PID 2172)
- csrss.exe (PID 504)
- avshadow.exe (PID 208)
- wuauclt.exe (PID 2632)
- vssvc.exe (PID 3084)
- avguard.exe (PID 1600)
- svchost.exe (PID 1036)
- services.exe (PID 572)
- iexplore.exe (PID 2368)
- smss.exe (PID 456)
- explorer.exe (PID 1256)
- jqs.exe (PID 1664)
- lsass.exe (PID 584)
- spoolsv.exe (PID 1284)
- nmjrmrvn.exe (PID 2696) (Avira AntiRootkit Tool)
- svchost.exe (PID 752)
- svchost.exe (PID 812)
- dllhost.exe (PID 3136)
- svchost.exe (PID 968)
- alg.exe (PID 900)
- taskmgr.exe (PID 2916)
- sched.exe (PID 1368)
- avgnt.exe (PID 1512)
- wmiprvse.exe (PID 3988)
- srvany.exe (PID 1692)
- NMSAccessU.exe (PID 1716)
- WanMiniport1st_srv.exe (PID 1728)
- avirarkd.exe (PID 2596)
- dllhost.exe (PID 3228)
- msdtc.exe (PID 3464)
========================================================================================================
- Scan finished sabato 4 giugno 2011 - 15.38.15
========================================================================================================
Vorrei un chiarimento grazie
GMER 1.0.15.15640 - GMER - Rootkit Detector and Remover
Rootkit quick scan 2011-06-04 15:53:01
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 Nikimi_NIK-XV400A rev.A93.0500
Running: yowniu0n.exe; Driver: C:\DOCUME~1\gilberto\IMPOST~1\Temp\kgayrpoc.sys
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 MBR read error
Disk \Device\Harddisk0\DR0 MBR BIOS signature not found 0
---- System - GMER 1.0.15 ----
SSDT spro.sys ZwEnumerateKey [0xF75AAE4C]
SSDT spro.sys ZwEnumerateValueKey [0xF75AB1DA]
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 [F74E4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F74E4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F74E4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F74E4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F74E4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \FileSystem\Ntfs \Ntfs 82B711F8
Device \FileSystem\Fastfat \Fat 829C6470
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
Avira AntiRootkit Tool (1.3.0.1)
========================================================================================================
- Scan started sabato 4 giugno 2011 - 15.31.38
========================================================================================================
--------------------------------------------------------------------------------------------------------
Configuration:
--------------------------------------------------------------------------------------------------------
- [X] Scan files
- [X] Scan registry
- [X] Scan processes
- [ ] Fast scan
- Working disk total size : 37.27 GB
- Working disk free size : 29.86 GB (80 %)
--------------------------------------------------------------------------------------------------------
Results:
Value data length mismatch (16 <> 20): HKEY_USERS\S-1-5-21-1060284298-839522115-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs -> mrulistex
Value data mismatch : HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -> parseautoexec
Hidden value : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc\Config\Standalone -> drivelist
--------------------------------------------------------------------------------------------------------
Files: 0/13501
Registry items: 3/194265
Processes: 0/34
Scan time: 00:06:36
--------------------------------------------------------------------------------------------------------
Active processes:
- System (PID 4)
- winlogon.exe (PID 528)
- svchost.exe (PID 908)
- svchost.exe (PID 1928)
- iexplore.exe (PID 2172)
- csrss.exe (PID 504)
- avshadow.exe (PID 208)
- wuauclt.exe (PID 2632)
- vssvc.exe (PID 3084)
- avguard.exe (PID 1600)
- svchost.exe (PID 1036)
- services.exe (PID 572)
- iexplore.exe (PID 2368)
- smss.exe (PID 456)
- explorer.exe (PID 1256)
- jqs.exe (PID 1664)
- lsass.exe (PID 584)
- spoolsv.exe (PID 1284)
- nmjrmrvn.exe (PID 2696) (Avira AntiRootkit Tool)
- svchost.exe (PID 752)
- svchost.exe (PID 812)
- dllhost.exe (PID 3136)
- svchost.exe (PID 968)
- alg.exe (PID 900)
- taskmgr.exe (PID 2916)
- sched.exe (PID 1368)
- avgnt.exe (PID 1512)
- wmiprvse.exe (PID 3988)
- srvany.exe (PID 1692)
- NMSAccessU.exe (PID 1716)
- WanMiniport1st_srv.exe (PID 1728)
- avirarkd.exe (PID 2596)
- dllhost.exe (PID 3228)
- msdtc.exe (PID 3464)
========================================================================================================
- Scan finished sabato 4 giugno 2011 - 15.38.15
========================================================================================================
Vorrei un chiarimento grazie