Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

Ripristinare MBR da infezione rootkit

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

Re: Ripristinare MBR da infezione rootkit

Messaggioda dario-vr » mer nov 18, 2009 8:54 pm

il log di RootkitBuster:

+----------------------------------------------------
| Trend Micro RootkitBuster
| Module version: 2.80.0.1071
+----------------------------------------------------


--== Dump Hidden MBR and Hidden File on C:\ ==--
[HIDDEN_FILE]:
FullPath : C:\acqmod
FullPathLength: 9
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x20
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Documents and Settings\All Users\Dati applicazioni\TEMP\
FullPathLength: 71
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x30
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Documents and Settings\Utente\Documenti\File ricevuti\Thumbs.db
FullPathLength: 66
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x826
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Documents and Settings\Utente\Documenti\funrecent.fmp
FullPathLength: 56
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x800
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Documents and Settings\Utente\Documenti\Immagini\Kodak Pictures\Parigi-Eurodisney2008\Thumbs.db
FullPathLength: 98
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x826
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Documents and Settings\Utente\Documenti\Musica\Canzoni\Gianluca Grignani - La Mia Storia Tra Le Dita.mp3
FullPathLength: 107
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x800
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Documents and Settings\Utente\Documenti\Musica\Canzoni\Renato Zero - Ovunque Sei.mp3
FullPathLength: 87
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x800
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Documents and Settings\Utente\Documenti\Musica\Canzoni\Thumbs.db
FullPathLength: 67
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x826
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Documents and Settings\Utente\Documenti\Musica\iTunes\iTunes Music\Thumbs.db
FullPathLength: 79
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x826
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Documents and Settings\Utente\Documenti\Musica\Thumbs.db
FullPathLength: 59
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x806
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Documents and Settings\Utente\Documenti\RegRun2\Regrun2.rr2
FullPathLength: 62
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x800
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Documents and Settings\Utente\Preferiti\빐£gnalibri non catalogati\Aggiungi account.URL
FullPathLength: 89
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x20
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Documents and Settings\Utente\Preferiti\빐£gnalibri non catalogati\Il mio eBay oggetti che osservi.URL
FullPathLength: 105
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x20
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\HijackThis\HijackThis.exe
FullPathLength: 28
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\Programmi\Windows Media Player\Network Sharing\Thumbs.db
FullPathLength: 59
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x826
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Afrik.bmp
FullPathLength: 42
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Arabic.BMP
FullPathLength: 43
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Catalan.bmp
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Chinese.bmp
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Czech.bmp
FullPathLength: 42
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Deutsch.bmp
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Dutch.bmp
FullPathLength: 42
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\English.bmp
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Español.bmp
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Finnish.bmp
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\French.bmp
FullPathLength: 43
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\frisian.bmp
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Galego.bmp
FullPathLength: 43
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Hungarian.bmp
FullPathLength: 46
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Indonesian.bmp
FullPathLength: 47
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Italiano.bmp
FullPathLength: 45
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Korean.bmp
FullPathLength: 43
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Lithuanian.bmp
FullPathLength: 47
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Malagasy.bmp
FullPathLength: 45
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Norwegian.bmp
FullPathLength: 46
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\persian.bmp
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Polish.bmp
FullPathLength: 43
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Português-BR.bmp
FullPathLength: 49
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Romana.bmp
FullPathLength: 43
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Serbian.bmp
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\Turkish.bmp
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Languages\unknown.bmp
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\license.rtf
FullPathLength: 34
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\mycookies.ini
FullPathLength: 36
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Order.doc
FullPathLength: 32
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\RegHist.txt
FullPathLength: 34
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\RegSeeker.exe
FullPathLength: 36
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\RegSeeker\RegSeeker\Thumbs.db
FullPathLength: 32
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x826
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
FullPathLength: 46
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x800
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
FullPathLength: 45
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x800
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\WINDOWS\$NtServicePackUninstall$\sens.dll
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x800
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\WINDOWS\AvDetected.ini
FullPathLength: 25
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\WINDOWS\bootstat.dat
FullPathLength: 23
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x24
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\WINDOWS\Provisioning\Schemas\branding.xdr
FullPathLength: 44
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\WINDOWS\security\templates\setup security.inf
FullPathLength: 48
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\WINDOWS\system32\drivers\etc\lmhosts.sam
FullPathLength: 43
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x20
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\WINDOWS\system32\drivers\regguard.sys
FullPathLength: 40
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\WINDOWS\system32\nwiz.exe
FullPathLength: 28
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\WINDOWS\system32\ScsiAccess.EXE
FullPathLength: 34
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x20
ShareAccess : 0x0
Type : 0x0
[HIDDEN_FILE]:
FullPath : C:\WINDOWS\system32\wvc1dmod.dll
FullPathLength: 32
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x820
ShareAccess : 0x0
Type : 0x0
75 hidden files found.

--== Dump Hidden Registry Value on HKLM ==--
No hidden registry entries found.


--== Dump Hidden Process ==--
No hidden processes found.

--== Dump Hidden Driver ==--
No hidden drivers found.

uso wilkised perché non riesco a postare il log di Prevx:
log prevx.log

Cosa ne pensi? il computer funziona egregiamente. I programmi di sicurezza installati si aggiornano regolarmente.
Per cui non so... ho letto in giro che quel che scrive mbr.exe potrebe trattarsi anche solo di un residuo di informazione del rootkit rimosso con le precedenti pulizie.
Si impara dagli errori degli altri: non si può vivere cosi' a lungo per farli tutti.
Avatar utente
dario-vr
Senior Member
Senior Member
 
Messaggi: 160
Iscritto il: gio gen 08, 2009 9:59 am
Località: Verona

Precedente

Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 4 ospiti

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising