Sempre da remoto sto sistemando il PC di una amica.
Aprendo Gmer vedo la dicitura >>>>

La seconda mi preoccupa.
Come avevo già indicato ,ha trovato e rimosso SinowalUomo Senza Sonno ha scritto:Prova ad utilizzare TDSSKiller
Sono con da remoto..un po complicato. Comunque dice che è normale,che è a posto.e dopo fai fare una scansione con lo Stealth Rootkit Detector semplicemente con un doppio click sull'eseguibile. Apparirà un log nella cartella dove è presente l'eseguibile (se il file è in C:\, il log sarà lì, se il file è nel desktop apparirà nel desktop e via dicendo), postalo.
Non posso. Sempre per il motivo di cui sopra.Nota a margine, se vedi che il sistama non si avvia correttamente dopo l'utilizzo di TDSSKiller, effettua un fixboot e fixmbr dalla console di ripristino di windows xp.
Se poi ci sono rimasugli, andremo a toglierli bene con una procedura mirata.
Codice: Seleziona tutto
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD16 rev.11.0 -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
Codice: Seleziona tutto
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000003c
Kernel Drivers (total 161):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E5000 \WINDOWS\system32\hal.dll
0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
0xB9F79000 ACPI.sys
0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xB9F68000 pci.sys
0xBA0A8000 isapnp.sys
0xBA4BC000 compbatt.sys
0xBA4C0000 \WINDOWS\system32\DRIVERS\BATTC.SYS
0xB9F4A000 pcmcia.sys
0xBA0B8000 MountMgr.sys
0xB9F2B000 ftdisk.sys
0xB9F05000 dmio.sys
0xBA328000 PartMgr.sys
0xBA4C4000 ACPIEC.sys
0xBA670000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
0xBA0C8000 VolSnap.sys
0xB9E35000 iaStor.sys
0xBA0D8000 disk.sys
0xBA0E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xB9E15000 fltMgr.sys
0xBA5AC000 DLACDBHM.SYS
0xB9DFE000 DRVMCDB.SYS
0xBA0F8000 PxHelp20.sys
0xB9DE7000 KSecDD.sys
0xB9D5A000 Ntfs.sys
0xB9D2D000 NDIS.sys
0xBA108000 PBADRV.sys
0xBA118000 ohci1394.sys
0xBA128000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
0xB9D13000 Mup.sys
0xB9CEA000 aswVmm.sys
0xBA138000 aswRvrt.sys
0xBA1C8000 \SystemRoot\system32\DRIVERS\nic1394.sys
0xB7E1C000 \SystemRoot\system32\DRIVERS\igxpmp32.sys
0xB7E08000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xBA3C0000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xB7DE4000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xBA3C8000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB7DBC000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xB7A45000 \SystemRoot\system32\DRIVERS\NETw5x32.sys
0xB7A16000 \SystemRoot\system32\DRIVERS\b57xp32.sys
0xB7A02000 \SystemRoot\system32\DRIVERS\sdbus.sys
0xBA2B8000 \SystemRoot\system32\DRIVERS\rimmptsk.sys
0xB8A18000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xB79D5000 \SystemRoot\system32\DRIVERS\Apfiltr.sys
0xB8A08000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS
0xB7943000 \SystemRoot\system32\DRIVERS\Wdf01000.sys
0xBA458000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xBA468000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xB7697000 \SystemRoot\system32\DRIVERS\serial.sys
0xB95C8000 \SystemRoot\system32\DRIVERS\serenum.sys
0xB8988000 \SystemRoot\system32\DRIVERS\imapi.sys
0xB8470000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xB8460000 \SystemRoot\system32\DRIVERS\redbook.sys
0xB7674000 \SystemRoot\system32\DRIVERS\ks.sys
0xB95C0000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0xB95BC000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0xB8450000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB7566000 \SystemRoot\system32\DRIVERS\btkrnl.sys
0xBA73B000 \SystemRoot\system32\DRIVERS\audstub.sys
0xBA612000 \SystemRoot\System32\Drivers\RootMdm.sys
0xBA488000 \SystemRoot\System32\Drivers\Modem.SYS
0xB8420000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xBA580000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB6F73000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xB8410000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xB8400000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xBA490000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB6F62000 \SystemRoot\system32\DRIVERS\psched.sys
