Poslao: 25 Jul 2009 12:18
- Srki94

- Mod u pemziji
- Pridružio: 14 Feb 2008
- Poruke: 12405
Napisano: 25 Jul 2009 12:17
USBNoRisk 2.4 (1 June 2009) by bobby
Started at 7/25/2009 12:13:54 PM
Searching for connected USB Mass storage...
Searching for other storage...
C: {cfc123b3-757f-11de-a7fe-806d6172696f}
D: {cfc123b8-757f-11de-a7fe-806d6172696f}
Scanning fixed storage...
No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for cfc123b3-757f-11de-a7fe-806d6172696f
No Desktop.ini files found on C:
No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for cfc123b8-757f-11de-a7fe-806d6172696f
No Desktop.ini files found on D:
Initial scan finished!
New device connected at 7/25/2009 12:14:15 PM
Scanning for connected USB mass storage...
G: {ba729f55-7601-11de-885a-001d72c737e6}
Added G:
Scanning USB mass storage for files...
No blocked files found on G:
autorun.inf found on G:
File G:\autorun.inf renamed successfully
Content of G:\autorun.inf.blocked
action=Open folder to view files using Windows Explorer
Files referenced from G:\autorun.inf.blocked
Sanitized mountpoint for ba729f55-7601-11de-885a-001d72c737e6
Desktop.ini found at G:\info\ contains interesting CLSID string
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
No mimics found on drive G:
Removed G:
New device connected at 7/25/2009 12:15:15 PM
Scanning for connected USB mass storage...
G: {62219c0e-758a-11de-8858-001d72c737e6}
Added G:
Scanning USB mass storage for files...
No blocked files found on G:
No Autorun.inf files found on G:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
No Desktop.ini files found on G:
No mimics found on drive G:
Removed G:
New device connected at 7/25/2009 12:16:22 PM
Scanning for connected USB mass storage...
G: {62219c0e-758a-11de-8858-001d72c737e6}
Added G:
Scanning USB mass storage for files...
No blocked files found on G:
No Autorun.inf files found on G:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
No Desktop.ini files found on G:
No mimics found on drive G:
Removed G:
New device connected at 7/25/2009 12:16:40 PM
Scanning for connected USB mass storage...
G: {62219c0e-758a-11de-8858-001d72c737e6}
Added G:
Scanning USB mass storage for files...
No blocked files found on G:
No Autorun.inf files found on G:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
No Desktop.ini files found on G:
No mimics found on drive G:
Removed G:
Nema nigde nista. Sve je cisto. Imam ovaj program odavno...
Ekstraktovao sam ono sto si rekao u Sys32.
Dopuna: 25 Jul 2009 12:18
Lupio sam ne znam da li nema nista xD Mislio sam da se gleda ovo No Mimics found ali cutacu jer nemam pojma. Izvinite
Poslao: 25 Jul 2009 12:35
- dr_Bora

- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
Program vanja.exe koji se nalazi(o) na tom prvom flashu... Sam si ga postavio tamo ili ti nije poznat?
Poslao: 25 Jul 2009 13:47
- Srki94

- Mod u pemziji
- Pridružio: 14 Feb 2008
- Poruke: 12405
Nepoznat je to je bio moj flash glavni. Cudno jer ga stalno formatiram i na tom flashu je :
Gta San Andreas Multyplayer sa njihovog sajta
Moj program koji sam radio u basicu
i nista vise.
Tako da ne znam ni sta je to ...
Poslao: 25 Jul 2009 14:02
- dr_Bora

- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
OK. Pokreni USBNoRisk, pređi na Script tab i tamo iskopiraj sledeće:
folder_list_sub: %DRIVE%
Ponovi postupak sa priključivanjem drive-ova i na kraju postavi novi log.
Poslao: 25 Jul 2009 14:40
- Srki94

