Tak jsem provedl,
SPTD - tam nešlo kliknout, bylo to neaktivní, takže jsem ignoroval
Defrogger - zde už ano, kliknul jsem na Disable a po několika vteřinách mi to napsalo Finished? Znovu jsem dal Disable a restartoval počítač
MBR - podle návodu, přikládám log, zde by asi mohl být problém...
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 6.1.7601 Disk: FUJITSU_ rev.0084 -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: >>UNKNOWN [0x8304D000]<< >>UNKNOWN [0x8BBB2000]<< >>UNKNOWN [0x8BC00000]<< >>UNKNOWN [0x8B4A5000]<< >>UNKNOWN [0x83016000]<< >>UNKNOWN [0x8B633000]<<
_asm { DEC EBP; POP EDX; NOP ; ADD [EBX], AL; ADD [EAX], AL; ADD [EAX+EAX], AL; ADD [EAX], AL; }
1 ntkrnlpa!IofCallDriver[0x8308452A] -> \Device\Harddisk0\DR0[0x8792E500]
\Driver\Disk[0x8792DA78] -> IRP_MJ_CREATE -> 0x8BBB639F
3 [0x8BBB659E] -> ntkrnlpa!IofCallDriver[0x8308452A] -> [0x866ED958]
\Driver\ACPI[0x8629F648] -> IRP_MJ_CREATE -> 0x8B4AE4CC
5 [0x8B4AE3D4] -> ntkrnlpa!IofCallDriver[0x8308452A] -> \Device\Ide\IAAStorageDevice-0[0x862C0028]
\Driver\iaStor[0x866C0E48] -> IRP_MJ_CREATE -> 0x8B677954
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !