MeridianEX
15-09-2009, 16:05
Ciao a tutti,
gmer ha rilevato un servizio pericoloso ma non so cosa devo fare per eliminarlo. Ho provato a fare disattiva servizio da GMER ma al riavvio tutto come prima. Ho fatto la scansione e la tentata rimozione in modalità provvisoria. Come antivirus ho avira e quando non sono in modalità provvisoria mi mostra tante finestre di avviso di trovata infezione ma nonostante dica di bloccare l'accesso e di ricordare la scelta continua a sbucare una volta ogni 3-4 minuti. Vi prego aiutatemi!!!! Grazie in anticipo.
Ecco il log:
GMER 1.0.15.15086 - http://www.gmer.net
Rootkit scan 2009-09-15 15:56:34
Windows 6.0.6002 Service Pack 2
Running: 2mt526wb.exe; Driver: C:\Users\Antonio\AppData\Local\Temp\aujasnkj.sys
---- System - GMER 1.0.15 ----
Code 8CC70C18 ZwEnumerateKey
Code 8C7DB2D0 ZwFlushInstructionCache
Code 8C7D92BE ZwSaveKey
Code 8C7D02C6 ZwSaveKeyEx
Code 8558695D IofCallDriver
Code 8C7CC32E IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCallDriver 81C4D912 5 Bytes JMP 85586962
.text ntkrnlpa.exe!IofCompleteRequest 81C4D97F 5 Bytes JMP 8C7CC333
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 81DB8EF5 5 Bytes JMP 8C7DB2D4
PAGE ntkrnlpa.exe!ZwEnumerateKey 81E060BA 5 Bytes JMP 8CC70C1C
PAGE ntkrnlpa.exe!ZwSaveKey 81E5B969 5 Bytes JMP 8C7D92C2
PAGE ntkrnlpa.exe!ZwSaveKeyEx 81E5BB07 5 Bytes JMP 8C7D02CA
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Gestione filtri file system Microsoft/Microsoft Corporation)
---- Services - GMER 1.0.15 ----
Service C:\Windows\system32\drivers\rotscxmdhndocy.sys (*** hidden *** ) [SYSTEM] rotscxxpsbgnba <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001bfb56facb
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e3d3a15ae
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba@imagepath \systemroot\system32\drivers\rotscxmdhndocy.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main@aid 10072
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main\injector@* rotscxwsp8.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\drivers\rotscxmdhndocy.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxncxfosid.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxxdeeybem.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxqpwnqeqn.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxebnuivwv.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxtwxtvfpa.dll
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001bfb56facb (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001e3d3a15ae (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba@imagepath \systemroot\system32\drivers\rotscxmdhndocy.sys
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main@aid 10072
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main@sid 0
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main\injector@* rotscxwsp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\drivers\rotscxmdhndocy.sys
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxncxfosid.dat
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxxdeeybem.dat
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxqpwnqeqn.dll
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxebnuivwv.dll
---- Files - GMER 1.0.15 ----
File C:\Windows\System32\drivers\rotscxmdhndocy.sys 69632 bytes <-- ROOTKIT !!!
File C:\Windows\System32\rotscxbojipcos.dll 20480 bytes
File C:\Windows\System32\rotscxebnuivwv.dll 20480 bytes
File C:\Windows\System32\rotscxjieuexdj.dat 43 bytes
File C:\Windows\System32\rotscxncxfosid.dat 43 bytes
File C:\Windows\System32\rotscxqpwnqeqn.dll 44544 bytes
File C:\Windows\System32\rotscxtqmiydck.dat 8848 bytes
File C:\Windows\System32\rotscxtwxtvfpa.dll 19456 bytes executable
File C:\Windows\System32\rotscxvewfqtup.dll 19456 bytes executable
File C:\Windows\System32\rotscxxdeeybem.dat 2368 bytes
File C:\Windows\System32\rotscxxsqweker.dll 44544 bytes
---- EOF - GMER 1.0.15 ----
gmer ha rilevato un servizio pericoloso ma non so cosa devo fare per eliminarlo. Ho provato a fare disattiva servizio da GMER ma al riavvio tutto come prima. Ho fatto la scansione e la tentata rimozione in modalità provvisoria. Come antivirus ho avira e quando non sono in modalità provvisoria mi mostra tante finestre di avviso di trovata infezione ma nonostante dica di bloccare l'accesso e di ricordare la scelta continua a sbucare una volta ogni 3-4 minuti. Vi prego aiutatemi!!!! Grazie in anticipo.
