nepoznata particija

1

nepoznata particija

offline
  • ljupco
  • Pridružio: 22 Jan 2009
  • Poruke: 18
  • Gde živiš: bitola

zdravo:
nedavno sam preinstalirao kom ali upotrebom nekog stika(usb) nakacio sam nesto! onda se pojavila nova particia E: neznam kako a u D: particii pojavio se autorun.inf folder koji nemogu izbrisati, a i AV stalno izbacue upozorenje za blokadu tog naslova
pozdrav

[Link mogu videti samo ulogovani korisnici]



offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Pozdrav orkabitola!








Arrow

Okaci detekcije Avire da pogledamo o cemu je rec.
Za pravljenje SS-a pogledaj sledeci link: [Link mogu videti samo ulogovani korisnici]




Arrow

Okaci sadrzaj Extras.txt log-a koji je napravljen pokretanjem OTL-a.
Log se nalazi (najverovatnije) na Desktop-u.





goran9888 (AMF Tim)



offline
  • ljupco
  • Pridružio: 22 Jan 2009
  • Poruke: 18
  • Gde živiš: bitola

avira detektira ovo samo kada idem u d: particiu
[Link mogu videti samo ulogovani korisnici]







offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Arrow


- Preuzmi USBNoRisk na Desktop i pokreni ga duplim klikom na ikonicu programa.
- Sacekaj koji sekund dok program izvrsi inicijalno skeniranje.
- Ubacuj sve USB memorijske uredjaje redom u USB slot i svaki zadrzi u slotu po 10 sekundi.
- Ukoliko imas vise uredjaja za proveru, onda na parcetu papira zapisi kojim redom su ubacivani jer ce nam kasnije trebati taj podatak
- Kada zavrsis sa svim uredjajima, klikni desno dugme misa na sred prozora programa i odaberi opciju Save scrambled log. To ce automatski otvoriti log u Notepadu. Iskopiraj nam taj log iz Notepada na forum.

Objasnjenje: U USB memorijske uredjaje spadaju svi oni uredjaji koji po prikljucivanju na kompjuter dobijaju svoju oznaku particije. Tu spadaju USB flash drajvovi, eksterni hard-diskovi, memorijske kartice, MP3 i MP4 plejeri, neki mobilni telefoni, neki GPS (navigacioni) uredjaji itd.

offline
  • ljupco
  • Pridružio: 22 Jan 2009
  • Poruke: 18
  • Gde živiš: bitola

zdravo gorane:
prvi memoriski uredjaj sam pre ovoga ocistio ( mislim ) za ostale neznam..ova tri uredjaja najvise koristim ostalo ne
pozdrav
p.s.
ako je prvi uredjaj cist ..onda drugi cu da formatiram ili icistiti sa avirom
[Link mogu videti samo ulogovani korisnici]


USBNoRisk 2.7 (28 December 2010) by bobby

Started at 08.01.2011 18:24:55

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
C: {ead74d0c-18ef-11e0-afe9-806e6f6e6963}
D: {ead74d0d-18ef-11e0-afe9-806e6f6e6963}
E: {ead74d0e-18ef-11e0-afe9-806e6f6e6963}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for ead74d0c-18ef-11e0-afe9-806e6f6e6963
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for ead74d0d-18ef-11e0-afe9-806e6f6e6963
No Desktop.ini files found on D:
----------------------------------------

No blocked files found on E:
No autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for ead74d0e-18ef-11e0-afe9-806e6f6e6963
No Desktop.ini files found on E:
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 08.01.2011 18:25:02

Scanning for connected USB mass storage...
----------------------------------------
G: {a90b23fd-18f4-11e0-ac41-00e0b100e317}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
Sanitized mountpoint for a90b23fd-18f4-11e0-ac41-00e0b100e317
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

.lnk/.pif/.com/.scr files found on drive G:
========================================

========================================
Removed G:
========================================


New device connected at 08.01.2011 18:25:17

Scanning for connected USB mass storage...
----------------------------------------
G: {9c13b122-18ab-11e0-ac02-00e0b100e317}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
Blocked file found: G:\autorun.inf.blocked
----------------------------------------
----------------------------------------
Could not open G:\autorun.inf.blocked to read the content
File lock detected:
USBNoRisk cannot find what locked the file
----------------------------------------

----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 9c13b122-18ab-11e0-ac02-00e0b100e317
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

.lnk/.pif/.com/.scr files found on drive G:
========================================

========================================
Removed G:
========================================

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Slobodno prikljuci i te ciste USB memorijske uredjaje da ih proverimo. Najbolje je da ih mi ocistimo, jer nekada ni sam AV ne moze bas najbolje da se snadje sa USB memorijskim uredjajima i vrlo cesto dopusti reinfekciju. Samo detaljno isprati Uputstvo koje sam ti dao u prethodnoj poruci.

