Poslao: 25 Dec 2008 23:30
|
offline
- rewritable
- Ugledni građanin
- Pridružio: 20 Mar 2009
- Poruke: 300
- Gde živiš: Republic Of Srpska Banjaluka
|
stvarno mi nije drago sto sam opet ovdje ali sta ces
davao sam svoj usb na koriscenje i naravno vracen mi je sa nekim djavolom
cim sam ga ustekao nod je pocrvenio ali bez mogucnosti brisanja
na sledeci sken nodom dao je opciju delete i navodno je obrisan
malver bajts je nasao neka cetiri trojan agenta u nekim recyclerima obrisao ih i na ponovni sken ih ne prijavljuje
ali usb se nastavio cudno ponasati
kad ga ustekam neda mi otvoriti na dupli klik vec na explore i ikonica nije kao hard disk vec folder(ikona od usb-a)
na format odreaguje pusti dupli klik i pojavi se ikona od diska ali cim ga ponovo prijavim ista stvar kaze K is not a valid win32 application
jos jednom izvinjenje zabog mog treceg dolaska u ambulantu
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:57, on 12/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ClocX\ClocX.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\PST\Desktop\New Folder\TR3.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{81D323A9-3773-4DF3-972D-1E5BD598DEAB}: NameServer = 62.68.96.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
--
End of file - 4858 bytes
tek cu se ujutro moci javiti!sljakam!pozdrav
Dopuna: 25 Dec 2008 23:30
ovo sam izbrisao
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
|
|
|
|
|
Poslao: 26 Dec 2008 17:16
|
offline
- rewritable
- Ugledni građanin
- Pridružio: 20 Mar 2009
- Poruke: 300
- Gde živiš: Republic Of Srpska Banjaluka
|
nisam mogao ranije sad sam ustao
evo ga
samo da ti napomenem bila mi je konekcija aktivna i digao se nod al je nestao i instalirao je recovery konzolu
ComboFix 08-12-25.04 - PST 2008-12-26 17:03:18.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1535.1051 [GMT 1:00]
Running from: c:\documents and settings\PST\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\dumphive.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2008-11-26 to 2008-12-26 )))))))))))))))))))))))))))))))
.
2008-12-25 22:21 . 2008-12-25 22:21 5,777,139 --a------ C:\goca trzan - kad ponos ubije ljubav iz nehata.mp3
2008-12-15 22:12 . 2008-12-15 22:12 512,096 --a------ c:\windows\system32\drivers\amon.sys
2008-12-15 22:12 . 2008-12-15 22:12 299,392 --a------ c:\windows\system32\imon.dll
2008-12-15 22:12 . 2008-12-15 22:12 15,424 --a------ c:\windows\system32\drivers\nod32drv.sys
2008-12-15 22:11 . 2008-12-25 22:22 <DIR> d-------- c:\program files\ESET
2008-12-15 22:02 . 2008-12-15 22:03 <DIR> d-------- c:\windows\system32\updfiles
2008-12-15 22:01 . 2008-12-15 22:01 87 --a------ c:\windows\system32\EpfwUser.dat
2008-12-15 20:13 . 2008-12-15 20:13 <DIR> d-------- c:\program files\Common Files\eSellerate
2008-12-15 20:13 . 2008-12-15 20:13 360,580 --a------ c:\windows\eSellerateEngine.dll
2008-12-15 20:13 . 2008-12-15 20:17 135 --ah----- c:\documents and settings\PST\Application Data\lakerda1967.sys
2008-12-04 06:14 . 2008-12-04 06:14 2,432 --a------ c:\documents and settings\cc_20081204_0614.reg
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-26 15:56 --------- d-----w c:\documents and settings\PST\Application Data\uTorrent
2008-12-21 21:34 25,992 ----a-w c:\windows\system32\pgdfgsvc.exe
2008-12-20 18:50 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-20 18:50 --------- d-----w c:\program files\SpywareBlaster
2008-12-20 18:48 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-12 18:08 --------- d-----w c:\documents and settings\PST\Application Data\Skype
2008-12-12 16:35 --------- d-----w c:\documents and settings\PST\Application Data\skypePM
2008-12-06 17:06 12,524 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-12-04 05:12 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-03 18:52 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-03 18:52 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-12-01 16:47 --------- d-----w c:\program files\Opera
