offline
- gilespis
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Građanin
- Pridružio: 04 Jan 2011
- Poruke: 79
- Gde živiš: Niš
|
Napisano: 30 Maj 2011 21:04
ovaj prvi deo, da postavim log koji bude bio nnapravljen na kraju ciscenja nisam bas razumeo, jer kad se sve zavrsilo nista nisam mogao da postavim
Dopuna: 30 Maj 2011 21:36
USBNoRisk 2.7 (28 December 2010) by bobby
Started at 30.5.2011 21:12:06
Searching for connected USB Mass storage...
----------------------------------------
I: {bda035d3-e83b-11df-82d3-00e04da51dad}
========================================
Searching for other storage...
----------------------------------------
F: {55237bc5-411e-11e0-9ae4-806e6f6e6963}
C: {8ce65185-e62f-11df-861d-806e6f6e6963}
D: {8ce65186-e62f-11df-861d-806e6f6e6963}
========================================
Scanning removable storage...
----------------------------------------
No blocked files found on I:
No autorun.inf files found on I:
Sanitized mountpoint for bda035d3-e83b-11df-82d3-00e04da51dad
No Desktop.ini files found on I:
No mimics found on drive I:
No .lnk/.pif/.com/.scr files found on drive I:
----------------------------------------
Scanning fixed storage...
----------------------------------------
No blocked files found on C:
No autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 8ce65185-e62f-11df-861d-806e6f6e6963
----------------------------------------
Desktop.ini found at C:\ComboFix\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={20D04FE0-3AEA-1069-A2D8-08002B30309D}
IconResource=C:\Windows\system32\SHELL32.dll,4
----------------------------------------
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D},InfoTip = @%SystemRoot%\system32\shell32.dll,-22913
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D},LocalizedString = @%SystemRoot%\system32\shell32.dll,-9216
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon,@ = %SystemRoot%\System32\imageres.dll,-109
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32,@ = %SystemRoot%\system32\shell32.dll
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find,@ = @%SystemRoot%\system32\shell32.dll,-8503
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find\command,@ = %SystemRoot%\Explorer.exe
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage,@ = @%systemroot%\system32\mycomput.dll,-400
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage,MUIVerb = @%systemroot%\system32\mycomput.dll,-400
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage\command,@ = %SystemRoot%\system32\CompMgmtLauncher.exe
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D},InfoTip = @%SystemRoot%\system32\shell32.dll,-22913
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D},LocalizedString = @%SystemRoot%\system32\shell32.dll,-9216
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon,@ = %SystemRoot%\System32\imageres.dll,-109
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32,@ = %SystemRoot%\system32\shell32.dll
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find,@ = @%SystemRoot%\system32\shell32.dll,-8503
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find\command,@ = %SystemRoot%\Explorer.exe
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage,@ = @%systemroot%\system32\mycomput.dll,-400
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage,MUIVerb = @%systemroot%\system32\mycomput.dll,-400
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage\command,@ = %SystemRoot%\system32\CompMgmtLauncher.exe
----------------------------------------
No blocked files found on D:
No autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for 8ce65186-e62f-11df-861d-806e6f6e6963
No Desktop.ini files found on D:
----------------------------------------
No blocked files found on F:
No autorun.inf files found on F:
No mountpoint found for F:
No mountpoint found for 55237bc5-411e-11e0-9ae4-806e6f6e6963
No Desktop.ini files found on F:
----------------------------------------
========================================
Initial scan finished!
========================================
========================================
Removed I:
========================================
New device connected at 30.5.2011 21:14:14
Scanning for connected USB mass storage...
----------------------------------------
========================================
New drive connected, but USBNoRisk can't find it
========================================
New device connected at 30.5.2011 21:14:14
Scanning for connected USB mass storage...
----------------------------------------
========================================
New drive connected, but USBNoRisk can't find it
========================================
New device connected at 30.5.2011 21:14:18
Scanning for connected removable storage...
----------------------------------------
I: {8cdc1f57-3028-11e0-8448-00e04da51dad}
J: {8cdc1f5d-3028-11e0-8448-00e04da51dad}
Added J:
========================================
Scanning removable storage for files...
----------------------------------------
New device connected at 30.5.2011 21:14:19
Scanning for connected removable storage...
----------------------------------------
========================================
Scanning removable storage for files...
