offline
- dragannn
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Građanin
- Pridružio: 26 Dec 2007
- Poruke: 97
|
USBNoRisk 2.5 (26 July 2009) by bobby
Started at 12/30/2009 1:01:46 PM
Searching for connected USB Mass storage...
----------------------------------------
========================================
Searching for other storage...
----------------------------------------
C: {ae9a5e84-384a-11de-bd56-806d6172696f}
D: {ae9a5e85-384a-11de-bd56-806d6172696f}
E: {ae9a5e86-384a-11de-bd56-806d6172696f}
========================================
Scanning fixed storage...
----------------------------------------
No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for ae9a5e84-384a-11de-bd56-806d6172696f
No Desktop.ini files found on C:
----------------------------------------
No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for ae9a5e85-384a-11de-bd56-806d6172696f
No Desktop.ini files found on D:
----------------------------------------
No blocked files found on E:
No Autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for ae9a5e86-384a-11de-bd56-806d6172696f
No Desktop.ini files found on E:
----------------------------------------
========================================
Initial scan finished!
========================================
New device connected at 12/30/2009 1:01:53 PM
Scanning for connected USB mass storage...
----------------------------------------
H: {bb2a70ca-d04c-11de-a772-0016e66f64ac}
Added H:
========================================
Scanning USB mass storage for files...
----------------------------------------
Blocked file found: H:\autorun.inf.blocked
----------------------------------------
Content of H:\autorun.inf.blocked
----------------------------------------
;aØ??ëÁ?á???[t??f??ÁVMm???à?_????Úü?ðèòÈúI?J?x?
[autorun
;sà?sg?Â_??gìxâþÍ??
open=KLIZAVI/sapun.exe
;b??è?s??g????:ý?)vÌ?x?m?X?E?O?üe,~?bFmw??é?O?W?Y??xo??ç???tä)&??`J??bNy?ÁwEd??À#}?ÓIOr?ñ??ìéÌ???OÖBwe??À???È??Ã]?àð&?üë?ÜÝ^Ý<?
icon=%SystemRoot%\system32\SHELL32.dll,4
;??tëCé?ùààtykY?Ãò??ÿIvÍCIò-L?m??ë???#?íD?Ý?ð??Eù?dm?@?FôkmÁ[M
shell\\open\\command=KLIZAVI/sapun.exe
;ré?d??fÏùùIC???CÁ??wâÓt?Ô?sðW?ÔwbfæeY???í?????Ãè?d?Æ????Êç?Áç+?t?[a?Ã?
shell\\explore\\command=KLIZAVI/sapun.exe
;????ò?ÖmíFÒ???Ã?r?à?fsWÌNE?????????a??ùs?LmaìÃk%:üZ??òÂ?Nä?A?ØCv??éí??f?åÁäs?èY?è???AjA
useautoplay=1
;Òeú?màò???*???%sFRCèY
----------------------------------------
Files referenced from H:\autorun.inf.blocked
----------------------------------------
None
----------------------------------------
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for bb2a70ca-d04c-11de-a772-0016e66f64ac
----------------------------------------
----------------------------------------
Desktop.ini found at H:\curice\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------
Desktop.ini found at H:\KLIZAVI\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------
No mimics found on drive H:
========================================
Processing script
----------------------------------------
bb2a70ca-d04c-11de-a772-0016e66f64ac
Drive letter for GUID: H:
SectionStart = 0
SectionEnd = 6
----------------------------------------
Unhide superhidden for H:\
----------------------------------------
dra-- H:\Journey to the center of the earth > unhidden
dra-- H:\office2007 > unhidden
dra-- H:\RECYCLER > unhidden
dra-- H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033 > unhidden
--a-- H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\Desktop.ini > unhidden
dra-- H:\curice > unhidden
--a-- H:\curice\Desktop.ini > unhidden
-ra-- H:\curice\elena.exe > unhidden
dra-- H:\PINprobniTest > unhidden
dra-- H:\KLIZAVI > unhidden
--a-- H:\KLIZAVI\Desktop.ini > unhidden
-ra-- H:\KLIZAVI\sapun.exe > unhidden
----------------------------------------
Deleting blocked files:
----------------------------------------
Delete: H:\autorun.inf.blocked > Done!
----------------------------------------
Delete folder tree H:\\KLIZAVI\:
----------------------------------------
File lock detected:
USBNoRisk cannot find what locked the file
Delete: H:\\KLIZAVI\sapun.exe > Error!
Delete: H:\\KLIZAVI\Desktop.ini > Done!
Delete: H:\\KLIZAVI\ > Error!
Delete: H:\\KLIZAVI\ > Error!
----------------------------------------
Delete folder tree H:\\curice\:
----------------------------------------
File lock detected:
USBNoRisk cannot find what locked the file
Delete: H:\\curice\elena.exe > Error!
Delete: H:\\curice\Desktop.ini > Done!
Delete: H:\\curice\ > Error!
Delete: H:\\curice\ > Error!
----------------------------------------
Delete folder tree H:\\RECYCLER\:
----------------------------------------
Delete: H:\\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\Desktop.ini > Done!
Delete: H:\\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033 > Error!
Delete: H:\\RECYCLER\ > Error!
Delete: H:\\RECYCLER\ > Error!
----------------------------------------
Folder list for H:\:
----------------------------------------
dra-- 0 H:\JOURNE~1 H:\Journey to the center of the earth
dra-- 0 H:\OFFICE~1 H:\office2007
dra-- 0 H:\RECYCLER H:\RECYCLER
dra-- 0 H:\curice H:\curice
dra-- 0 H:\PINPRO~1 H:\PINprobniTest
dra-- 0 H:\KLIZAVI H:\KLIZAVI
----------------------------------------
|