2008-11-30 11:55 --------- d-----w c:\documents and settings\All Users\Application Data\nView_Profiles
2008-11-09 13:29 --------- d-----w c:\program files\Corel
2008-11-09 13:28 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-09 13:27 --------- d-----w c:\documents and settings\PST\Application Data\Corel
2008-11-09 13:06 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-09 13:06 --------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2008-11-08 13:06 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-08 00:55 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-07 20:19 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-11-07 20:19 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-11-02 03:04 --------- d-----w c:\program files\Common Files\Adobe
2008-10-28 17:19 --------- d-----w c:\documents and settings\All Users\Application Data\NVIDIA
2008-10-27 17:34 --------- d-----w c:\documents and settings\PST\Application Data\Steinberg
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2005-01-26 270336]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-12-15 950664]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 c:\windows\system32\nvmctray.dll]
c:\documents and settings\PST\Start Menu\Programs\Startup\
Cyber-shot Viewer Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-01-17 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.DVSD"= pdvcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Native Instruments\\Traktor DJ Studio 2\\TraktorDJStudio2.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\PST\\Desktop\\Skype.exe"=
R0 viasraid;viasraid;c:\windows\system32\DRIVERS\viasraid.sys [2005-05-31 77056]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-12-15 15424]
R2 Asapi;Asapi;c:\windows\system32\drivers\Asapi.sys [2005-06-01 8768]
R2 MarxDev1;MarxDev1;c:\windows\system32\drivers\MarxDev1.sys [2005-06-01 8864]
R2 MarxDev2;MarxDev2;c:\windows\system32\drivers\MarxDev2.sys [2005-06-01 8864]
R2 MarxDev3;MarxDev3;c:\windows\system32\drivers\MarxDev3.sys [2005-06-01 8864]
S2 Tdlpt;Tdlpt;\??\c:\windows\system32\drivers\Tdlpt.sys [2005-06-01 8012]
S3 usb2vcom;USB Data Cable;c:\windows\system32\DRIVERS\usb2vcom.sys [2006-05-16 29152]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
TCP: {81D323A9-3773-4DF3-972D-1E5BD598DEAB} = 62.68.96.2
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-26 17:04:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(688-)
c:\windows\system32\imon.dll
.
Completion time: 2008-12-26 17:05:32
ComboFix-quarantined-files.txt 2008-12-26 16:05:13
Pre-Run: 8,090,284,032 bytes free
Post-Run: 8,077,885,440 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
128
Dopuna: 26 Dec 2008 17:16
i nisam disejblovao nod u toku skeniranja
i nisu mi bili ukljuceni ext hard disk i usb drajv
|
|
|
|
Poslao: 26 Dec 2008 22:35
|
offline
- dr_Bora
- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
|
Skini sledeci program - http://amf.mycity.rs/personal/bobby/USB_blocker/usb_blocker.exe
- startuj ga i odaberi opciju Auto block
- ubaci USB stick u komp i sacekaj koji sekund (recimo 5-10 sekundi)
- program je sada uradio analizu sticka (vidi se u donjem delu programa, u logu)
- gore levo klikni duplo na slovo koje oznacava particiju, tj. tvoj USB stick
- dole kraj sata ce se pojaviti poruka da smes da izvadis USB stick iz kompa
- ne gasi program, vec ubaci sledeci USB stick i za njega isto sacekaj par sekundi, i tako redom za sve stickove, MP3 plejere, mobilni
- zapamti kojim redom su ubacivani stickovi
Kada sve to zavrsis, log u donjem delu programa ce sadrzati sve podatke koji su meni potrebni da bih video koji stick je zarazen.
Klikni desnim dugmetom misa na log/izvestaj i odaberi Save log.
Automatski ce se otvoriti Notepad i u njemu izvestaj.
