flesh problem

2

flesh problem

offline
  • Pridružio: 26 Dec 2007
  • Poruke: 97

USBNoRisk 2.5 (26 July 2009) by bobby

Started at 12/30/2009 1:01:46 PM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
C: {ae9a5e84-384a-11de-bd56-806d6172696f}
D: {ae9a5e85-384a-11de-bd56-806d6172696f}
E: {ae9a5e86-384a-11de-bd56-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for ae9a5e84-384a-11de-bd56-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for ae9a5e85-384a-11de-bd56-806d6172696f
No Desktop.ini files found on D:
----------------------------------------

No blocked files found on E:
No Autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for ae9a5e86-384a-11de-bd56-806d6172696f
No Desktop.ini files found on E:
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 12/30/2009 1:01:53 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {bb2a70ca-d04c-11de-a772-0016e66f64ac}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
Blocked file found: H:\autorun.inf.blocked
----------------------------------------
Content of H:\autorun.inf.blocked
----------------------------------------
;aØ??ëÁ?á???[t??f??ÁVMm???à?_????Úü?ðèòÈúI?J?x?
[autorun
;sà?sg?Â_??gìxâþÍ??
open=KLIZAVI/sapun.exe
;b??è?s??g????:ý?)vÌ?x?m?X?E?O?üe,~?bFmw??é?O?W?Y??xo??ç???tä)&??`J??bNy?ÁwEd??À#}?ÓIOr?ñ??ìéÌ???OÖBwe??À???È??Ã]?àð&?üë?ÜÝ^Ý<?
icon=%SystemRoot%\system32\SHELL32.dll,4
;??tëCé?ùààtykY?Ãò??ÿIvÍCIò-L?m??ë???#?íD?Ý?ð??Eù?dm?@?FôkmÁ[M
shell\\open\\command=KLIZAVI/sapun.exe
;ré?d??fÏùùIC???CÁ??wâÓt?Ô?sðW?ÔwbfæeY???í?????Ãè?d?Æ????Êç?Áç+?t?[a?Ã?
shell\\explore\\command=KLIZAVI/sapun.exe
;????ò?ÖmíFÒ???Ã?r?à?fsWÌNE?????????a??ùs?LmaìÃk%:üZ??òÂ?Nä?A?ØCv??éí??f?åÁäs?èY?è???AjA
useautoplay=1
;Òeú?màò???*???%sFRCèY
----------------------------------------

Files referenced from H:\autorun.inf.blocked
----------------------------------------
None
----------------------------------------

----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for bb2a70ca-d04c-11de-a772-0016e66f64ac
----------------------------------------

----------------------------------------
Desktop.ini found at H:\curice\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------
Desktop.ini found at H:\KLIZAVI\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------

No mimics found on drive H:
========================================


Processing script
----------------------------------------
bb2a70ca-d04c-11de-a772-0016e66f64ac
Drive letter for GUID: H:
SectionStart = 0
SectionEnd = 6
----------------------------------------
Unhide superhidden for H:\
----------------------------------------
dra-- H:\Journey to the center of the earth > unhidden
dra-- H:\office2007 > unhidden
dra-- H:\RECYCLER > unhidden
dra-- H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033 > unhidden
--a-- H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\Desktop.ini > unhidden
dra-- H:\curice > unhidden
--a-- H:\curice\Desktop.ini > unhidden
-ra-- H:\curice\elena.exe > unhidden
dra-- H:\PINprobniTest > unhidden
dra-- H:\KLIZAVI > unhidden
--a-- H:\KLIZAVI\Desktop.ini > unhidden
-ra-- H:\KLIZAVI\sapun.exe > unhidden
----------------------------------------
Deleting blocked files:
----------------------------------------
Delete: H:\autorun.inf.blocked > Done!
----------------------------------------
Delete folder tree H:\\KLIZAVI\:
----------------------------------------
File lock detected:
USBNoRisk cannot find what locked the file
Delete: H:\\KLIZAVI\sapun.exe > Error!
Delete: H:\\KLIZAVI\Desktop.ini > Done!
Delete: H:\\KLIZAVI\ > Error!
Delete: H:\\KLIZAVI\ > Error!
----------------------------------------
Delete folder tree H:\\curice\:
----------------------------------------
File lock detected:
USBNoRisk cannot find what locked the file
Delete: H:\\curice\elena.exe > Error!
Delete: H:\\curice\Desktop.ini > Done!
Delete: H:\\curice\ > Error!
Delete: H:\\curice\ > Error!
----------------------------------------
Delete folder tree H:\\RECYCLER\:
----------------------------------------
Delete: H:\\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\Desktop.ini > Done!
Delete: H:\\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033 > Error!
Delete: H:\\RECYCLER\ > Error!
Delete: H:\\RECYCLER\ > Error!
----------------------------------------
Folder list for H:\:
----------------------------------------

dra--   0   H:\JOURNE~1   H:\Journey to the center of the earth
dra--   0   H:\OFFICE~1   H:\office2007
dra--   0   H:\RECYCLER   H:\RECYCLER
dra--   0   H:\curice   H:\curice
dra--   0   H:\PINPRO~1   H:\PINprobniTest
dra--   0   H:\KLIZAVI   H:\KLIZAVI

----------------------------------------

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Moraćemo još jednom da ponovimo postupak.