----------------------------------------
No blocked files found on J:
----------------------------------------
No autorun.inf files found on J:
Sanitized mountpoint for 8cdc1f5d-3028-11e0-8448-00e04da51dad
----------------------------------------
No Desktop.ini files found on J:
----------------------------------------
No mimics found on drive J:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive J:
========================================
No blocked files found on J:
----------------------------------------
No autorun.inf files found on J:
No mountpoint found for 8cdc1f5d-3028-11e0-8448-00e04da51dad
----------------------------------------
No Desktop.ini files found on J:
----------------------------------------
No mimics found on drive J:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive J:
========================================
========================================
Removed J:
========================================
New device connected at 30.5.2011 21:15:04
Scanning for connected USB mass storage...
----------------------------------------
I: {bda035d3-e83b-11df-82d3-00e04da51dad}
Added I:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on I:
----------------------------------------
No autorun.inf files found on I:
Sanitized mountpoint for bda035d3-e83b-11df-82d3-00e04da51dad
----------------------------------------
No Desktop.ini files found on I:
----------------------------------------
No mimics found on drive I:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive I:
========================================
========================================
Removed I:
========================================
New device connected at 30.5.2011 21:18:14
Scanning for connected USB mass storage...
----------------------------------------
I: {f3366286-fbdd-11df-91b6-00e04da51dad}
Added I:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on I:
----------------------------------------
No autorun.inf files found on I:
Sanitized mountpoint for f3366286-fbdd-11df-91b6-00e04da51dad
----------------------------------------
No Desktop.ini files found on I:
----------------------------------------
No mimics found on drive I:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive I:
========================================
========================================
Removed I:
========================================
USBNoRisk 2.7 (28 December 2010) by bobby
Started at 30.5.2011 21:12:06
Searching for connected USB Mass storage...
----------------------------------------
I: {bda035d3-e83b-11df-82d3-00e04da51dad}
========================================
Searching for other storage...
----------------------------------------
F: {55237bc5-411e-11e0-9ae4-806e6f6e6963}
C: {8ce65185-e62f-11df-861d-806e6f6e6963}
D: {8ce65186-e62f-11df-861d-806e6f6e6963}
========================================
Scanning removable storage...
----------------------------------------
No blocked files found on I:
No autorun.inf files found on I:
Sanitized mountpoint for bda035d3-e83b-11df-82d3-00e04da51dad
No Desktop.ini files found on I:
No mimics found on drive I:
No .lnk/.pif/.com/.scr files found on drive I:
----------------------------------------
Scanning fixed storage...
----------------------------------------
No blocked files found on C:
No autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 8ce65185-e62f-11df-861d-806e6f6e6963
----------------------------------------
Desktop.ini found at C:\ComboFix\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={20D04FE0-3AEA-1069-A2D8-08002B30309D}
IconResource=C:\Windows\system32\SHELL32.dll,4
----------------------------------------
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D},InfoTip = @%SystemRoot%\system32\shell32.dll,-22913
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D},LocalizedString = @%SystemRoot%\system32\shell32.dll,-9216
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon,@ = %SystemRoot%\System32\imageres.dll,-109
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32,@ = %SystemRoot%\system32\shell32.dll
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find,@ = @%SystemRoot%\system32\shell32.dll,-8503
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find\command,@ = %SystemRoot%\Explorer.exe
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage,@ = @%systemroot%\system32\mycomput.dll,-400
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage,MUIVerb = @%systemroot%\system32\mycomput.dll,-400
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage\command,@ = %SystemRoot%\system32\CompMgmtLauncher.exe
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D},InfoTip = @%SystemRoot%\system32\shell32.dll,-22913
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D},LocalizedString = @%SystemRoot%\system32\shell32.dll,-9216
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon,@ = %SystemRoot%\System32\imageres.dll,-109
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32,@ = %SystemRoot%\system32\shell32.dll
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find,@ = @%SystemRoot%\system32\shell32.dll,-8503
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find\command,@ = %SystemRoot%\Explorer.exe
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage,@ = @%systemroot%\system32\mycomput.dll,-400
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage,MUIVerb = @%systemroot%\system32\mycomput.dll,-400
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage\command,@ = %SystemRoot%\system32\CompMgmtLauncher.exe
----------------------------------------
No blocked files found on D:
No autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for 8ce65186-e62f-11df-861d-806e6f6e6963
No Desktop.ini files found on D:
----------------------------------------
No blocked files found on F:
No autorun.inf files found on F:
No mountpoint found for F:
No mountpoint found for 55237bc5-411e-11e0-9ae4-806e6f6e6963
No Desktop.ini files found on F:
----------------------------------------
========================================
Initial scan finished!