Ja u log-u vidim da si skenirao USB No Risk-om samo dva USB memorijska uredjaja, pa bih te zamolio da ponovis postupak za sve uredjaje i napises redosled prikljucivanja, ukoliko zelis.









goran9888 (AMF Tim)

offline
  • ljupco
  • Pridružio: 22 Jan 2009
  • Poruke: 18
  • Gde živiš: bitola

zdravo
evo ponovo sam skenirao stikove i konstatirao da treci ne valja..pokvario se.Mobitel sam stavio ali ne verujem da sadrzi virus (sonyericsson w705)Malo sam analizirao aviru i video da virus imenom W32/Sality ide u exe failove i sve (vecinom) mi zarazio a onda avirom sam obrisao sa d: particiu a i sa stika prvog koga sam skenirao avirom..drugi stik nije jos skeniran
pozz
[Link mogu videti samo ulogovani korisnici]


USBNoRisk 2.7 (28 December 2010) by bobby

Started at 09.01.2011 10:18:45

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
C: {ead74d0c-18ef-11e0-afe9-806e6f6e6963}
D: {ead74d0d-18ef-11e0-afe9-806e6f6e6963}
E: {ead74d0e-18ef-11e0-afe9-806e6f6e6963}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for ead74d0c-18ef-11e0-afe9-806e6f6e6963
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for ead74d0d-18ef-11e0-afe9-806e6f6e6963
No Desktop.ini files found on D:
----------------------------------------

No blocked files found on E:
No autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for ead74d0e-18ef-11e0-afe9-806e6f6e6963
No Desktop.ini files found on E:
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 09.01.2011 10:18:54

Scanning for connected USB mass storage...
----------------------------------------
G: {a90b23fd-18f4-11e0-ac41-00e0b100e317}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
Sanitized mountpoint for a90b23fd-18f4-11e0-ac41-00e0b100e317
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

.lnk/.pif/.com/.scr files found on drive G:
========================================

========================================
Removed G:
========================================


New device connected at 09.01.2011 10:19:02

Scanning for connected USB mass storage...
----------------------------------------
G: {9c13b122-18ab-11e0-ac02-00e0b100e317}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
Blocked file found: G:\autorun.inf.blocked
----------------------------------------
----------------------------------------
Could not open G:\autorun.inf.blocked to read the content
File lock detected:
USBNoRisk cannot find what locked the file
----------------------------------------

----------------------------------------
No autorun.inf files found on G:
Sanitized mountpoint for 9c13b122-18ab-11e0-ac02-00e0b100e317
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

.lnk/.pif/.com/.scr files found on drive G:
========================================

========================================
Removed G:
========================================
========================================

========================================
========================================

========================================
========================================

========================================
========================================

========================================

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Arrow


Okaci mi sliku karantina Avire da pogledam.




Arrow


Vidoh da koristis Malwarebytes Anti-Malware. Update-uj ga, izaberi opciju Perform Quick Scan i klikni na Scan. Po zavrsetku procesa klikni OK, Show Results: u listi detektovanog malware-a (ukoliko ga bude bilo), obelezi sve stavke i klikni Remove Selected. Okaci mi sadrzaj log-a koji ti bude izasao uz sledecu poruku.



----------------------




Arrow Postupak ponoviti za ta dva USB memorijska uredjaja koja si u prethodnom koraku prikljucivao



- Pokrenuti USBNoRisk i sačekati da izvrši inicijalno skeniranje.

- Po završetku inicijalnog skeniranja priključiti USB memorijski uređaj.

