Problem sa USB diskovima

2

Problem sa USB diskovima

offline
  • Pridružio: 14 Nov 2003
  • Poruke: 324

Ma sranje se dogodilo kada sam postavio prvi log.
Znači, postavio sam prvi log i kada sam krenuo da vidim šta se radi po kompu, čekalo me ono što sam već opisao.

Komp mi treba, pa sam zbog toga ghost-irao sistem i ne ubacujem USB dok ne nađem neko trajnije rešenje.

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Napisano: 09 Jun 2009 22:13

- Preuzmi USBNoRisk na Desktop i pokreni ga duplim klikom na ikonicu programa.
- Sacekaj koji sekund dok program izvrsi inicijalno skeniranje.
- Ubacuj sve USB memorijske uredjaje redom u USB slot i svaki zadrzi u slotu po 10 sekundi.
- Ukoliko imas vise uredjaja za proveru, onda na parcetu papira zapisi kojim redom su ubacivani jer ce nam kasnije trebati taj podatak
- Kada zavrsis sa svim uredjajima, klikni desno dugme misa na sred prozora programa i odaberi opciju Save log. To ce automatski otvoriti log u Notepadu. Iskopiraj nam taj log iz Notepada na forum.

Objasnjenje: U USB memorijske uredjaje spadaju svi oni uredjaji koji po prikljucivanju na kompjuter dobijaju svoju oznaku particije. Tu spadaju USB flash drajvovi, eksterni hard-diskovi, memorijske kartice, MP3 i MP4 plejeri, neki mobilni telefoni, neki GPS (navigacioni) uredjaji itd.

Dopuna: 09 Jun 2009 22:14

USBNoRisk nece dozvoliti da se virus automatski pokrene kada ubacis USB HD, tako da ga mozes i kasnije koristiti za tako nesto.

offline
  • Pridružio: 14 Nov 2003
  • Poruke: 324

Ima li neko neki predlog za dobar program tipa antimalware-spyware da se trajno zaštitim od čudesa koja kruže po USB diskovima.
Imam još dva eksterna hard diska sa podacima, a kačim ih preko USB adaptera a trebaju mi kao hleb a ne smem sada da ih nakačim.

Hvala unapred

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Gore sam napisao - USBNoRisk.

offline
  • Pridružio: 14 Nov 2003
  • Poruke: 324

USBNoRisk 2.4 (1 June 2009) by bobby

Started at 6/9/2009 10:15:36 PM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
C: {04025096-a1c9-11dc-93f9-806d6172696f}
D: {04025097-a1c9-11dc-93f9-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 04025096-a1c9-11dc-93f9-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for 04025097-a1c9-11dc-93f9-806d6172696f
No Desktop.ini files found on D:
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 6/9/2009 10:15:50 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {010d4142-0b3d-11de-9ea5-5050506f4531}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
autorun.inf found on H:
----------------------------------------
File H:\autorun.inf renamed successfully

----------------------------------------
Could not open H:\autorun.inf.blocked to read the content
File lock detected:
USBNoRisk cannot find what locked the file
----------------------------------------

No mountpoint found for 010d4142-0b3d-11de-9ea5-5050506f4531
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

Mimics found on drive H:
========================================

========================================
Removed H:
========================================


New device connected at 6/9/2009 10:16:47 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {08813fee-5526-11de-9eb0-5050506f4531}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for 08813fee-5526-11de-9eb0-5050506f4531
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
========================================

========================================
Removed H:
========================================


New device connected at 6/9/2009 10:16:57 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {08813fee-5526-11de-9eb0-5050506f4531}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for 08813fee-5526-11de-9eb0-5050506f4531
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
========================================

========================================
Removed H:
========================================


New device connected at 6/9/2009 10:17:06 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {08813fee-5526-11de-9eb0-5050506f4531}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for 08813fee-5526-11de-9eb0-5050506f4531
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
========================================

========================================
Removed H:
========================================


New device connected at 6/9/2009 10:17:24 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {010d413c-0b3d-11de-9ea5-5050506f4531}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for 010d413c-0b3d-11de-9ea5-5050506f4531
----------------------------------------

----------------------------------------
Desktop.ini found at H:\Recycled\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------

Mimics found on drive H:
========================================

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Prvi i zadnji uredjaj su zarazeni, a onaj koji si ukljucivao tri puta izmedju toga - on je cist.

Predji na karticu Script u USBNoRisku i tamo iskopiraj sledeci skript:
{010d4142-0b3d-11de-9ea5-5050506f4531}
delete_mimics:
folder_list: %DRIVE%

{010d413c-0b3d-11de-9ea5-5050506f4531}
delete_mimics:
folder_list: %DRIVE%


Vrati se na karticu Monitor.
Nakon toga prikljuci ponovo ona dva problematicna HD-a na komp, jedan po jedan. Kada prikljucis prvi, daj USBNoRisku dovoljno vremena da ocisti HD, pa ga tek onda istekaj i ustekaj sledeci HD.

