Validnost logova van safe moda

2

Validnost logova van safe moda

offline
  • Velin 
  • Novi MyCity građanin
  • Pridružio: 21 Avg 2009
  • Poruke: 11

11/18/2011 2:55:07 PM > Scanning drive G: ( ~, HDD )...


>>> G:\nrhsg.pif - Malware > Deleted. (11.11.18. 14.55 nrhsg.pif.761105; MD5: 40024f2c51f4abd602a08afed2212ec1)

> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013
> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (MD5: 7457a5df1ff47c957acf1fa000d7d9ad)
> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svchost.exe (MD5: 733a906eb2ead42faef89ba4c8dc6d85)
> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\windowsupdate.com (MD5: 45c941fecceb99d704a903bf3f77760b)

>>> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013 - Malware.Folder > Deleted. (11.11.18. 14.55 S-1-5-21-1482476501-1644491937-682003330-1013.946754)

> G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213
> G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\Desktop.ini (MD5: e783bdd20a976eaeaae1ff4624487420)
> G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe (MD5: f4e54486c56337fcf4ebb3667c51d98a)
> G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\USB-Helper.exe (MD5: b8cc670451849ee57ac8519bcdf0a32c)

>>> G:\recycler\s-1-6-21-2434476501-1644491937-600003330-1213 - Malware.Folder > Deleted. (11.11.18. 14.55 s-1-6-21-2434476501-1644491937-600003330-1213.94137)

>>> G:\recycler.exe - Suspicious > Renamed. (MD5: 625a36d37fe852c276ca3d95d05078ae)


=> Malicious files : 1/1 deleted.
=> Malicious folders : 2/2 deleted.
=> Suspicious files : 1/1 renamed.

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Da uradimo jos jednu proveru za USB flash

- Preuzmi USBNoRisk na Desktop i pokreni ga duplim klikom na ikonicu programa.
- Sacekaj koji sekund dok program izvrsi inicijalno skeniranje.
- Ubacuj sve USB memorijske uredjaje redom u USB slot i svaki zadrzi u slotu po 10 sekundi.
- Ukoliko imas vise uredjaja za proveru, onda na parcetu papira zapisi kojim redom su ubacivani jer ce nam kasnije trebati taj podatak
- Kada zavrsis sa svim uredjajima, klikni desno dugme misa na sred prozora programa i odaberi opciju Save scrambled log. To ce automatski otvoriti log u Notepadu. Iskopiraj nam taj log iz Notepada na forum.

Objasnjenje: U USB memorijske uredjaje spadaju svi oni uredjaji koji po prikljucivanju na kompjuter dobijaju svoju oznaku particije. Tu spadaju USB flash drajvovi, eksterni hard-diskovi, memorijske kartice, MP3 i MP4 plejeri, neki mobilni telefoni, neki GPS (navigacioni) uredjaji itd.

---------------------------------

Ukoliko imas vise uredjaja, zapisi redosled kojim ih prikljucujes, da znas ukoliko budem dao skriptu na koji se odnosi.

offline
  • Velin 
  • Novi MyCity građanin
  • Pridružio: 21 Avg 2009
  • Poruke: 11

USBNoRisk 2.7 (28 December 2010) by bobby

Started at 11/19/2011 11:47:49 AM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
D: {92917b24-10b8-11e1-96b7-806d6172696f}
C: {92917b26-10b8-11e1-96b7-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 92917b26-10b8-11e1-96b7-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for 92917b24-10b8-11e1-96b7-806d6172696f
----------------------------------------
Desktop.ini found at D:\RECYCLED\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 11/19/2011 11:48:03 AM

Scanning for connected USB mass storage...
----------------------------------------
G: {66640363-11ec-11e1-9320-0007951fccfb}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 66640363-11ec-11e1-9320-0007951fccfb
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

Mimics found on drive G:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive G:
========================================

========================================
Removed G:
========================================


New device connected at 11/19/2011 11:50:11 AM

Scanning for connected USB mass storage...
----------------------------------------
G: {40721870-129c-11e1-9323-0007951fccfb}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 40721870-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive G:
========================================