- Kliknuti na karticu Script;

U beli okvir prozora iskopirati sledeći tekst:

{a90b23fd-18f4-11e0-ac41-00e0b100e317}
folder_list:%DRIVE%
no_sh

{9c13b122-18ab-11e0-ac02-00e0b100e317}
delete_blocked:
folder_list:%DRIVE%
no_sh

{ead74d0d-18ef-11e0-afe9-806e6f6e6963}
folder_list:%DRIVE%autorun.inf


- Izvršiti komandu klikom na taster Run Script;



Po izvršenju komande USBNoRisk će se automatski vratiti na karticu Monitor;

- Uraditi desni klik unutar belog okvira prozora i odabrati opciju Save Scrambled Log;

Otvoriće se prozor Notepad_a sa tekstom koji je potrebno iskopirati ovde u poruci.






goran9888 (AMF Tim)

offline
  • ljupco
  • Pridružio: 22 Jan 2009
  • Poruke: 18
  • Gde živiš: bitola

Napisano: 09 Jan 2011 22:47

zdravo:
Malwarebytes Anti-Malware nije nasao nista..usb sam prosao kako si rekao ali samo jedno..izvini puno ali drugo nije tu sutra cu ovo isto ponoviti sa njim ..slika karantina je delic celog karantina neznam kako da sav sadrzaj karantina snimim
pozz..

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]








USBNoRisk 2.7 (28 December 2010) by bobby

Started at 09.01.2011 22:18:17

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
C: {ead74d0c-18ef-11e0-afe9-806e6f6e6963}
D: {ead74d0d-18ef-11e0-afe9-806e6f6e6963}
E: {ead74d0e-18ef-11e0-afe9-806e6f6e6963}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for ead74d0c-18ef-11e0-afe9-806e6f6e6963
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for ead74d0d-18ef-11e0-afe9-806e6f6e6963
No Desktop.ini files found on D:
----------------------------------------

No blocked files found on E:
No autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for ead74d0e-18ef-11e0-afe9-806e6f6e6963
No Desktop.ini files found on E:
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 09.01.2011 22:18:38

Scanning for connected USB mass storage...
----------------------------------------
H: {a90b23fd-18f4-11e0-ac41-00e0b100e317}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No autorun.inf files found on H:
Sanitized mountpoint for a90b23fd-18f4-11e0-ac41-00e0b100e317
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
----------------------------------------

.lnk/.pif/.com/.scr files found on drive H:
========================================


Processing script
----------------------------------------
a90b23fd-18f4-11e0-ac41-00e0b100e317
Drive letter for GUID: H:
SectionStart = 0
SectionEnd = 3
----------------------------------------
Folder list for H:\:
----------------------------------------