- Pokrenuti USBNoRisk i sačekati da izvrši inicijalno skeniranje.

- Po završetku inicijalnog skeniranja priključiti USB memorijski uređaj.

- Kliknuti na karticu Script;

U beli okvir prozora iskopirati sledeći tekst:

{bb2a70ca-d04c-11de-a772-0016e66f64ac}
f_delete:%DRIVE%curice\elena.exe
f_delete:%DRIVE%KLIZAVI\sapun.exe
folder_delete:%DRIVE%curice\
folder_delete:%DRIVE%klizavi\
folder_delete:%DRIVE%RECYCLER\
folder_list:%DRIVE%


- Izvršiti komandu klikom na taster Run Script;



Po izvršenju komande USBNoRisk će se automatski vratiti na karticu Monitor;

- Uraditi desni klik unutar belog okvira prozora i odabrati opciju Save Log;

Otvoriće se prozor Notepad_a sa tekstom koji je potrebno iskopirati ovde u poruci.

offline
  • Pridružio: 26 Dec 2007
  • Poruke: 97

Napisano: 31 Dec 2009 11:49

USBNoRisk 2.5 (26 July 2009) by bobby

Started at 12/31/2009 11:40:07 AM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
C: {ae9a5e84-384a-11de-bd56-806d6172696f}
D: {ae9a5e85-384a-11de-bd56-806d6172696f}
E: {ae9a5e86-384a-11de-bd56-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for ae9a5e84-384a-11de-bd56-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for ae9a5e85-384a-11de-bd56-806d6172696f
No Desktop.ini files found on D:
----------------------------------------

No blocked files found on E:
No Autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for ae9a5e86-384a-11de-bd56-806d6172696f
No Desktop.ini files found on E:
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 12/31/2009 11:40:22 AM

Scanning for connected USB mass storage...
----------------------------------------
H: {bb2a70ca-d04c-11de-a772-0016e66f64ac}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for bb2a70ca-d04c-11de-a772-0016e66f64ac
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
========================================


Processing script
----------------------------------------
bb2a70ca-d04c-11de-a772-0016e66f64ac
Drive letter for GUID: H:
SectionStart = 1
SectionEnd = 7
f_delete:
file "H:\curice\elena.exe" deleted successfully
f_delete:
file "H:\KLIZAVI\sapun.exe" deleted successfully
----------------------------------------
Delete folder tree H:\curice\:
----------------------------------------
Folder tree is empty
Delete: H:\curice\ > Error!
----------------------------------------
Delete folder tree H:\klizavi\:
----------------------------------------
Folder tree is empty
Delete: H:\klizavi\ > Error!
----------------------------------------
Delete folder tree H:\RECYCLER\:
----------------------------------------
Delete: H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033 > Error!
Delete: H:\RECYCLER\ > Error!
Delete: H:\RECYCLER\ > Error!
----------------------------------------
Folder list for H:\:
----------------------------------------

dra--   0   H:\JOURNE~1   H:\Journey to the center of the earth
dra--   0   H:\OFFICE~1   H:\office2007
dra--   0   H:\RECYCLER   H:\RECYCLER
dra--   0   H:\curice   H:\curice
dra--   0   H:\PINPRO~1   H:\PINprobniTest
dra--   0   H:\KLIZAVI   H:\KLIZAVI

----------------------------------------

Dopuna: 31 Dec 2009 12:02

**********************************************************
evo nesto sto sam primetio:
jel treba da deinstaliram combofix?
na D particiji primetio sam da ima $RECYCLE.BIN(0 bytes) i RECYCLER(85 bytes) folder,inace su prazni.
na E particiji RECYCLER(85bytes) isto prazan.
to nije dosada bilo.

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Idemo još jednom, samo ovaj put isključi Anti-Virus zaštitu...

http://www.mycity.rs/Uputstva/Iskljucivanje-zastitnog-softvera.html


- Pokrenuti USBNoRisk i sačekati da izvrši inicijalno skeniranje.

- Po završetku inicijalnog skeniranja priključiti USB memorijski uređaj.