Iskopiraj mi taj izvestaj ovde na forum.
|
|
|
|
Poslao: 26 Dec 2008 23:07
|
offline
- rewritable
- Ugledni građanin
- Pridružio: 20 Mar 2009
- Poruke: 300
- Gde živiš: Republic Of Srpska Banjaluka
|
evo ga druze kad sam ubo telefon nod je pocrvenio
i prikazao da ima nesto na telefonu ali ne i na kartici
evo log
USB_blocker by bobby
Started at 12/26/2008 10:53:31 PM
Scanning for connected USB Mass storage...
========================================
========================================
Scanning for other storage...
========================================
C: 554182df-d20c-11d9-b070-806d6172696f
E: 554182e0-d20c-11d9-b070-806d6172696f
F: 554182e1-d20c-11d9-b070-806d6172696f
H: 5858e082-fe43-11d5-8517-00112fb41aa6
I: 5858e083-fe43-11d5-8517-00112fb41aa6
========================================
Scanning fixed storage for autorun.inf files...
========================================
========================================
New device connected at 12/26/2008 10:53:56 PM
Scanning for connected USB Mass storage...
========================================
K: 3e79412a-a51e-11dd-8514-00112fb41aa6
========================================
Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 3e79412a-a51e-11dd-8514-00112fb41aa6
========================================
New device connected at 12/26/2008 10:56:18 PM
Scanning for connected USB Mass storage...
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6
========================================
Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
autorun.inf found on J:
File J:\autorun.inf renamed successfully
Sanitizing Shell Menu...
No key for GUID: 612cc46f-d30c-11dd-8552-00112fb41aa6
========================================
New device connected at 12/26/2008 10:56:22 PM
Scanning for connected USB Mass storage...
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6
K: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================
Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 612cc46f-d30c-11dd-8552-00112fb41aa6
No key for GUID: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================
K: 612cc470-d30c-11dd-8552-00112fb41aa6
New device connected at 12/26/2008 10:56:32 PM
Scanning for connected USB Mass storage...
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6
K: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================
Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 612cc46f-d30c-11dd-8552-00112fb41aa6
No key for GUID: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================
K: 612cc470-d30c-11dd-8552-00112fb41aa6
New device connected at 12/26/2008 10:56:37 PM
Scanning for connected USB Mass storage...
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6
K: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================
Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 612cc46f-d30c-11dd-8552-00112fb41aa6
No key for GUID: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6
New device connected at 12/26/2008 10:56:43 PM
Scanning for connected USB Mass storage...
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6
K: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================
Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 612cc46f-d30c-11dd-8552-00112fb41aa6
No key for GUID: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6
New device connected at 12/26/2008 10:58:16 PM
Scanning for connected USB Mass storage...
========================================
J: 9478dbf4-b5bf-11dd-852f-00112fb41aa6
========================================
Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 9478dbf4-b5bf-11dd-852f-00112fb41aa6
========================================
|
|
|
|
Poslao: 26 Dec 2008 23:25
|
offline
- dr_Bora
- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
|
Na uređaju koji si priključio drugi po redu se nalazi file autorun.inf.blocked - otvori ga u Notepad-u i iskopiraj ovde njegov sadržaj.
|
|
|
|
Poslao: 26 Dec 2008 23:50
|
offline
- rewritable
- Ugledni građanin
- Pridružio: 20 Mar 2009
- Poruke: 300
- Gde živiš: Republic Of Srpska Banjaluka
|
eb ga na poslu sam do sest ujutro
jeste drugi je uredjaj po redu bio telefon ali nije mi jasno kako cu naci na telefonu fajl
nista probacu ujutro
pozdrav
|
|
|
|
Poslao: 26 Dec 2008 23:53
|
offline
- dr_Bora
- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
|
Čim spojiš telefon, on će biti prikazan kao neki drive u My Computer.
