Poslao: 18 Nov 2011 14:56
|
offline
- Velin
- Novi MyCity građanin
- Pridružio: 21 Avg 2009
- Poruke: 11
|
11/18/2011 2:55:07 PM > Scanning drive G: ( ~, HDD )...
>>> G:\nrhsg.pif - Malware > Deleted. (11.11.18. 14.55 nrhsg.pif.761105; MD5: 40024f2c51f4abd602a08afed2212ec1)
> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013
> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (MD5: 7457a5df1ff47c957acf1fa000d7d9ad)
> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svchost.exe (MD5: 733a906eb2ead42faef89ba4c8dc6d85)
> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\windowsupdate.com (MD5: 45c941fecceb99d704a903bf3f77760b)
>>> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013 - Malware.Folder > Deleted. (11.11.18. 14.55 S-1-5-21-1482476501-1644491937-682003330-1013.946754)
> G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213
> G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\Desktop.ini (MD5: e783bdd20a976eaeaae1ff4624487420)
> G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe (MD5: f4e54486c56337fcf4ebb3667c51d98a)
> G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\USB-Helper.exe (MD5: b8cc670451849ee57ac8519bcdf0a32c)
>>> G:\recycler\s-1-6-21-2434476501-1644491937-600003330-1213 - Malware.Folder > Deleted. (11.11.18. 14.55 s-1-6-21-2434476501-1644491937-600003330-1213.94137)
>>> G:\recycler.exe - Suspicious > Renamed. (MD5: 625a36d37fe852c276ca3d95d05078ae)
=> Malicious files : 1/1 deleted.
=> Malicious folders : 2/2 deleted.
=> Suspicious files : 1/1 renamed.
|
|
|
|
Poslao: 18 Nov 2011 16:23
|
rip
- argus
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
Da uradimo jos jednu proveru za USB flash
- Preuzmi USBNoRisk na Desktop i pokreni ga duplim klikom na ikonicu programa.
- Sacekaj koji sekund dok program izvrsi inicijalno skeniranje.
- Ubacuj sve USB memorijske uredjaje redom u USB slot i svaki zadrzi u slotu po 10 sekundi.
- Ukoliko imas vise uredjaja za proveru, onda na parcetu papira zapisi kojim redom su ubacivani jer ce nam kasnije trebati taj podatak
- Kada zavrsis sa svim uredjajima, klikni desno dugme misa na sred prozora programa i odaberi opciju Save scrambled log. To ce automatski otvoriti log u Notepadu. Iskopiraj nam taj log iz Notepada na forum.
Objasnjenje: U USB memorijske uredjaje spadaju svi oni uredjaji koji po prikljucivanju na kompjuter dobijaju svoju oznaku particije. Tu spadaju USB flash drajvovi, eksterni hard-diskovi, memorijske kartice, MP3 i MP4 plejeri, neki mobilni telefoni, neki GPS (navigacioni) uredjaji itd.
---------------------------------
Ukoliko imas vise uredjaja, zapisi redosled kojim ih prikljucujes, da znas ukoliko budem dao skriptu na koji se odnosi.
|
|
|
|
Poslao: 19 Nov 2011 11:51
|
offline
- Velin
- Novi MyCity građanin
- Pridružio: 21 Avg 2009
- Poruke: 11
|
USBNoRisk 2.7 (28 December 2010) by bobby
Started at 11/19/2011 11:47:49 AM
Searching for connected USB Mass storage...
----------------------------------------
========================================
Searching for other storage...
----------------------------------------
D: {92917b24-10b8-11e1-96b7-806d6172696f}
C: {92917b26-10b8-11e1-96b7-806d6172696f}
========================================
Scanning fixed storage...
----------------------------------------
No blocked files found on C:
No autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 92917b26-10b8-11e1-96b7-806d6172696f
No Desktop.ini files found on C:
----------------------------------------
No blocked files found on D:
No autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for 92917b24-10b8-11e1-96b7-806d6172696f
----------------------------------------
Desktop.ini found at D:\RECYCLED\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------
========================================
Initial scan finished!
========================================
New device connected at 11/19/2011 11:48:03 AM
Scanning for connected USB mass storage...
----------------------------------------
G: {66640363-11ec-11e1-9320-0007951fccfb}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 66640363-11ec-11e1-9320-0007951fccfb
----------------------------------------
No Desktop.ini files found on G:
----------------------------------------
Mimics found on drive G:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive G:
========================================
========================================
Removed G:
========================================
New device connected at 11/19/2011 11:50:11 AM
Scanning for connected USB mass storage...
----------------------------------------
G: {40721870-129c-11e1-9323-0007951fccfb}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 40721870-129c-11e1-9323-0007951fccfb
----------------------------------------
No Desktop.ini files found on G:
----------------------------------------
No mimics found on drive G:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive G:
========================================
New device connected at 11/19/2011 11:50:13 AM
Scanning for connected USB mass storage...