Kada to odradis, snimi ponovo log i iskopiraj mi ga ovde.

offline
  • Pridružio: 14 Nov 2003
  • Poruke: 324

Sve odradio kako si rekao i evo log-a.

Uzgred, da li je ovo dobra zaštita od ovih USB napasti?



USBNoRisk 2.4 (1 June 2009) by bobby

Started at 6/9/2009 10:30:10 PM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
C: {04025096-a1c9-11dc-93f9-806d6172696f}
D: {04025097-a1c9-11dc-93f9-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 04025096-a1c9-11dc-93f9-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for 04025097-a1c9-11dc-93f9-806d6172696f
No Desktop.ini files found on D:
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 6/9/2009 10:30:31 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {010d4142-0b3d-11de-9ea5-5050506f4531}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for 010d4142-0b3d-11de-9ea5-5050506f4531
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

Mimics found on drive H:
========================================

Processing script
----------------------------------------
010d4142-0b3d-11de-9ea5-5050506f4531
Drive letter for GUID: H:
SectionStart = 0
SectionEnd = 3
----------------------------------------
Deleting mimics:
----------------------------------------
f_delete: C:\Win\lsass.exe > File does not exist!
Mimics found: H:\Cover CDR format.exe
f_delete:
file "H:\Cover CDR format.exe" deleted successfully
----------------------------------------
Folder list for H:\:
----------------------------------------

--a--   81006   H:\INFORM~1.CDR   H:\Informatika.cdr
--a--   76730   H:\INFORM~2.CDR   H:\Informatika 2.cdr
--a--   479476   H:\WINXPS~1.CDR   H:\winxp sp2.cdr
dr-hs   0   H:\COVERC~1   H:\Cover CDR format

----------------------------------------

========================================
Scan finished!
========================================

========================================
Removed H:
========================================


New device connected at 6/9/2009 10:31:05 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {010d413c-0b3d-11de-9ea5-5050506f4531}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for 010d413c-0b3d-11de-9ea5-5050506f4531
----------------------------------------

----------------------------------------
Desktop.ini found at H:\Recycled\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------

Mimics found on drive H:
========================================

Processing script
----------------------------------------
010d413c-0b3d-11de-9ea5-5050506f4531
Drive letter for GUID: H:
SectionStart = 4
SectionEnd = 6
----------------------------------------
Deleting mimics:
----------------------------------------
f_delete: C:\Win\lsass.exe > File does not exist!
Mimics found: H:\Murder at 1600 (1997).exe
f_delete:
file "H:\Murder at 1600 (1997).exe" deleted successfully
Mimics found: H:\Eldar.exe
f_delete:
file "H:\Eldar.exe" deleted successfully
Mimics found: H:\Foto te Kroit te Vitakut.exe
f_delete:
file "H:\Foto te Kroit te Vitakut.exe" deleted successfully
Mimics found: H:\New Folder.exe
f_delete:
file "H:\New Folder.exe" deleted successfully
Mimics found: H:\Mirrors (2008-).exe
f_delete:
file "H:\Mirrors (2008-).exe" deleted successfully
Mimics found: H:\The Devils Tomb (2009).exe
f_delete:
file "H:\The Devils Tomb (2009).exe" deleted successfully
Mimics found: H:\The Broken.exe
f_delete:
file "H:\The Broken.exe" deleted successfully
Mimics found: H:\Prison Break 4.exe
f_delete:
file "H:\Prison Break 4.exe" deleted successfully
Mimics found: H:\Pranimi teknik.exe
f_delete:
file "H:\Pranimi teknik.exe" deleted successfully
Mimics found: H:\The Day The Earth Stood Still.exe
f_delete:
file "H:\The Day The Earth Stood Still.exe" deleted successfully
Mimics found: H:\Recycled.exe
f_delete:
file "H:\Recycled.exe" deleted successfully
Mimics found: H:\Privat.exe
f_delete:
file "H:\Privat.exe" deleted successfully
----------------------------------------
Folder list for H:\:
----------------------------------------

dr-hs   0   H:\MURDER~1   H:\Murder at 1600 (1997)
dr-hs   0   H:\Eldar   H:\Eldar
dr-hs   0   H:\FOTOTE~1   H:\Foto te Kroit te Vitakut
dr-hs   0   H:\NEWFOL~1   H:\New Folder
dr-hs   0   H:\MIRROR~1   H:\Mirrors (2008)
dr-hs   0   H:\THEDEV~1   H:\The Devils Tomb (2009)
--a--   735408128   H:\BEOGRA~1.AVI   H:\Beogradski Fantom.avi
dr-hs   0   H:\THEBRO~1   H:\The Broken
--a--   378631   H:\OKRUGL~1.SKP   H:\Okrugla masina zajedno.skp
--a--   113   H:\NEWTEX~1.TXT   H:\New Text Document.txt
dr-hs   0   H:\PRISON~1   H:\Prison Break 4
dr-hs   0   H:\PRANIM~1   H:\Pranimi teknik
dr-hs   0   H:\THEDAY~1   H:\The Day The Earth Stood Still
dr-hs   0   H:\Recycled   H:\Recycled
dr-hs   0   H:\Privat   H:\Privat