--a--   107   H:\(2).txt   H:\(2).txt
--a--   151   H:\1.txt   H:\1.txt
--a--   23197   H:\3.jpg   H:\3.jpg
--a--   350   H:\3.TXT   H:\3.TXT
--a--   296   H:\4.txt   H:\4.txt
d----   0   H:\ALATZA~1   H:\alat za spy
--a--   2764121   H:\DSC07612.JPG   H:\DSC07612.JPG
--a--   2747902   H:\DSC07613.JPG   H:\DSC07613.JPG
--a--   2763670   H:\DSC07614.JPG   H:\DSC07614.JPG
--a--   2799113   H:\DSC07615.JPG   H:\DSC07615.JPG
--a--   2753064   H:\DSC07616.JPG   H:\DSC07616.JPG
--a--   2809012   H:\DSC07617.JPG   H:\DSC07617.JPG
--a--   2810409   H:\DSC07618.JPG   H:\DSC07618.JPG
--a--   2699561   H:\DSC07619.JPG   H:\DSC07619.JPG
--a--   2650772   H:\DSC07620.JPG   H:\DSC07620.JPG
--a--   2881364   H:\DSC07621.JPG   H:\DSC07621.JPG
--a--   2705283   H:\DSC07622.JPG   H:\DSC07622.JPG
--a--   2793813   H:\DSC07623.JPG   H:\DSC07623.JPG
--a--   2632694   H:\DSC07624.JPG   H:\DSC07624.JPG
--a--   2711531   H:\DSC07625.JPG   H:\DSC07625.JPG
--a--   2528830   H:\DSC07626.JPG   H:\DSC07626.JPG
--a--   2723752   H:\DSC07627.JPG   H:\DSC07627.JPG
--a--   2783372   H:\DSC07628.JPG   H:\DSC07628.JPG
--a--   2899596   H:\DSC07629.JPG   H:\DSC07629.JPG
--a--   2738241   H:\DSC07630.JPG   H:\DSC07630.JPG
dr---   0   H:\FAVORI~1   H:\Favorites
d----   0   H:\GOCE   H:\GOCE
d----   0   H:\KAKODA~1   H:\KAKO DA NAPRAVIS
--a--   48962   H:\LAGER0~1.TXT   H:\lager 03.01.2011.txt
--a--   49041   H:\LAGER3~1.TXT   H:\lager 31.12.2010.txt
--a--   1464   H:\MINUS3~1.TXT   H:\minus 31.12.2010.txt
dr-hs   0   H:\myfolder   H:\myfolder
--a--   142   H:\NEWTEX~1.TXT   H:\New Text Document.txt
--a--   88046920   H:\NORMAN~1.EXE   H:\Norman_Malware_Cleaner_1.exe
d----   0   H:\PARTIT~1.0FI   H:\PARTITION MAGIC V4.0 FINAL
d----   0   H:\portable   H:\portable
d----   0   H:\radio   H:\radio
dr-hs   0   H:\RECYCLER   H:\RECYCLER
d----   0   H:\REMOVE~1   H:\removeWGA ili genius
d----   0   H:\rku   H:\rku
--a--   704   H:\SAMPLE~1.LNK   H:\Sample Pictures.lnk
d----   0   H:\se   H:\se
--a--   1078   H:\sve.txt   H:\sve.txt
d----   0   H:\totalcmd   H:\totalcmd
d--hs   0   H:\vseqrntn.bin   H:\vseqrntn.bin
d----   0   H:\WIN~1.7AC   H:\Win. 7 Activator

----------------------------------------

ead74d0d-18ef-11e0-afe9-806e6f6e6963
Drive letter for GUID: D:
SectionStart = 9
SectionEnd = 10
----------------------------------------
Folder list for D:\autorun.inf:
----------------------------------------

--a--   -1   D:\aut[b][/b]orun.inf\lpt3.Drive_is_protected_against_flash_viruses_by_RegRun   D:\aut[b][/b]orun.inf\lpt3.Drive_is_protected_against_flash_viruses_by_RegRun

----------------------------------------



Dopuna: 12 Jan 2011 14:28
-------------------------------------------------------------


zdravo:
Izvini bio sam zauzet...i drugi Usb sam prosao
pozz
[Link mogu videti samo ulogovani korisnici]


USBNoRisk 2.7 (28 December 2010) by bobby

Started at 12.01.2011 14:21:22

Searching for connected USB Mass storage...
----------------------------------------
H: {9c13b122-18ab-11e0-ac02-00e0b100e317}
========================================

Searching for other storage...
----------------------------------------
C: {ead74d0c-18ef-11e0-afe9-806e6f6e6963}
D: {ead74d0d-18ef-11e0-afe9-806e6f6e6963}
E: {ead74d0e-18ef-11e0-afe9-806e6f6e6963}
========================================

Scanning removable storage...
----------------------------------------

Blocked file found: H:\autorun.inf.blocked
----------------------------------------
----------------------------------------
Could not open H:\autorun.inf.blocked to read the content
File lock detected:
USBNoRisk cannot find what locked the file
----------------------------------------

No autorun.inf files found on H:
Sanitized mountpoint for 9c13b122-18ab-11e0-ac02-00e0b100e317
No Desktop.ini files found on H:
No mimics found on drive H:
.lnk/.pif/.com/.scr files found on drive H:
----------------------------------------


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for ead74d0c-18ef-11e0-afe9-806e6f6e6963
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for ead74d0d-18ef-11e0-afe9-806e6f6e6963
No Desktop.ini files found on D:
----------------------------------------

No blocked files found on E:
No autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for ead74d0e-18ef-11e0-afe9-806e6f6e6963
No Desktop.ini files found on E:
----------------------------------------

========================================
Initial scan finished!
========================================