- Mod u pemziji
- Pridružio: 14 Feb 2008
- Poruke: 12405
USBNoRisk 2.4 (1 June 2009) by bobby
Started at 7/25/2009 2:39:02 PM
Searching for connected USB Mass storage...
Searching for other storage...
C: {cfc123b3-757f-11de-a7fe-806d6172696f}
D: {cfc123b8-757f-11de-a7fe-806d6172696f}
Scanning fixed storage...
No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for cfc123b3-757f-11de-a7fe-806d6172696f
No Desktop.ini files found on C:
No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for cfc123b8-757f-11de-a7fe-806d6172696f
No Desktop.ini files found on D:
Initial scan finished!
New device connected at 7/25/2009 2:39:21 PM
Scanning for connected USB mass storage...
G: {ba729f55-7601-11de-885a-001d72c737e6}
Added G:
Scanning USB mass storage for files...
Blocked file found: G:\autorun.inf.blocked
Content of G:\autorun.inf.blocked
action=Open folder to view files using Windows Explorer
Files referenced from G:\autorun.inf.blocked
No Autorun.inf files found on G:
No mountpoint found for ba729f55-7601-11de-885a-001d72c737e6
Desktop.ini found at G:\info\ contains interesting CLSID string
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
No mimics found on drive G:
Processing script
Drive letter for GUID: G:
SectionStart = 0
SectionEnd = 2
Folder list for G:\:
--a-- 4857339 G:\SA-MP-~1.EXE G:\sa-mp-0.2X-u1_2-install.exe
dr-hs 0 G:\info G:\info
--ahs 64 G:\info\Desktop.ini G:\info\Desktop.ini
-rahs 130560 G:\info\vanja.exe G:\info\vanja.exe
--a-- 8879 G:\ANYCAM~1.ZIP G:\Any Camera Capturer.zip
--a-- 328 G:\AUTORU~1.BLO G:\autorun.inf.blocked
Deleting blocked files:
Delete: G:\autorun.inf.blocked > Done!
Scan finished!
New device connected at 7/25/2009 2:39:47 PM
Scanning for connected USB mass storage...
H: {62219c0e-758a-11de-8858-001d72c737e6}
Added H:
Scanning USB mass storage for files...
No blocked files found on H:
No Autorun.inf files found on H:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
No Desktop.ini files found on H:
No mimics found on drive H:
Processing script
Drive letter for GUID: G:
SectionStart = 0
SectionEnd = 2
Folder list for G:\:
--a-- 4857339 G:\SA-MP-~1.EXE G:\sa-mp-0.2X-u1_2-install.exe
dr-hs 0 G:\info G:\info
--ahs 64 G:\info\Desktop.ini G:\info\Desktop.ini
-rahs 130560 G:\info\vanja.exe G:\info\vanja.exe
--a-- 8879 G:\ANYCAM~1.ZIP G:\Any Camera Capturer.zip
Deleting blocked files:
Scan finished!
Removed H:
Removed G:
New device connected at 7/25/2009 2:40:00 PM
Scanning for connected USB mass storage...
H: {62219c0e-758a-11de-8858-001d72c737e6}
Added H:
Scanning USB mass storage for files...
No blocked files found on H:
No Autorun.inf files found on H:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
No Desktop.ini files found on H:
No mimics found on drive H:
Processing script
Scan finished!
Removed H:
New device connected at 7/25/2009 2:40:10 PM
Scanning for connected USB mass storage...
H: {62219c0e-758a-11de-8858-001d72c737e6}
Added H:
Scanning USB mass storage for files...
No blocked files found on H:
No Autorun.inf files found on H:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
No Desktop.ini files found on H:
No mimics found on drive H:
Processing script
Scan finished!
Removed H:
Istim redosledom sam ubaciovao.
Poslao: 25 Jul 2009 14:50
- dr_Bora

- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
Ista priča kao i ranije... Sledeća skripta:
f_delete: %DRIVE%info\vanja.exe
folder_delete: %DRIVE%info
folder_list_sub: %DRIVE%
Postavi novi log.
Poslao: 26 Jul 2009 04:31
- Srki94