New device connected at 11/19/2011 11:50:13 AM

Scanning for connected USB mass storage...
----------------------------------------
H: {40721871-129c-11e1-9323-0007951fccfb}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No autorun.inf files found on H:
No mountpoint found for 40721871-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive H:
========================================

========================================
Removed G:
========================================


New device connected at 11/19/2011 11:50:28 AM

Scanning for connected USB mass storage...
----------------------------------------
G: {40721870-129c-11e1-9323-0007951fccfb}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 40721870-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive G:
========================================

========================================
Removed H:
========================================


New device connected at 11/19/2011 11:50:31 AM

Scanning for connected USB mass storage...
----------------------------------------
H: {40721871-129c-11e1-9323-0007951fccfb}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No autorun.inf files found on H:
No mountpoint found for 40721871-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive H:
========================================

========================================
Removed G:
========================================


New device connected at 11/19/2011 11:50:33 AM

Scanning for connected USB mass storage...
----------------------------------------
G: {40721870-129c-11e1-9323-0007951fccfb}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 40721870-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive G:
========================================

========================================
Removed H:
========================================


New device connected at 11/19/2011 11:50:35 AM

Scanning for connected USB mass storage...
----------------------------------------
H: {40721871-129c-11e1-9323-0007951fccfb}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No autorun.inf files found on H:
No mountpoint found for 40721871-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive H:
========================================

========================================
Removed H:
========================================


New device connected at 11/19/2011 11:51:01 AM

Scanning for connected USB mass storage...
----------------------------------------
G: {40721872-129c-11e1-9323-0007951fccfb}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 40721872-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive G:
========================================

========================================

========================================


New device connected at 11/19/2011 11:51:34 AM

Scanning for connected USB mass storage...
----------------------------------------
Removed G:
========================================
New drive connected, but USBNoRisk can't find it
========================================

========================================

========================================

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Pokreni USBNoRisk i sacekaj koji sekund dok program izvrsi inicijalno skeniranje.
Sada ubodi problematicni USB stick br. 1 u komp, prebaci se na karticu Script i tamo kopiraj sledeci tekst:

{66640363-11ec-11e1-9320-0007951fccfb}
delete_mimics:
no_sh:
folder_list: %DRIVE%



Klikni na Run Script i sacekaj da USBNoRisk obavi svoje.
Na kartici monitor klikni desno dugme misa na sred prozora programa i odaberi opciju Save log.
Iskopiraj mi taj log iz Notepada na forum.

offline
  • Velin 
  • Novi MyCity građanin
  • Pridružio: 21 Avg 2009
  • Poruke: 11

Automatski se pokrenuo, odradio proces i izbacio sledeci izvestaj:
11/19/2011 3:49:47 PM > Scanning drive G: (no label ~4 GB, FAT32 flash drive )...


> G:\RECYCLER

>>> G:\recycler - Malware.Folder > Deleted. (11.11.19. 15.50 recycler.640454)


=> Malicious folders : 1/1 deleted.





A ovaj log koji ste trazili:

USBNoRisk 2.7 (28 December 2010) by bobby

Started at 11/19/2011 3:49:25 PM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
D: {92917b24-10b8-11e1-96b7-806d6172696f}
C: {92917b26-10b8-11e1-96b7-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 92917b26-10b8-11e1-96b7-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for 92917b24-10b8-11e1-96b7-806d6172696f
----------------------------------------
Desktop.ini found at D:\RECYCLED\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 11/19/2011 3:49:40 PM

Scanning for connected USB mass storage...
----------------------------------------
G: {66640363-11ec-11e1-9320-0007951fccfb}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No Autorun.inf files found on G:
No mountpoint found for 66640363-11ec-11e1-9320-0007951fccfb
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive G:
========================================


