Nod32 non si installa piu...
Inviato: sab lug 07, 2007 10:21 pm
da 4 giorni combatto con sti virus infami... ne avro tolto un 3/4 ... ora
sono arrivato ad eliminare 2 varianti del beagle, quella con voce "rosa" e "hlrrr"
tuttavia quando tento di installare nod, il programma si blocca e non va avanti.
terminando forzatamente la procedura, nonostante non appaia nei programmi installati, e nemmeno si faccia disinstallare, parte e non trova ovviamente i dati per operare....
manco a dirlo, non sono abilitate le scansioni on line..
allego il log di gmer. sperando in un aiuto...
ultimo log
*********************************
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-07-07 21:46:32
Windows 5.1.2600 Service Pack 2
---- Kernel code sections - GMER 1.0.13 ----
? srescan.sys Impossibile trovare il file specificato.
? C:\WINDOWS\system32\Drivers\mchInjDrv.sys Impossibile trovare il file specificato.
---- User code sections - GMER 1.0.13 ----
.text C:\Documents and Settings\Marco\Desktop\gmer.exe[1028] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\explorer.exe[3600] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\system32\notepad.exe[4048] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Programmi\Mozilla Firefox\firefox.exe[4056] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
---- Devices - GMER 1.0.13 ----
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_NAMED_PIPE 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_EA 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_EA 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_VOLUME_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_VOLUME_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DIRECTORY_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FILE_SYSTEM_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_LOCK_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLEANUP 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_MAILSLOT 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_SECURITY 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_SECURITY 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CHANGE 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_QUOTA 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_QUOTA 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 872EE750
Device \Driver\nvatabus \Device\00000080 IRP_MJ_INTERNAL_DEVICE_CONTROL [F76F08B4] sfsync02.sys
Device \Driver\nvatabus \Device\00000081 IRP_MJ_INTERNAL_DEVICE_CONTROL [F76F08B4] sfsync02.sys
Device \Driver\nvatabus \Device\00000082 IRP_MJ_INTERNAL_DEVICE_CONTROL
sono arrivato ad eliminare 2 varianti del beagle, quella con voce "rosa" e "hlrrr"
tuttavia quando tento di installare nod, il programma si blocca e non va avanti.
terminando forzatamente la procedura, nonostante non appaia nei programmi installati, e nemmeno si faccia disinstallare, parte e non trova ovviamente i dati per operare....
manco a dirlo, non sono abilitate le scansioni on line..
allego il log di gmer. sperando in un aiuto...
ultimo log
*********************************
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-07-07 21:46:32
Windows 5.1.2600 Service Pack 2
---- Kernel code sections - GMER 1.0.13 ----
? srescan.sys Impossibile trovare il file specificato.
? C:\WINDOWS\system32\Drivers\mchInjDrv.sys Impossibile trovare il file specificato.
---- User code sections - GMER 1.0.13 ----
.text C:\Documents and Settings\Marco\Desktop\gmer.exe[1028] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\explorer.exe[3600] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\system32\notepad.exe[4048] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Programmi\Mozilla Firefox\firefox.exe[4056] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
---- Devices - GMER 1.0.13 ----
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 872EE750
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 872EE750
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_NAMED_PIPE 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_EA 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_EA 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_VOLUME_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_VOLUME_INFORMATION 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DIRECTORY_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FILE_SYSTEM_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_LOCK_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLEANUP 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_MAILSLOT 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_SECURITY 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_SECURITY 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CHANGE 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_QUOTA 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_QUOTA 872EE750
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 872EE750
Device \Driver\nvatabus \Device\00000080 IRP_MJ_INTERNAL_DEVICE_CONTROL [F76F08B4] sfsync02.sys
Device \Driver\nvatabus \Device\00000081 IRP_MJ_INTERNAL_DEVICE_CONTROL [F76F08B4] sfsync02.sys
Device \Driver\nvatabus \Device\00000082 IRP_MJ_INTERNAL_DEVICE_CONTROL