0xB83F0000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xBA498000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xBA4A0000 \SystemRoot\system32\DRIVERS\raspti.sys
0xBA4A8000 \SystemRoot\system32\DRIVERS\RimSerial.sys
0xB6F32000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xB83E0000 \SystemRoot\system32\DRIVERS\termdd.sys
0xBA614000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB6EAC000 \SystemRoot\system32\DRIVERS\update.sys
0xBA598000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xB6E98000 \SystemRoot\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys
0xA2894000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xA2814000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xBA5CC000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x9E034000 \SystemRoot\system32\drivers\sthda.sys
0x9E010000 \SystemRoot\system32\drivers\portcls.sys
0xA2804000 \SystemRoot\system32\drivers\drmk.sys
0x9DFF5000 \SystemRoot\system32\drivers\AESTAud.sys
0x9DFC1000 \SystemRoot\system32\DRIVERS\HSFHWAZL.sys
0x9DED0000 \SystemRoot\system32\DRIVERS\HSF_DPV.sys
0x9DE1D000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
0x9DDFD000 \SystemRoot\system32\drivers\IntcHdmi.sys
0x97974000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xA10B5000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x974D5000 \SystemRoot\System32\Drivers\Null.SYS
0x987CF000 \SystemRoot\System32\Drivers\Beep.SYS
0x97850000 \SystemRoot\System32\Drivers\DLARTL_M.SYS
0x9735C000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x97354000 \SystemRoot\System32\drivers\vga.sys
0x987CD000 \SystemRoot\System32\Drivers\mnmdd.SYS
0x987BF000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x97334000 \SystemRoot\System32\Drivers\Msfs.SYS
0x9732C000 \SystemRoot\System32\Drivers\Npfs.SYS
0x9795C000 \SystemRoot\system32\DRIVERS\rasacd.sys
0x96F27000 \SystemRoot\system32\DRIVERS\ipsec.sys
0x96ECE000 \SystemRoot\system32\DRIVERS\tcpip.sys
0x9799A000 \??\C:\WINDOWS\system32\drivers\aswTdi.sys
0x96EA8000 \SystemRoot\system32\DRIVERS\ipnat.sys
0x96E80000 \SystemRoot\system32\DRIVERS\netbt.sys
0x9798A000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x98B67000 \??\C:\WINDOWS\system32\drivers\aswRdr.sys
0x96E5E000 \SystemRoot\System32\drivers\afd.sys
0x98B77000 \SystemRoot\system32\DRIVERS\arp1394.sys
0x98B47000 \SystemRoot\system32\DRIVERS\netbios.sys
0x96E33000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x96DC3000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x98B57000 \SystemRoot\System32\Drivers\Fips.SYS
0x96D63000 \??\C:\WINDOWS\system32\drivers\aswSP.sys
0x96CA3000 \??\C:\WINDOWS\system32\drivers\aswSnx.sys
0x973EA000 \SystemRoot\System32\Drivers\Cdfs.SYS
0x96BD3000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0xBF800000 \SystemRoot\System32\win32k.sys
0xB9CBE000 \SystemRoot\System32\drivers\Dxapi.sys
0xA048B000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA797000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF024000 \SystemRoot\System32\igxpgd32.dll
0xBF012000 \SystemRoot\System32\igxprd32.dll
0xBF04F000 \SystemRoot\System32\igxpdv32.DLL
0xBF280000 \SystemRoot\System32\igxpdx32.DLL
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0x96B6A000 \SystemRoot\system32\DRIVERS\WavxDMgr.sys
0x96B43000 \??\C:\WINDOWS\system32\drivers\aswMonFlt.sys
0xA5868000 \??\C:\WINDOWS\system32\drivers\aswFsBlk.sys
0x9743A000 \SystemRoot\System32\Drivers\DRVNDDM.SYS
0xBA7AF000 \SystemRoot\System32\Drivers\DLADResM.SYS
0x96B2A000 \SystemRoot\System32\Drivers\DLAIFS_M.SYS
0xA5860000 \SystemRoot\System32\Drivers\DLAOPIOM.SYS
0x9F467000 \SystemRoot\System32\Drivers\DLAPoolM.SYS
0xA5858000 \SystemRoot\System32\Drivers\DLABMFSM.SYS
0xA5850000 \SystemRoot\System32\Drivers\DLABOIOM.SYS
0x96B14000 \SystemRoot\System32\Drivers\DLAUDFAM.SYS
0x96AFD000 \SystemRoot\System32\Drivers\DLAUDF_M.SYS
0xB9C7D000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xB9C71000 \SystemRoot\system32\DRIVERS\s24trans.sys
0x969F8000 \SystemRoot\system32\drivers\wdmaud.sys
0x979BA000 \SystemRoot\system32\drivers\sysaudio.sys
0x968DD000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xBA62C000 \??\C:\Programmi\Broadcom\MgmtAgent\BASFND.sys
0x96509000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0x96356000 \SystemRoot\system32\DRIVERS\srv.sys
0x952E9000 \SystemRoot\System32\Drivers\HTTP.sys
0xBA3F0000 \SystemRoot\System32\Drivers\TDTCP.SYS
0x952C6000 \SystemRoot\System32\Drivers\RDPWD.SYS
0x9708B000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x95169000 \SystemRoot\system32\DRIVERS\qcusbser.sys
0x9734C000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x96A95000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0x94D30000 \SystemRoot\system32\drivers\kmixer.sys
0xBA350000 \??\C:\DOCUME~1\angfio\IMPOST~1\Temp\mbr.sys
0x7C910000 \WINDOWS\system32\ntdll.dll
Processes (total 53):
0 System Idle Process
4 System
876 C:\WINDOWS\system32\smss.exe
948 C:\WINDOWS\system32\csrss.exe
976 C:\WINDOWS\system32\winlogon.exe
1020 C:\WINDOWS\system32\services.exe
1032 C:\WINDOWS\system32\lsass.exe
1240 C:\Programmi\Fingerprint Sensor\AtService.exe
1260 C:\WINDOWS\system32\svchost.exe
1328 C:\WINDOWS\system32\svchost.exe
1368 C:\WINDOWS\system32\svchost.exe
1420 C:\Programmi\Intel\WiFi\bin\S24EvMon.exe
1536 C:\WINDOWS\system32\svchost.exe
1580 C:\WINDOWS\system32\svchost.exe
1812 C:\Programmi\AVAST Software\Avast\AvastSvc.exe
1968 C:\WINDOWS\system32\spoolsv.exe
2004 C:\drivers\audio\R190031\stacsv.exe
496 C:\WINDOWS\explorer.exe
696 C:\WINDOWS\system32\svchost.exe
148 C:\Programmi\Dell\Dell ControlPoint\Connection Manager\SMManager.exe
1520 C:\WINDOWS\system32\wbem\wmiprvse.exe
2176 C:\Programmi\Altiris\AClient\ACLIENT.EXE
2196 C:\Programmi\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
2220 C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
2232 C:\Programmi\Dell\Dell ControlPoint\DCPButtonSvc.exe
2328 C:\Programmi\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
2412 C:\Programmi\File comuni\DeviceHelper\DeviceManager.exe
2444 C:\Programmi\Intel\WiFi\bin\EvtEng.exe
2576 C:\Programmi\Intel\Intel Matrix Storage Manager\IAANTmon.exe
2608 C:\Programmi\Java\jre6\bin\jqs.exe
2748 C:\Programmi\lotus\notes\ntmulti.exe
2808 C:\Programmi\File comuni\Intel\WirelessCommon\RegSrvc.exe
3264 C:\Programmi\WIDCOMM\Bluetooth Software\BTTray.exe
3316 C:\WINDOWS\system32\svchost.exe
3344 C:\Programmi\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
3588 C:\Programmi\TeamViewer\Version8\TeamViewer_Service.exe
3644 C:\Programmi\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe
3676 C:\Programmi\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
3688 C:\Programmi\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
3776 C:\Programmi\File comuni\Java\Java Update\jusched.exe
3808 C:\Programmi\AVAST Software\Avast\AvastUI.exe
3864 C:\Programmi\Intel\WiFi\bin\WLKEEPER.exe
3916 C:\WINDOWS\system32\ctfmon.exe
2504 C:\WINDOWS\system32\wbem\wmiapsrv.exe
2684 C:\WINDOWS\system32\alg.exe
620 C:\Programmi\HSPA USB MODEM\HSPA USB MODEM.exe
3208 C:\WINDOWS\system32\wuauclt.exe
920 C:\Programmi\TeamViewer\Version8\TeamViewer.exe
2552 C:\Programmi\TeamViewer\Version8\tv_w32.exe
2208 C:\Programmi\TeamViewer\Version8\TeamViewer_Desktop.exe
4580 C:\Programmi\Mozilla Firefox\firefox.exe
5804 C:\Documents and Settings\angfio\Impostazioni locali\Dati applicazioni\Learnpulse\Screenpresso\Screenpresso.exe
3196 C:\Documents and Settings\angfio\Documenti\Downloads\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`075a9e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000012`9605d000 (NTFS)
PhysicalDrive0 Model Number: WDCWD1600BJKT-75F4T0, Rev: 11.01A11
Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 83E058FFA5EA65E1EA7466377B7F51B9D31D9379
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Poichè sei da remoto, prova ad utilizzare lo strumento e la guida presente in questo link, dovrebbe andare senza problemi.magopenguin ha scritto:..e come faccio?
Ti posso dire con certezza se conviene o meno farlo, ma dovrei controllare sia il settore 0, che gli estremi di partizione con HxD. Se lo installi nel pc che controlli da remoto e mi posti le immagini dei settori posso fare un'analisi accurata e dirti nel caso cosa fare.magopenguin ha scritto: Dici che vale la pena eseguire tutto questo ambaradan?
Non posso che quotare.Uomo Senza Sonno ha scritto:Ti posso dire con certezza se conviene o meno farlo, ma dovrei controllare sia il settore 0, che gli estremi di partizione con HxD. Se lo installi nel pc che controlli da remoto e mi posti le immagini dei settori posso fare un'analisi accurata e dirti nel caso cosa fare.