Ecco il log:
GMER 1.0.15.15086 - http://www.gmer.net
Rootkit scan 2009-09-15 15:56:34
Windows 6.0.6002 Service Pack 2
Running: 2mt526wb.exe; Driver: C:\Users\Antonio\AppData\Local\Temp\aujasnkj.sys
---- System - GMER 1.0.15 ----
Code 8CC70C18 ZwEnumerateKey
Code 8C7DB2D0 ZwFlushInstructionCache
Code 8C7D92BE ZwSaveKey
Code 8C7D02C6 ZwSaveKeyEx
Code 8558695D IofCallDriver
Code 8C7CC32E IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCallDriver 81C4D912 5 Bytes JMP 85586962
.text ntkrnlpa.exe!IofCompleteRequest 81C4D97F 5 Bytes JMP 8C7CC333
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 81DB8EF5 5 Bytes JMP 8C7DB2D4
PAGE ntkrnlpa.exe!ZwEnumerateKey 81E060BA 5 Bytes JMP 8CC70C1C
PAGE ntkrnlpa.exe!ZwSaveKey 81E5B969 5 Bytes JMP 8C7D92C2
PAGE ntkrnlpa.exe!ZwSaveKeyEx 81E5BB07 5 Bytes JMP 8C7D02CA
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Gestione filtri file system Microsoft/Microsoft Corporation)
---- Services - GMER 1.0.15 ----
Service C:\Windows\system32\drivers\rotscxmdhndocy.sys (*** hidden *** ) [SYSTEM] rotscxxpsbgnba <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001bfb56facb
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e3d3a15ae
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba@imagepath \systemroot\system32\drivers\rotscxmdhndocy.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main@aid 10072
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main\injector@* rotscxwsp8.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\drivers\rotscxmdhndocy.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxncxfosid.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxxdeeybem.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxqpwnqeqn.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxebnuivwv.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxtwxtvfpa.dll
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001bfb56facb (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001e3d3a15ae (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba@imagepath \systemroot\system32\drivers\rotscxmdhndocy.sys
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main@aid 10072
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main@sid 0
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main\injector@* rotscxwsp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\drivers\rotscxmdhndocy.sys
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxncxfosid.dat
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxxdeeybem.dat
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxqpwnqeqn.dll
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxxpsbgnba\[email protected] \systemroot\system32\rotscxebnuivwv.dll
---- Files - GMER 1.0.15 ----
File C:\Windows\System32\drivers\rotscxmdhndocy.sys 69632 bytes <-- ROOTKIT !!!
File C:\Windows\System32\rotscxbojipcos.dll 20480 bytes
File C:\Windows\System32\rotscxebnuivwv.dll 20480 bytes
File C:\Windows\System32\rotscxjieuexdj.dat 43 bytes
File C:\Windows\System32\rotscxncxfosid.dat 43 bytes
File C:\Windows\System32\rotscxqpwnqeqn.dll 44544 bytes
File C:\Windows\System32\rotscxtqmiydck.dat 8848 bytes
File C:\Windows\System32\rotscxtwxtvfpa.dll 19456 bytes executable
File C:\Windows\System32\rotscxvewfqtup.dll 19456 bytes executable
File C:\Windows\System32\rotscxxdeeybem.dat 2368 bytes
File C:\Windows\System32\rotscxxsqweker.dll 44544 bytes
---- EOF - GMER 1.0.15 ----