Processing script
----------------------------------------
9c13b122-18ab-11e0-ac02-00e0b100e317
Drive letter for GUID: H:
SectionStart = 4
SectionEnd = 8
----------------------------------------
Deleting blocked files:
----------------------------------------
Delete: H:\autorun.inf.blocked > Done!
----------------------------------------
Folder list for H:\:
----------------------------------------

d--h-   0   H:\IS   H:\IS
d--h-   0   H:\CG   H:\CG
d--h-   0   H:\DD   H:\DD
--a--   49256427   H:\AVIRAP~1.RAR   H:\Avira Premium Security Suite v9.0.0.356 [Corporate Key] !.rar
d----   0   H:\DRIVER   H:\DRIVER

----------------------------------------

ead74d0d-18ef-11e0-afe9-806e6f6e6963
Drive letter for GUID: D:
SectionStart = 9
SectionEnd = 10
----------------------------------------
Folder list for D:\autorun.inf:
----------------------------------------

--a--   -1   D:\aut[b][/b]orun.inf\lpt3.Drive_is_protected_against_flash_viruses_by_RegRun   D:\aut[b][/b]orun.inf\lpt3.Drive_is_protected_against_flash_viruses_by_RegRun

----------------------------------------

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Arrow Postupak ponovi za svaki uredjaj ponaosob


- Pokrenuti USBNoRisk i sačekati da izvrši inicijalno skeniranje.

- Po završetku inicijalnog skeniranja priključiti USB memorijski uređaj.

- Kliknuti na karticu Script;

U beli okvir prozora iskopirati sledeći tekst:

{a90b23fd-18f4-11e0-ac41-00e0b100e317}
folder_delete:%DRIVE%RECYCLER
folder_delete:%DRIVE%myfolder
folder_delete:%DRIVE%vseqrntn.bin

{ead74d0d-18ef-11e0-afe9-806e6f6e6963}
f_delete:%DRIVE%autorun.inf\lpt3.Drive_is_protected_against_flash_viruses_by_RegRun

{9c13b122-18ab-11e0-ac02-00e0b100e317}
folder_delete:%DRIVE%IS
folder_delete:%DRIVE%CG
folder_delete:%DRIVE%DD


- Izvršiti komandu klikom na taster Run Script;



Po izvršenju komande USBNoRisk će se automatski vratiti na karticu Monitor;

- Uraditi desni klik unutar belog okvira prozora i odabrati opciju Save Scrambled Log;

Otvoriće se prozor Notepad_a sa tekstom koji je potrebno iskopirati ovde u poruci.







goran9888 (AMF Tim)

Ko je trenutno na forumu
 

Ukupno su 1073 korisnika na forumu :: 120 registrovanih, 8 sakrivenih i 945 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 100ka, A.R.Chafee.Jr., acov34, Apok, aramis s, Aska, Asparagus, babaroga, Banovo Brdo, bestguarder, Bo96, Bokiboks, boromir, brufen, Chainsaw, Cian, Citalac, dejno, Dimitrije Paunovic, draganl, E_Kurir, Electron, famoso, FOX, GeoM, Georgius, GrobarPovratak, Hardenberg, havoc995, ikan, ILGromovnik, interesujeme, istina, ivica976, jodzula, Kajzer_Soze, Krusarac, kunktator, KUZMAR, kybonacci, laurusri, Lotus, Lucije Kvint, luja, M74AB3, Maki1981, Marko1238, Meklejn, Metanoja, mexo, mgolub, milanpb, milanpetkovicv, milenko crazy north, Millennium, Milometer, milos97, mishkooo, mist-mist, moldway, Mrav Obrad, nebkv, nemkea71, nenad81, nevjerna beba, NMNJ, nuke92, OtacMakarije, pein, pisac12, Plavi Jadran, Polemarchoi, Povratak1912, Prašinar, precan, Prečanin30, PrincipL, promajauglavi, qurtamurta, R_038, raptorsi, SamostalniReferent, Sančo, sasa87, savaskytec, silikon, Skakac7, Slingshot, Srbin do koske, starlights, Stoilkovic, Stoorb, strn, styg, t.mile, tanakadzo, Tas011, Timočka Divizija, Toper, Tribal, trutcina, TTN, Valter071, vathra, Velizar Laro, vensla, Vlad000, vlada035, Vlada78, vladas87, vladulns, voja64, vuksa72, Wrangler, zg, zokizemun, Zvrk, zziko, Žoržo, 79693