- Mod u pemziji
- Pridružio: 14 Feb 2008
- Poruke: 12405
Nasao mi je Desktop.ini na memory kartici.
Evo Log:
USBNoRisk 2.4 (1 June 2009) by bobby
Started at 7/26/2009 4:28:32 AM
Searching for connected USB Mass storage...
Searching for other storage...
C: {cfc123b3-757f-11de-a7fe-806d6172696f}
D: {cfc123b8-757f-11de-a7fe-806d6172696f}
Scanning fixed storage...
No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for cfc123b3-757f-11de-a7fe-806d6172696f
No Desktop.ini files found on C:
No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for cfc123b8-757f-11de-a7fe-806d6172696f
No Desktop.ini files found on D:
Initial scan finished!
New device connected at 7/26/2009 4:28:44 AM
Scanning for connected USB mass storage...
G: {ba729f55-7601-11de-885a-001d72c737e6}
Added G:
Scanning USB mass storage for files...
No blocked files found on G:
No Autorun.inf files found on G:
No mountpoint found for ba729f55-7601-11de-885a-001d72c737e6
Desktop.ini found at G:\info\ contains interesting CLSID string
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
No mimics found on drive G:
Processing script
Drive letter for GUID: G:
SectionStart = 0
SectionEnd = 3
driver version mismatch: use command "net stop catchme" to stop old driver
driver version mismatch: use command "net stop catchme" to stop old driver
delete file error: G:\info\vanja.exe, The handle is invalid.
Delete folder tree G:\info:
File lock detected:
USBNoRisk cannot find what locked the file
Delete: G:\info\vanja.exe > Error!
Delete: G:\info\Desktop.ini > Done!
Delete: G:\info > Error!
Delete: G:\info > Error!
Folder list for G:\:
--a-- 4857339 G:\SA-MP-~1.EXE G:\sa-mp-0.2X-u1_2-install.exe
dr-hs 0 G:\info G:\info
-rahs 130560 G:\info\vanja.exe G:\info\vanja.exe
--a-- 8879 G:\ANYCAM~1.ZIP G:\Any Camera Capturer.zip
Scan finished!
Removed G:
New device connected at 7/26/2009 4:28:59 AM
Scanning for connected USB mass storage...
H: {62219c0e-758a-11de-8858-001d72c737e6}
Added H:
Scanning USB mass storage for files...
No blocked files found on H:
No Autorun.inf files found on H:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
No Desktop.ini files found on H:
No mimics found on drive H:
Processing script
Scan finished!
Removed H:
New device connected at 7/26/2009 4:29:20 AM
Scanning for connected USB mass storage...
H: {62219c0e-758a-11de-8858-001d72c737e6}
Added H:
Scanning USB mass storage for files...
No blocked files found on H:
No Autorun.inf files found on H:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
No Desktop.ini files found on H:
No mimics found on drive H:
Processing script
Scan finished!
Removed H:
New device connected at 7/26/2009 4:29:29 AM
Scanning for connected USB mass storage...
H: {62219c0e-758a-11de-8858-001d72c737e6}
Added H:
Scanning USB mass storage for files...
No blocked files found on H:
No Autorun.inf files found on H:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
No Desktop.ini files found on H:
No mimics found on drive H:
Processing script
Scan finished!
Removed H:
New device connected at 7/26/2009 4:29:39 AM
Scanning for connected USB mass storage...
H: {62219c0e-758a-11de-8858-001d72c737e6}
Added H:
Scanning USB mass storage for files...
No blocked files found on H:
No Autorun.inf files found on H:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
No Desktop.ini files found on H:
No mimics found on drive H:
Processing script
Scan finished!
Removed H:
New device connected at 7/26/2009 4:29:45 AM
Scanning for connected USB mass storage...
H: {62219c0e-758a-11de-8858-001d72c737e6}
Added H:
Scanning USB mass storage for files...
No blocked files found on H:
No Autorun.inf files found on H:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
No Desktop.ini files found on H:
No mimics found on drive H:
Processing script
Scan finished!
Removed H:
New device connected at 7/26/2009 4:29:56 AM
Scanning for connected USB mass storage...
H: {62219c0e-758a-11de-8858-001d72c737e6}
Added H:
Scanning USB mass storage for files...
No blocked files found on H:
No Autorun.inf files found on H:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
No Desktop.ini files found on H:
No mimics found on drive H:
Processing script
Scan finished!
Removed H:
Uradio sam scan sa Avg-om i nije nista nasao.
Ali desi se da mi se otvori stranica u Firefoxu i da odjednom iskoci Avg i kaze da je nasao trojan.generic ... sve ih obrisem odmah.
Poslao: 26 Jul 2009 09:41
- dr_Bora

- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
Ukoliko u međuvremenu nisi gasio PC, sada ga restartuj i ponovi prethodni postupak.
Poslao: 26 Jul 2009 12:04
- Srki94

- Mod u pemziji
- Pridružio: 14 Feb 2008
- Poruke: 12405
Ne nisam gasio vec nekoliko dana laptop. Evo sada cu. Samo mislis na ceo postupak od samog pocetka, ili na postupak od prve skripte koju si mi dao?