Processing script
----------------------------------------
66640363-11ec-11e1-9320-0007951fccfb
Drive letter for GUID: G:
SectionStart = 0
SectionEnd = 3
----------------------------------------
Deleting mimics:
----------------------------------------
f_delete: C:\Win\lsass.exe > File does not exist!
----------------------------------------
Unhide superhidden for G:\
----------------------------------------
dra-- G:\za stampu > unhidden
dra-- G:\RECYCLER > unhidden
d-a-- G:\FOUND.000 > unhidden
dra-- G:\PPTUSB > unhidden
dra-- G:\svega > unhidden
dra-- G:\Password Protect USB > unhidden
--a-- G:\Password Protect USB\+ > unhidden
--a-- G:\Password Protect USB\ncfpsys.exe > unhidden
dra-- G:\seminarski biologija-cula > unhidden
dra-- G:\Prekrsajno pravo > unhidden
dra-- G:\Engleski jezik 4 > unhidden
dra-- G:\Interna kontrola i revizija > unhidden
dra-- G:\Kriminalistika > unhidden
----------------------------------------
Folder list for G:\:
----------------------------------------

dra--   0   G:\ZASTAM~1   G:\za stampu
dra--   0   G:\RECYCLER   G:\RECYCLER
d-a--   0   G:\FOUND.000   G:\FOUND.000
dra--   0   G:\PPTUSB   G:\PPTUSB
dra--   0   G:\svega   G:\svega
dra--   0   G:\PASSWO~1   G:\Password Protect USB
dra--   0   G:\SEMINA~1   G:\seminarski biologija-cula
--a--   546   G:\op.txt   G:\op.txt
--a--   43520   G:\UPUTST~1.DOC   G:\Uputstvo za izradu seminarskog rada (pravni predmeti).doc
dra--   0   G:\PREKRS~1   G:\Prekrsajno pravo
dra--   0   G:\ENGLES~1   G:\Engleski jezik 4
dra--   0   G:\INTERN~1   G:\Interna kontrola i revizija
dra--   0   G:\KRIMIN~1   G:\Kriminalistika

----------------------------------------


Processing script
----------------------------------------
66640363-11ec-11e1-9320-0007951fccfb
Drive letter for GUID: G:
SectionStart = 0
SectionEnd = 3
----------------------------------------
Deleting mimics:
----------------------------------------
f_delete: C:\Win\lsass.exe > File does not exist!
----------------------------------------
Unhide superhidden for G:\
----------------------------------------
----------------------------------------
Folder list for G:\:
----------------------------------------

dra--   0   G:\ZASTAM~1   G:\za stampu
d-a--   0   G:\FOUND.000   G:\FOUND.000
dra--   0   G:\PPTUSB   G:\PPTUSB
dra--   0   G:\svega   G:\svega
dra--   0   G:\PASSWO~1   G:\Password Protect USB
dra--   0   G:\SEMINA~1   G:\seminarski biologija-cula
--a--   546   G:\op.txt   G:\op.txt
--a--   43520   G:\UPUTST~1.DOC   G:\Uputstvo za izradu seminarskog rada (pravni predmeti).doc
dra--   0   G:\PREKRS~1   G:\Prekrsajno pravo
dra--   0   G:\ENGLES~1   G:\Engleski jezik 4
dra--   0   G:\INTERN~1   G:\Interna kontrola i revizija
dra--   0   G:\KRIMIN~1   G:\Kriminalistika

----------------------------------------

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Otvori flesku i obrisi ova dva foldera

G:\RECYCLER
G:\FOUND.000

Imas li sada bilo kakvih problema sa racunarom?

offline
  • Velin 
  • Novi MyCity građanin
  • Pridružio: 21 Avg 2009
  • Poruke: 11

Sada radi sasvim dobro, nemam nikakvih problema.
Hvala mnogo.

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Da ne zaboravis Antivirus da instaliras i sp3, dao sam ti link. Preuzmes i samo pokrenes instalaciju sa desktopa.

Pozdrav.

Ko je trenutno na forumu
 

Ukupno su 988 korisnika na forumu :: 36 registrovanih, 1 sakriven i 951 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., aleksmajstor, babaroga, Ben Roj, bigfoot, bokisha253, cavatina, CHARLIE JA., draganca, draganl, francis begbie, krkalon, laurusri, Milicija Krajine, Milometer, MilosKop, milutin134, mocnijogurt, nenad81, panzerwaffe, pein, radoznao, rodoljub, Romibrat, shone34, stegonosa, Trpe Grozni, Tvrtko I, udbas, vathra, VJ, vukdra, W123, yrraf, zbazin, Zoca