- Kliknuti na karticu Script;

U beli okvir prozora iskopirati sledeći tekst:

{bb2a70ca-d04c-11de-a772-0016e66f64ac}
folder_delete:%DRIVE%RECYCLER\
folder_delete:%DRIVE%KLIZAVI\
folder_delete:%DRIVE%curice\
folder_list:%DRIVE%


- Izvršiti komandu klikom na taster Run Script;



Po izvršenju komande USBNoRisk će se automatski vratiti na karticu Monitor;

- Uraditi desni klik unutar belog okvira prozora i odabrati opciju Save Log;

Otvoriće se prozor Notepad_a sa tekstom koji je potrebno iskopirati ovde u poruci.

offline
  • Pridružio: 26 Dec 2007
  • Poruke: 97

Napisano: 31 Dec 2009 15:48

USBNoRisk 2.5 (26 July 2009) by bobby

Started at 12/31/2009 3:33:40 PM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
C: {ae9a5e84-384a-11de-bd56-806d6172696f}
D: {ae9a5e85-384a-11de-bd56-806d6172696f}
E: {ae9a5e86-384a-11de-bd56-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for ae9a5e84-384a-11de-bd56-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for ae9a5e85-384a-11de-bd56-806d6172696f
No Desktop.ini files found on D:
----------------------------------------

No blocked files found on E:
No Autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for ae9a5e86-384a-11de-bd56-806d6172696f
No Desktop.ini files found on E:
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 12/31/2009 3:33:49 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {bb2a70ca-d04c-11de-a772-0016e66f64ac}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for bb2a70ca-d04c-11de-a772-0016e66f64ac
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
========================================


Processing script
----------------------------------------
bb2a70ca-d04c-11de-a772-0016e66f64ac
Drive letter for GUID: H:
SectionStart = 1
SectionEnd = 5
----------------------------------------
Delete folder tree H:\RECYCLER\:
----------------------------------------
Delete: H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033 > Error!
Delete: H:\RECYCLER\ > Error!
Delete: H:\RECYCLER\ > Error!
----------------------------------------
Delete folder tree H:\KLIZAVI\:
----------------------------------------
Folder tree is empty
Delete: H:\KLIZAVI\ > Error!
----------------------------------------
Delete folder tree H:\curice\:
----------------------------------------
Folder tree is empty
Delete: H:\curice\ > Error!
----------------------------------------
Folder list for H:\:
----------------------------------------

dra--   0   H:\JOURNE~1   H:\Journey to the center of the earth
dra--   0   H:\OFFICE~1   H:\office2007
dra--   0   H:\RECYCLER   H:\RECYCLER
dra--   0   H:\curice   H:\curice
dra--   0   H:\PINPRO~1   H:\PINprobniTest
dra--   0   H:\KLIZAVI   H:\KLIZAVI

----------------------------------------

========================================
Removed H:
========================================

Dopuna: 31 Dec 2009 15:54

windows firewall iskljucio
avast,odbranbeni modul i stalnu zastitu iskljucio
spybot, iskljucio u rezidentu obe stavke i resetovan teatimer.

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Da probamo na drugi način...

Odradi po sledećem uputstvu...

http://www.mycity.rs/Uputstva/Kako-videti-skrivene-fajlove.html


Zatim obriši sledeće foldere:

- RECYCLER
- KLIZAVI
- curice




Kada to odradiš javi mi stanje.

offline
  • Pridružio: 26 Dec 2007
  • Poruke: 97

srecna nova!
e izvini ali ne znam gde da obrisem,daj mi upustvo,kamo srece da sam pripravnik kao ti:)
pokusao sam na kompu da obrisem recycler ali dobijam ovo:cennot delete recycler acess iz denied. make sure the disk iz not full or write-protected and that thefile iz not currently in use.
na C particiji je skriven a na E i D je obican folder
flesh nisam hteo da stavljam dok mi ne kazes...pozz

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Slobodno priključi usb uređaj i sa njega obriši foldere koje sam ti naveo.

Taj RECYCLER na kompjuteru je legitiman.

Znači samo sa usb uređaja ih obriši.


Srećna Nova...

offline
  • Pridružio: 26 Dec 2007
  • Poruke: 97

prikljucio i obrisao, i formatirao,radi sad kao pre:)
bio sam skenirao sa avastom kad nisu bili skriveni fajlovi i nasao je:C:\System Volume Information\_restore{F0C9D7D2-1A7A-444E-9401-EB1FE5439692}\RP20\A0008958.exe [L] Win32:Malware-gen (0)
Datoteka je uspešno premeštena u chest...
ali sve u svemu,hvala i sve najbolje

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Isprati još sledeće...


Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

ComboFix /Uninstall

Primeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.

Ko je trenutno na forumu
 

Ukupno su 1166 korisnika na forumu :: 17 registrovanih, 2 sakrivenih i 1147 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: avijacija, Bane san, Bickoooo, dragoljub11987, Haris, kybonacci, lcc, Leonov, Majka, mercedesamg, Mercury, Metanoja, raykan, sombrero, Stija zmija, zodiac94, Živković