----------------------------------------

========================================
Scan finished!
========================================

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Sada ces morati da restartujes racunar, pa posle restarta da odradis i sledeci skript u USBNoRisku (ovo ce ti povratiti tvoje fajlove koje je virus sakrio):
{010d4142-0b3d-11de-9ea5-5050506f4531}
no_sh:
folder_delete: C:\Win\
folder_list: %DRIVE%
delete_blocked:

{010d413c-0b3d-11de-9ea5-5050506f4531}
no_sh:
folder_list: %DRIVE%
delete_blocked:


Znaci, procedura ista kao gore - uneses skript, pa onda prikljucis uredjaje redom, pa na kraju snimis log i iskopiras ga ovde.

Inace, USBNoRisk moze da ti posluzi za vecinu, ako ne i za sve USB infekcije, ali treba znati sa njim raditi. Nije napravljen da automatski brise osim sto ce da blokira automatsko pokretanje nekih verzija malwarea.
Mozda uradim i takvu verziju kada se budem uverio da ova verzija radi svoj posao onako kako treba, tj. da ne prijavljuje i legitimne fajlove.

offline
  • Pridružio: 14 Nov 2003
  • Poruke: 324

O bogami bobby, teško da odradimo ovo....
Naime, posle unosa one prve skripte koju si dao, ja sam ovde postavio log.
Posle toga sam ubacio USB diskiće u kom i bila su samo po tri fajla, foldera nije bilo. Okreni-obrni, folderi su nestali. Proveravao sam, ali samo su bila po tri fajla. Fajlovi su moji, nisu bili u folderima.
Onda sam odradio format USB diskića. Zbog toga ovo ne mogu uraditi, jer mi se čini da neće imati efekta.
Kao što sam rekao, imam dva eksterna hard diska koje ni za živu glavu ne smem da prikačim dok ne nađem neko zaista trajno rešenje.

Kao što sam rekao u postevima iznad, treba mi neki program tipa antimalware-antispyware, plašim se da mi ovaj tvoj USBNoRisk ne pobriše nešto sa hardova.

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Corleone ::O bogami bobby, teško da odradimo ovo....
Naime, posle unosa one prve skripte koju si dao, ja sam ovde postavio log.
Posle toga sam ubacio USB diskiće u kom i bila su samo po tri fajla, foldera nije bilo. Okreni-obrni, folderi su nestali. Proveravao sam, ali samo su bila po tri fajla. Fajlovi su moji, nisu bili u folderima.
Onda sam odradio format USB diskića. Zbog toga ovo ne mogu uraditi, jer mi se čini da neće imati efekta.
Kao što sam rekao, imam dva eksterna hard diska koje ni za živu glavu ne smem da prikačim dok ne nađem neko zaista trajno rešenje.

Kao što sam rekao u postevima iznad, treba mi neki program tipa antimalware-antispyware, plašim se da mi ovaj tvoj USBNoRisk ne pobriše nešto sa hardova.

Jao bre...
Sto nisi odradio do kraja ono sto sam ti rekao, i sve bi bilo dobro.
Folderi su samo bili sakriveni (ne moze se videti ni ako ukljucis ono da se mogu videti hidden files).
Trebao si samo pustiti ovaj zadnji skript, i folderi bi opet bili vidljivi.

Ovaj malware funkcionise tako sto sakrije foldere i ubaci sebe umesto tih foldera. Od kada su ti diskovi bili zarazeni, ti vise foldere nisi mogao da vidis, vec si non-stop kliktao na malware i pokretao ga, pa ti je tek on prikazivao sadrzaj foldera.
Kada smo otklonili malware, trebalo je jos samo da pustis i drugu skriptu koja bi ti ponovo prikazala foldere.

Sta sada da ti radim i kako da ti pomognem kada si na svoju ruku uradio to sto si uradio?

Ko je trenutno na forumu
 

Ukupno su 1089 korisnika na forumu :: 30 registrovanih, 8 sakrivenih i 1051 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Aleksandar Tomić, Andrija357, bojankrstc, brundo65, cikadeda, Džordžino, janbo, Još malo pa deda, Kriglord, krkalon, mercedesamg, Milometer, Milos ZA, milutin134, mkukoleca, Parker, pein, Pele23, repac, ruso, Stoilkovic, suton, theNedjeljko, Trpe Grozni, vathra, Vlada1389, wizzardone, YugoSlav, 223223