Poslao: 13 Mar 2009 15:57
|
offline
- zarko123
- Ugledni građanin
- Pridružio: 02 Sep 2007
- Poruke: 390
- Gde živiš: Pljevlja
|
USBNoRisk 1.5 by bobby
Started at 3/11/2009 4:24:03 PM
Scanning for connected USB Mass storage...
----------------------------------------
========================================
Scanning for other storage...
----------------------------------------
C: {0c9af17c-9298-11dc-a2a3-806d6172696f}
========================================
Scanning fixed storage for autorun.inf files...
----------------------------------------
Autorun.inf on C: - None
----------------------------------------
Sanitizing Shell Menu...
----------------------------------------
No key found for C:
No key found for 0c9af17c-9298-11dc-a2a3-806d6172696f
========================================
autorun.inf found in Qoobox
----------------------------------------
Content of C:\QooBox\Quarantine\C\autorun.inf.vir
----------------------------------------
[AutoRun]
;
open=3ds.cmd
;K2Kwk0djwAk24ZsL
shell\open\Command=3ds.cmd
----------------------------------------
New device connected at 3/11/2009 4:24:22 PM
Scanning for connected USB mass storage...
----------------------------------------
J: {8a396e1e-a3d3-11dc-a2a8-0019db587c1f}
Added J:
========================================
Scanning USB mass storage for files...
----------------------------------------
----------------------------------------
Autorun.inf on J: - None
----------------------------------------
Sanitizing Shell Menu...
----------------------------------------
No key found for 8a396e1e-a3d3-11dc-a2a8-0019db587c1f
========================================
----------------------------------------
Desktop.ini on J: - None
----------------------------------------
========================================
Processing script
----------------------------------------
Drive letter for GUID: J:\
8a396e1e-a3d3-11dc-a2a8-0019db587c1f
SectionStart = 1
SectionEnd = 4
----------------------------------------
========================================
Processing script
----------------------------------------
Drive letter for GUID: J:\
8a396e1e-a3d3-11dc-a2a8-0019db587c1f
SectionStart = 1
SectionEnd = 4
----------------------------------------
Drive letter for GUID: C:\
No script to process for C:\
----------------------------------------
Scan started at 3/11/2009 4:27:54 PM
Drives:
C:\
D:\
E:\
F:\
G:\
H:\
J:\
====================
Scanning C:\
====================
Folder mimic list
--------------------
C:\WINDOWS\system32\MsDtc d----
C:\WINDOWS\system32\MsDtc.exe --a-- 6144 bytes
-
C:\WINDOWS\system32\Setup d----
C:\WINDOWS\system32\Setup.exe --a-- 23040 bytes
-
====================
CLSID >> C:\WINDOWS\Offline Web Pages\desktop.ini
--------------------
[.ShellClassInfo]
CLSID={F5175861-2688-11d0-9C5E-00AA00A45957}
--------------------
HKCR\CLSID\{F5175861-2688-11d0-9C5E-00AA00A45957}\DefaultIcon,@ = %SystemRoot%\system32\webcheck.dll
HKCR\CLSID\{F5175861-2688-11d0-9C5E-00AA00A45957}\InProcServer32,@ = %SystemRoot%\system32\webcheck.dll
HKLM\Software\Classes\CLSID\{F5175861-2688-11d0-9C5E-00AA00A45957}\DefaultIcon,@ = %SystemRoot%\system32\webcheck.dll
HKLM\Software\Classes\CLSID\{F5175861-2688-11d0-9C5E-00AA00A45957}\InProcServer32,@ = %SystemRoot%\system32\webcheck.dll
====================
Scanning J:\
====================
Scan finished at 3/11/2009 4:27:59 PM
Dopuna: 13 Mar 2009 15:57
Nadam se da nije problem sto sam temu ozivio 1 sat ranije nego sto je odredjeno (48 sati), razlog je sto upravo zavrsavam sa poslom pa kasnije ne mogu napisati poruku (zbog interneta)
Boby sta da radim dalje?
|
|
|
|
Poslao: 13 Mar 2009 17:22
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Izvinjavam se puno sto sam zaboravio da odgovorim...
Sada sam usao u stan. Sve mi je poslo naopako ovih dana.
Da te ne opterecujem detaljima...
Ne vidim iz loga. Moraces mi reci da li jos uvek ima onih fajlova na disku koji imitiraju foldere?
|
|
|
|
Poslao: 16 Mar 2009 09:17
|
offline
- zarko123
- Ugledni građanin
- Pridružio: 02 Sep 2007
- Poruke: 390
- Gde živiš: Pljevlja
|
Jedini problem koji sada primjecujem je taj da kada hocu da kreiram novi folder na racunaru on mu odmah nakon davanja imena sa moje strane dodjeljuje ispod "File Folder" , tako da je to vjerovatno to imitiranje koje pominjes. Kada isto odradim na flesu sve je normalno znači ne dodjeljuje mu File Folder.
Taj folder koji kreiram i kom mi ispod doda File Folder mogu da brisem, dok ranije to nisam mogao prije tvoje pomoci.
|
|
|
|
|
Poslao: 17 Mar 2009 11:30
|
offline
- zarko123
- Ugledni građanin
- Pridružio: 02 Sep 2007
- Poruke: 390
- Gde živiš: Pljevlja
|
Scan started at 3/17/2009 11:21:01 AM
Drives:
C:\
D:\
E:\
F:\
G:\
H:\
J:\
====================
Scanning C:\
====================
Folder mimic list
--------------------
C:\WINDOWS\system32\MsDtc d----
C:\WINDOWS\system32\MsDtc.exe --a-- 6144 bytes
-
C:\WINDOWS\system32\Setup d----
C:\WINDOWS\system32\Setup.exe --a-- 23040 bytes
-
====================
CLSID >> C:\WINDOWS\Offline Web Pages\desktop.ini
--------------------
[.ShellClassInfo]
CLSID={F5175861-2688-11d0-9C5E-00AA00A45957}
--------------------
HKCR\CLSID\{F5175861-2688-11d0-9C5E-00AA00A45957}\DefaultIcon,@ = %SystemRoot%\system32\webcheck.dll
HKCR\CLSID\{F5175861-2688-11d0-9C5E-00AA00A45957}\InProcServer32,@ = %SystemRoot%\system32\webcheck.dll
HKLM\Software\Classes\CLSID\{F5175861-2688-11d0-9C5E-00AA00A45957}\DefaultIcon,@ = %SystemRoot%\system32\webcheck.dll
HKLM\Software\Classes\CLSID\{F5175861-2688-11d0-9C5E-00AA00A45957}\InProcServer32,@ = %SystemRoot%\system32\webcheck.dll
====================
Scanning J:\
====================
Scan finished at 3/17/2009 11:21:10 AM
|
|
|
|
Poslao: 17 Mar 2009 19:21
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Ovo je sve OK sada.
Pretpostavljam da se jos secas kako se deinstalira ComboFix.
Ostale programe koje smo upotrebljavali je dovoljno obrisati, nema posebnih metoda deinstalacije.
|
|
|
|
Poslao: 18 Mar 2009 10:56
|
offline
- zarko123
- Ugledni građanin
- Pridružio: 02 Sep 2007
- Poruke: 390
- Gde živiš: Pljevlja
|
OK. deinstaliracu Combo a ostale cu pobrisati. I iskreno se nadam da se necu uskoro javljati u Ambulanti.
A ako me dugo ne bude na forumu uopste, znajte da su me ova gamad opet napala i da sam pod noge skrcao i komp. i sve sto ga prati.
Hvala.
|
|
|
|