========================================
========================================
Removed I:
========================================
New device connected at 30.5.2011 21:14:14
Scanning for connected USB mass storage...
----------------------------------------
========================================
New drive connected, but USBNoRisk can't find it
========================================
New device connected at 30.5.2011 21:14:14
Scanning for connected USB mass storage...
----------------------------------------
========================================
New drive connected, but USBNoRisk can't find it
========================================
New device connected at 30.5.2011 21:14:18
Scanning for connected removable storage...
----------------------------------------
I: {8cdc1f57-3028-11e0-8448-00e04da51dad}
J: {8cdc1f5d-3028-11e0-8448-00e04da51dad}
Added J:
========================================
Scanning removable storage for files...
----------------------------------------
New device connected at 30.5.2011 21:14:19
Scanning for connected removable storage...
----------------------------------------
========================================
Scanning removable storage for files...
----------------------------------------
No blocked files found on J:
----------------------------------------
No autorun.inf files found on J:
Sanitized mountpoint for 8cdc1f5d-3028-11e0-8448-00e04da51dad
----------------------------------------
No Desktop.ini files found on J:
----------------------------------------
No mimics found on drive J:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive J:
========================================
No blocked files found on J:
----------------------------------------
No autorun.inf files found on J:
No mountpoint found for 8cdc1f5d-3028-11e0-8448-00e04da51dad
----------------------------------------
No Desktop.ini files found on J:
----------------------------------------
No mimics found on drive J:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive J:
========================================
========================================
Removed J:
========================================
New device connected at 30.5.2011 21:15:04
Scanning for connected USB mass storage...
----------------------------------------
I: {bda035d3-e83b-11df-82d3-00e04da51dad}
Added I:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on I:
----------------------------------------
No autorun.inf files found on I:
Sanitized mountpoint for bda035d3-e83b-11df-82d3-00e04da51dad
----------------------------------------
No Desktop.ini files found on I:
----------------------------------------
No mimics found on drive I:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive I:
========================================
========================================
Removed I:
========================================
New device connected at 30.5.2011 21:18:14
Scanning for connected USB mass storage...
----------------------------------------
I: {f3366286-fbdd-11df-91b6-00e04da51dad}
Added I:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on I:
----------------------------------------
No autorun.inf files found on I:
Sanitized mountpoint for f3366286-fbdd-11df-91b6-00e04da51dad
----------------------------------------
No Desktop.ini files found on I:
----------------------------------------
No mimics found on drive I:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive I:
========================================
========================================
Removed I:
========================================
USBNoRisk 2.7 (28 December 2010) by bobby
Started at 30.5.2011 21:12:06
Searching for connected USB Mass storage...
----------------------------------------
I: {bda035d3-e83b-11df-82d3-00e04da51dad}
========================================
Searching for other storage...
----------------------------------------
F: {55237bc5-411e-11e0-9ae4-806e6f6e6963}
C: {8ce65185-e62f-11df-861d-806e6f6e6963}
D: {8ce65186-e62f-11df-861d-806e6f6e6963}
========================================
Scanning removable storage...
----------------------------------------
No blocked files found on I:
No Autorun.inf files found on I:
Sanitized mountpoint for bda035d3-e83b-11df-82d3-00e04da51dad
No Desktop.ini files found on I:
No mimics found on drive I:
No .lnk/.pif/.com/.scr files found on drive I:
----------------------------------------
Scanning fixed storage...