Čim ga otvoriš (dvoklikom na ikonicu), taj file odmah treba da bude vidljiv.
|
|
|
|
Poslao: 27 Dec 2008 07:36
|
offline
- rewritable
- Ugledni građanin
- Pridružio: 20 Mar 2009
- Poruke: 300
- Gde živiš: Republic Of Srpska Banjaluka
|
i jos sam da dodam telefon sam redovno ukopcavao i prebacivao fajlove ali nikad nista nije pokazalo da je zarazen majku mu poljubim
Dopuna: 27 Dec 2008 6:54
uh znao sam ja da ovo nece biti lako
e ovako
kad sam upalio komp sa sistemom se upalio i externi hd
prvo sam probao naci na telefonu fajl autorun.inf kao sto si rekao ali usb blocker mi prijavljuje na local disc L (a to je ext hd) istoimeni fajl koji si ti spominjao
a na telefonu (skenirao sam ga nodom) prijavljuje fajl
Adober.exe - Win32/RJump.A worm
kaze da se fajl ne moze obrisati ali ga obrise i na ponovnom skernu ga ne prijavljuje a evo ti log od usb blockera jos jednom
USB_blocker by bobby
Started at 12/27/2008 6:42:02 AM
Scanning for connected USB Mass storage...
========================================
========================================
Scanning for other storage...
========================================
C: 554182df-d20c-11d9-b070-806d6172696f
E: 554182e0-d20c-11d9-b070-806d6172696f
F: 554182e1-d20c-11d9-b070-806d6172696f
H: 5858e082-fe43-11d5-8517-00112fb41aa6
I: 5858e083-fe43-11d5-8517-00112fb41aa6
========================================
Scanning fixed storage for autorun.inf files...
========================================
========================================
New device connected at 12/27/2008 6:42:36 AM
Scanning for connected USB Mass storage...
========================================
========================================
Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
========================================
New device connected at 12/27/2008 6:42:37 AM
Scanning for connected USB Mass storage...
========================================
========================================
Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
========================================
K: 612cc470-d30c-11dd-8552-00112fb41aa6
New device connected at 12/27/2008 6:44:41 AM
Scanning for connected USB Mass storage...
========================================
J: 3e79412a-a51e-11dd-8514-00112fb41aa6
========================================
Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 3e79412a-a51e-11dd-8514-00112fb41aa6
========================================
New device connected at 12/27/2008 6:45:42 AM
Scanning for connected USB Mass storage...
========================================
J: 9478dbf4-b5bf-11dd-852f-00112fb41aa6
========================================
Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 9478dbf4-b5bf-11dd-852f-00112fb41aa6
========================================
New device connected at 12/27/2008 6:46:35 AM
Scanning for connected USB Mass storage...
========================================
========================================
Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
========================================
s tim da mi nije prikazao u lijevom prozoru samo od telefona ikone i nisam ih mogao iskljuciti na dupli klik vec standardnom procedurom
dr boro sta se ovo desava
Dopuna: 27 Dec 2008 7:06
ovo je autorun sa diska i cini mi se da je njegov fabricki fajl al evo ovako izgleda u notepadu (samo sam ga prevukao u note pad)
jel tako trebalo
[autorun]
ICON=AUTORUN\WDLOGO.ICO
Dopuna: 27 Dec 2008 7:36
i da nisam uspio naci na telefonu taj fajl
prikaze samo foldere s tim da je jedan imenom system osjencen vjerovatno hidiran
nadam se da te necu smoriti
|
|
|
|
Poslao: 27 Dec 2008 10:29
|
offline
- dr_Bora
- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
|
Citat:ovo je autorun sa diska i cini mi se da je njegov fabricki fajl al evo ovako izgleda u notepadu (samo sam ga prevukao u note pad)
jel tako trebalo
[autorun]
ICON=AUTORUN\WDLOGO.ICO
Ovaj možeš da preimenuješ nazad u autorun.inf (to jeste fabrički file).
Što se tiče telefona: priključi ga a zatim idi na Start > Run i ukucaj:
notepad X:\autorun.inf.blocked
Slovo X zameni onim slovom koje bude dodeljeno telefonu.
Javi da li je ovo gore uspelo i da li ti sada AV nešto detektuje.
|
|
|
|