Salje se link ka virusu preko msn-a

3

Salje se link ka virusu preko msn-a

offline
  • Pridružio: 14 Feb 2008
  • Poruke: 12405

USBNoRisk 2.4 (1 June 2009) by bobby

Started at 7/26/2009 1:27:21 PM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
C: {cfc123b3-757f-11de-a7fe-806d6172696f}
D: {cfc123b8-757f-11de-a7fe-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for cfc123b3-757f-11de-a7fe-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for cfc123b8-757f-11de-a7fe-806d6172696f
No Desktop.ini files found on D:
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 7/26/2009 1:27:34 PM

Scanning for connected USB mass storage...
----------------------------------------
G: {ba729f55-7601-11de-885a-001d72c737e6}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No Autorun.inf files found on G:
No mountpoint found for ba729f55-7601-11de-885a-001d72c737e6
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
========================================

Processing script
----------------------------------------
ba729f55-7601-11de-885a-001d72c737e6
Drive letter for GUID: G:
SectionStart = 1
SectionEnd = 4
f_delete:
file "G:\info\vanja.exe" deleted successfully
----------------------------------------
Delete folder tree G:\info:
----------------------------------------
Folder tree is empty
Delete: G:\info > Error!
----------------------------------------
Folder list for G:\:
----------------------------------------

--a--   4857339   G:\SA-MP-~1.EXE   G:\sa-mp-0.2X-u1_2-install.exe
dr-hs   0   G:\info   G:\info
--a--   8879   G:\ANYCAM~1.ZIP   G:\Any Camera Capturer.zip

----------------------------------------

========================================
Scan finished!
========================================

========================================
Removed G:
========================================


New device connected at 7/26/2009 1:27:48 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {62219c0e-758a-11de-8858-001d72c737e6}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
========================================

Processing script
----------------------------------------
========================================
Scan finished!
========================================

========================================
Removed H:
========================================


New device connected at 7/26/2009 1:27:59 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {62219c0e-758a-11de-8858-001d72c737e6}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
========================================

Processing script
----------------------------------------
========================================
Scan finished!
========================================

========================================
Removed H:
========================================


New device connected at 7/26/2009 1:28:04 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {62219c0e-758a-11de-8858-001d72c737e6}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for 62219c0e-758a-11de-8858-001d72c737e6
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
========================================

Processing script
----------------------------------------
========================================
Scan finished!
========================================

========================================
Removed H:
========================================



offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Aktiviraj prikaz skrivenih file-ova: [Link mogu videti samo ulogovani korisnici]


Sa prvog flasha obriši folder Info.



Ostalo je čisto. Ako i dalje dolazi do slanja linkova sa tvog account-a za messenger, potrebno je da promeniš šifru (pa će onda biti ok).


Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

combofix /u

Primeti da postoji razmak između "ComboFix" i "/u".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.



Sem ako imaš neko pitanje, ovde smo gotovi.



offline
  • Pridružio: 14 Feb 2008
  • Poruke: 12405

Da imam pitanje. Nazalost Sad.
Nigde nema foldera info na fles memoriji, naravno ukljucio sam show hiden files and folders.

Hvala puno na vasoj pomoci dr Boro.

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pogledaj na svih flash drive-ovima koje imaš - na jednom od njih je.

Us svakom slučaju, folder je prazan tako da ne škodi ni da ga ostaviš.

offline
  • Pridružio: 14 Feb 2008
  • Poruke: 12405

Napisano: 26 Jul 2009 14:09

Da to sam i ja primetio iz onog loga gore. Nema ni na jednom fles drajvu.
Nema veze.
Hvala ti puno na strucnoj pomoci. Primetio sam da se niko ne zali na linkove ka softweru, takodje nema vise linkova koji se otvaraju u Firefox-u, i AVG "iskace". Hvala.

Dopuna: 27 Jul 2009 23:29

Link se opet salje. Ne smem da stavim link ovde a mozda i nije virus vec neka reklamacija na Face Booku?

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Jesi li promenio šifru?

offline
  • Pridružio: 14 Feb 2008
  • Poruke: 12405

Jesam, promenio sam.

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Skini novi ComboFix, pokreni ga i postavi log koji dobiješ.

Ko je trenutno na forumu
 

Ukupno su 846 korisnika na forumu :: 24 registrovanih, 0 sakrivenih i 822 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: bojanM84, celik, Django777, Draganeli, esx66, interesujeme, kolateralnasteta, MDrasko, MiloradKomadic, mrav pesadinac, opt1, Otto Grunf, Paklenica, panzerwaffe, pein, raketaš, RD84, S-lash, Sir Budimir, SlaKoj, t84dar, tmanda323, zziko, 1107