Salve
Il mio net (XPsp3) ha un tempo di boot piuttosto lunghetto, avast free non rileva anomalie, ho utilizzato una decina di tools e live cd
Poi utilizzando il tool aswMbr ho ottenuto un log ???
aswMBR version 0.9.8.978 Copyright(c) 2011 AVAST Software
Run date: 2011-08-19 22:58:59
22:58:59.890 OS Version: Windows 5.1.2600 Service Pack 3
22:58:59.890 Number of processors: 2 586 0x1C02
22:58:59.890 ComputerName: VULCAN UserName: nicola
22:59:11.203 Initialize success
22:59:18.750 AVAST engine defs: 11081900
22:59:32.671 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IAAStorageDevice-0
22:59:32.687 Disk 0 Vendor: WDC_WD16 13.0 Size: 152627MB BusType: 3
22:59:32.703 Disk 0 MBR read successfully
22:59:32.718 Disk 0 MBR scan
22:59:32.781 Disk 0 Windows VISTA default MBR code
22:59:32.796 Disk 0 scanning sectors +312581808
22:59:33.203 Disk 0 scanning C:\WINDOWS\system32\drivers
22:59:47.328 Service scanning
22:59:48.906 Modules scanning
22:59:59.703 Disk 0 trace - called modules:
22:59:59.734 ntkrnlpa.exe CLASSPNP.SYS disk.sys SahdIa32.sys iaStor.sys hal.dll
22:59:59.734 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x86378030]
22:59:59.734 3 CLASSPNP.SYS[f75c8fd7] → nt!IofCallDriver → [0x8637c478]
22:59:59.750 5 SahdIa32.sys[f75e9939] → nt!IofCallDriver → \Device\Ide\IAAStorageDevice-0[0x8636a028]
23:00:00.921 AVAST engine scan C:\WINDOWS
23:00:05.609 AVAST engine scan C:\WINDOWS\system32
23:01:38.578 AVAST engine scan C:\WINDOWS\system32\drivers
23:01:54.140 AVAST engine scan C:\Documents and Settings\nicola
23:02:55.109 AVAST engine scan C:\Documents and Settings\All Users
23:03:04.203 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\nicola\Documenti\MBR.dat”
23:03:04.203 The log file has been saved successfully to “C:\Documents and Settings\nicola\Documenti\aswMBR.txt”
Si tratta do rootkit sull’ MBR? >:(
Niente neppure dai tool specializzati
Come è possibile che mi legga su XP l’Mbr di Vista?