----------------------------------------
H: {40721871-129c-11e1-9323-0007951fccfb}
Added H:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No autorun.inf files found on H:
No mountpoint found for 40721871-129c-11e1-9323-0007951fccfb
----------------------------------------
No Desktop.ini files found on H:
----------------------------------------
No mimics found on drive H:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive H:
========================================
========================================
Removed G:
========================================
New device connected at 11/19/2011 11:50:28 AM
Scanning for connected USB mass storage...
----------------------------------------
G: {40721870-129c-11e1-9323-0007951fccfb}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 40721870-129c-11e1-9323-0007951fccfb
----------------------------------------
No Desktop.ini files found on G:
----------------------------------------
No mimics found on drive G:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive G:
========================================
========================================
Removed H:
========================================
New device connected at 11/19/2011 11:50:31 AM
Scanning for connected USB mass storage...
----------------------------------------
H: {40721871-129c-11e1-9323-0007951fccfb}
Added H:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No autorun.inf files found on H:
No mountpoint found for 40721871-129c-11e1-9323-0007951fccfb
----------------------------------------
No Desktop.ini files found on H:
----------------------------------------
No mimics found on drive H:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive H:
========================================
========================================
Removed G:
========================================
New device connected at 11/19/2011 11:50:33 AM
Scanning for connected USB mass storage...
----------------------------------------
G: {40721870-129c-11e1-9323-0007951fccfb}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 40721870-129c-11e1-9323-0007951fccfb
----------------------------------------
No Desktop.ini files found on G:
----------------------------------------
No mimics found on drive G:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive G:
========================================
========================================
Removed H:
========================================
New device connected at 11/19/2011 11:50:35 AM
Scanning for connected USB mass storage...
----------------------------------------
H: {40721871-129c-11e1-9323-0007951fccfb}
Added H:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No autorun.inf files found on H:
No mountpoint found for 40721871-129c-11e1-9323-0007951fccfb
----------------------------------------
No Desktop.ini files found on H:
----------------------------------------
No mimics found on drive H:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive H:
========================================
========================================
Removed H:
========================================
New device connected at 11/19/2011 11:51:01 AM
Scanning for connected USB mass storage...
----------------------------------------
G: {40721872-129c-11e1-9323-0007951fccfb}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 40721872-129c-11e1-9323-0007951fccfb
----------------------------------------
No Desktop.ini files found on G:
----------------------------------------
No mimics found on drive G:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive G:
========================================
========================================
========================================
New device connected at 11/19/2011 11:51:34 AM
Scanning for connected USB mass storage...
----------------------------------------
Removed G:
========================================
New drive connected, but USBNoRisk can't find it
========================================
========================================
========================================
|
|
|
|
Poslao: 19 Nov 2011 12:39
|
rip
- argus
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
Pokreni USBNoRisk i sacekaj koji sekund dok program izvrsi inicijalno skeniranje.
Sada ubodi problematicni USB stick br. 1 u komp, prebaci se na karticu Script i tamo kopiraj sledeci tekst:
{66640363-11ec-11e1-9320-0007951fccfb}
delete_mimics:
no_sh:
folder_list: %DRIVE%
Klikni na Run Script i sacekaj da USBNoRisk obavi svoje.
Na kartici monitor klikni desno dugme misa na sred prozora programa i odaberi opciju Save log.
Iskopiraj mi taj log iz Notepada na forum.
|
|
|
|
Poslao: 19 Nov 2011 15:53
|
offline
- Velin
- Novi MyCity građanin
- Pridružio: 21 Avg 2009
- Poruke: 11
|
Automatski se pokrenuo, odradio proces i izbacio sledeci izvestaj:
11/19/2011 3:49:47 PM > Scanning drive G: (no label ~4 GB, FAT32 flash drive )...
> G:\RECYCLER
>>> G:\recycler - Malware.Folder > Deleted. (11.11.19. 15.50 recycler.640454)
=> Malicious folders : 1/1 deleted.
A ovaj log koji ste trazili:
USBNoRisk 2.7 (28 December 2010) by bobby
Started at 11/19/2011 3:49:25 PM
Searching for connected USB Mass storage...
----------------------------------------
========================================
Searching for other storage...
----------------------------------------
D: {92917b24-10b8-11e1-96b7-806d6172696f}
C: {92917b26-10b8-11e1-96b7-806d6172696f}
========================================
Scanning fixed storage...
----------------------------------------
No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 92917b26-10b8-11e1-96b7-806d6172696f
No Desktop.ini files found on C:
----------------------------------------
No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for 92917b24-10b8-11e1-96b7-806d6172696f
----------------------------------------
Desktop.ini found at D:\RECYCLED\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------
========================================
Initial scan finished!
========================================
New device connected at 11/19/2011 3:49:40 PM
Scanning for connected USB mass storage...
----------------------------------------
G: {66640363-11ec-11e1-9320-0007951fccfb}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No Autorun.inf files found on G:
No mountpoint found for 66640363-11ec-11e1-9320-0007951fccfb
----------------------------------------
No Desktop.ini files found on G:
----------------------------------------
No mimics found on drive G:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive G:
========================================
Processing script
----------------------------------------
66640363-11ec-11e1-9320-0007951fccfb
Drive letter for GUID: G:
SectionStart = 0
SectionEnd = 3
----------------------------------------
Deleting mimics:
----------------------------------------
f_delete: C:\Win\lsass.exe > File does not exist!
----------------------------------------
Unhide superhidden for G:\
----------------------------------------
dra-- G:\za stampu > unhidden
dra-- G:\RECYCLER > unhidden
d-a-- G:\FOUND.000 > unhidden
dra-- G:\PPTUSB > unhidden
dra-- G:\svega > unhidden
dra-- G:\Password Protect USB > unhidden
--a-- G:\Password Protect USB\+ > unhidden
--a-- G:\Password Protect USB\ncfpsys.exe > unhidden
dra-- G:\seminarski biologija-cula > unhidden
dra-- G:\Prekrsajno pravo > unhidden
dra-- G:\Engleski jezik 4 > unhidden
dra-- G:\Interna kontrola i revizija > unhidden
dra-- G:\Kriminalistika > unhidden
----------------------------------------
Folder list for G:\:
----------------------------------------
dra-- 0 G:\ZASTAM~1 G:\za stampu
dra-- 0 G:\RECYCLER G:\RECYCLER
d-a-- 0 G:\FOUND.000 G:\FOUND.000
dra-- 0 G:\PPTUSB G:\PPTUSB
dra-- 0 G:\svega G:\svega
dra-- 0 G:\PASSWO~1 G:\Password Protect USB
dra-- 0 G:\SEMINA~1 G:\seminarski biologija-cula
--a-- 546 G:\op.txt G:\op.txt
--a-- 43520 G:\UPUTST~1.DOC G:\Uputstvo za izradu seminarskog rada (pravni predmeti).doc
dra-- 0 G:\PREKRS~1 G:\Prekrsajno pravo
dra-- 0 G:\ENGLES~1 G:\Engleski jezik 4
dra-- 0 G:\INTERN~1 G:\Interna kontrola i revizija
dra-- 0 G:\KRIMIN~1 G:\Kriminalistika
----------------------------------------
Processing script
----------------------------------------
66640363-11ec-11e1-9320-0007951fccfb
Drive letter for GUID: G:
SectionStart = 0
SectionEnd = 3
----------------------------------------
Deleting mimics:
----------------------------------------
f_delete: C:\Win\lsass.exe > File does not exist!
----------------------------------------
Unhide superhidden for G:\
----------------------------------------
----------------------------------------
Folder list for G:\:
----------------------------------------
dra-- 0 G:\ZASTAM~1 G:\za stampu
d-a-- 0 G:\FOUND.000 G:\FOUND.000
dra-- 0 G:\PPTUSB G:\PPTUSB
dra-- 0 G:\svega G:\svega
dra-- 0 G:\PASSWO~1 G:\Password Protect USB
dra-- 0 G:\SEMINA~1 G:\seminarski biologija-cula
--a-- 546 G:\op.txt G:\op.txt
--a-- 43520 G:\UPUTST~1.DOC G:\Uputstvo za izradu seminarskog rada (pravni predmeti).doc
dra-- 0 G:\PREKRS~1 G:\Prekrsajno pravo
dra-- 0 G:\ENGLES~1 G:\Engleski jezik 4
dra-- 0 G:\INTERN~1 G:\Interna kontrola i revizija
dra-- 0 G:\KRIMIN~1 G:\Kriminalistika
----------------------------------------
|
|
|
|
Poslao: 19 Nov 2011 17:09
|
rip
- argus
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
Otvori flesku i obrisi ova dva foldera
G:\RECYCLER
G:\FOUND.000
Imas li sada bilo kakvih problema sa racunarom?
|
|
|
|
Poslao: 20 Nov 2011 00:49
|
offline
- Velin
- Novi MyCity građanin
- Pridružio: 21 Avg 2009
- Poruke: 11
|
Sada radi sasvim dobro, nemam nikakvih problema.
Hvala mnogo.
|
|
|
|
Poslao: 20 Nov 2011 09:37
|
rip
- argus
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
Da ne zaboravis Antivirus da instaliras i sp3, dao sam ti link. Preuzmes i samo pokrenes instalaciju sa desktopa.
Pozdrav.
|
|
|
|