----------------------------------------
No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 8ce65185-e62f-11df-861d-806e6f6e6963
----------------------------------------
Desktop.ini found at C:\ComboFix\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={20D04FE0-3AEA-1069-A2D8-08002B30309D}
IconResource=C:\Windows\system32\SHELL32.dll,4
----------------------------------------
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D},InfoTip = @%SystemRoot%\system32\shell32.dll,-22913
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D},LocalizedString = @%SystemRoot%\system32\shell32.dll,-9216
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon,@ = %SystemRoot%\System32\imageres.dll,-109
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32,@ = %SystemRoot%\system32\shell32.dll
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find,@ = @%SystemRoot%\system32\shell32.dll,-8503
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find\command,@ = %SystemRoot%\Explorer.exe
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage,@ = @%systemroot%\system32\mycomput.dll,-400
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage,MUIVerb = @%systemroot%\system32\mycomput.dll,-400
HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage\command,@ = %SystemRoot%\system32\CompMgmtLauncher.exe
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D},InfoTip = @%SystemRoot%\system32\shell32.dll,-22913
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D},LocalizedString = @%SystemRoot%\system32\shell32.dll,-9216
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon,@ = %SystemRoot%\System32\imageres.dll,-109
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32,@ = %SystemRoot%\system32\shell32.dll
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find,@ = @%SystemRoot%\system32\shell32.dll,-8503
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find\command,@ = %SystemRoot%\Explorer.exe
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage,@ = @%systemroot%\system32\mycomput.dll,-400
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage,MUIVerb = @%systemroot%\system32\mycomput.dll,-400
HKLM\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\Manage\command,@ = %SystemRoot%\system32\CompMgmtLauncher.exe
----------------------------------------
No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for 8ce65186-e62f-11df-861d-806e6f6e6963
No Desktop.ini files found on D:
----------------------------------------
No blocked files found on F:
No Autorun.inf files found on F:
No mountpoint found for F:
No mountpoint found for 55237bc5-411e-11e0-9ae4-806e6f6e6963
No Desktop.ini files found on F:
----------------------------------------
========================================
Initial scan finished!
========================================
========================================
Removed I:
========================================
New device connected at 30.5.2011 21:14:14
Scanning for connected USB mass storage...
----------------------------------------
========================================
New drive connected, but USBNoRisk can't find it
========================================
New device connected at 30.5.2011 21:14:14
Scanning for connected USB mass storage...
----------------------------------------
========================================
New drive connected, but USBNoRisk can't find it
========================================
New device connected at 30.5.2011 21:14:18
Scanning for connected removable storage...
----------------------------------------
I: {8cdc1f57-3028-11e0-8448-00e04da51dad}
J: {8cdc1f5d-3028-11e0-8448-00e04da51dad}
Added J:
========================================
Scanning removable storage for files...
----------------------------------------
New device connected at 30.5.2011 21:14:19
Scanning for connected removable storage...
----------------------------------------
========================================
Scanning removable storage for files...
----------------------------------------
No blocked files found on J:
----------------------------------------
No Autorun.inf files found on J:
Sanitized mountpoint for 8cdc1f5d-3028-11e0-8448-00e04da51dad
----------------------------------------
No Desktop.ini files found on J:
----------------------------------------
No mimics found on drive J:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive J:
========================================
No blocked files found on J:
----------------------------------------
No Autorun.inf files found on J:
No mountpoint found for 8cdc1f5d-3028-11e0-8448-00e04da51dad
----------------------------------------
No Desktop.ini files found on J:
----------------------------------------
No mimics found on drive J:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive J:
========================================
========================================
Removed J:
========================================
New device connected at 30.5.2011 21:15:04
Scanning for connected USB mass storage...
----------------------------------------
I: {bda035d3-e83b-11df-82d3-00e04da51dad}
Added I:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on I:
----------------------------------------
No Autorun.inf files found on I:
Sanitized mountpoint for bda035d3-e83b-11df-82d3-00e04da51dad
----------------------------------------
No Desktop.ini files found on I:
----------------------------------------
No mimics found on drive I:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive I:
========================================
========================================
Removed I:
========================================
New device connected at 30.5.2011 21:18:14
Scanning for connected USB mass storage...
----------------------------------------
I: {f3366286-fbdd-11df-91b6-00e04da51dad}
Added I:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on I:
----------------------------------------
No Autorun.inf files found on I:
Sanitized mountpoint for f3366286-fbdd-11df-91b6-00e04da51dad
----------------------------------------
No Desktop.ini files found on I:
----------------------------------------
No mimics found on drive I:
----------------------------------------
No .lnk/.pif/.com/.scr files found on drive I:
========================================
========================================
Removed I:
========================================
Dopuna: 30 Maj 2011 21:37
sto se tice combofix, prijavljuje mi neki virus, i da je rizicno
|