Poslao: 03 Jun 2010 22:56
|
offline
- Pridružio: 21 Okt 2007
- Poruke: 127
- Gde živiš: somewhere...
|
Apsoštrumfno nepoznat.
USBNoRisk 2.5 (26 July 2009) by bobby
Started at 3.6.2010 22:56:06
Searching for connected USB Mass storage...
----------------------------------------
========================================
Searching for other storage...
----------------------------------------
C: {46ea5fb1-922c-11dd-ab27-806e6f6e6963}
E: {46ea5fb2-922c-11dd-ab27-806e6f6e6963}
========================================
Scanning fixed storage...
----------------------------------------
No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 46ea5fb1-922c-11dd-ab27-806e6f6e6963
No Desktop.ini files found on C:
----------------------------------------
No blocked files found on E:
No Autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for 46ea5fb2-922c-11dd-ab27-806e6f6e6963
No Desktop.ini files found on E:
----------------------------------------
========================================
Initial scan finished!
========================================
New device connected at 3.6.2010 22:56:11
Scanning for connected USB mass storage...
----------------------------------------
D: {9ca85e83-9bc1-11dd-ab3c-001f3c96cb06}
Added D:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on D:
----------------------------------------
No Autorun.inf files found on D:
Sanitized mountpoint for 9ca85e83-9bc1-11dd-ab3c-001f3c96cb06
----------------------------------------
----------------------------------------
Desktop.ini found at D:\ljutis\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\shell32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\shell32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\imageres.dll,-55
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\imageres.dll,-55
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\imageres.dll,-54
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = %SystemRoot%\system32\shell32.dll
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\Open CCleaner...\command,@ = C:\Program Files\CCleaner\ccleaner.exe
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\Run CCleaner\command,@ = C:\Program Files\CCleaner\ccleaner.exe /AUTO
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\shell32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\shell32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\imageres.dll,-55
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\imageres.dll,-55
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\imageres.dll,-54
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = %SystemRoot%\system32\shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\Open CCleaner...\command,@ = C:\Program Files\CCleaner\ccleaner.exe
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\Run CCleaner\command,@ = C:\Program Files\CCleaner\ccleaner.exe /AUTO
----------------------------------------
No mimics found on drive D:
========================================
Processing script
----------------------------------------
9ca85e83-9bc1-11dd-ab3c-001f3c96cb06
Drive letter for GUID: D:
SectionStart = 0
SectionEnd = 3
----------------------------------------
Unhide superhidden for D:\
----------------------------------------
dra-- D:\ljutis > unhidden
--a-- D:\ljutis\Desktop.ini > unhidden
-ra-- D:\ljutis\drugom.exe > unhidden
--a-- D:\autorun.exe > unhidden
f_delete:
driver loading error driver loading error driver loading error delete file error: D:\autorun.exe, The handle is invalid.
f_delete:
driver loading error driver loading error driver loading error delete file error: D:\app1.EXE, The handle is invalid.
----------------------------------------
|
|
|
|
Poslao: 03 Jun 2010 23:56
|
offline
- Bogdan-Tc
- Anti Malware Fighter
Rank 1
- Pridružio: 04 Jan 2009
- Poruke: 2168
|
Izvadi USB uređaj i zatvori USBNoRisk.
Ponovo pokreni USBNorisk, ali opcijom desni klik pa Run As Administrator, zatim ponovo priključi taj USB i odradi po uputstvu iz moje prethodne poruke.
|
|
|
|
Poslao: 03 Jun 2010 23:59
|
offline
- Pridružio: 21 Okt 2007
- Poruke: 127
- Gde živiš: somewhere...
|
Evo opet, sad je obrisao:
USBNoRisk 2.5 (26 July 2009) by bobby
Started at 3.6.2010 23:59:34
Searching for connected USB Mass storage...
----------------------------------------
========================================
Searching for other storage...
----------------------------------------
C: {46ea5fb1-922c-11dd-ab27-806e6f6e6963}
E: {46ea5fb2-922c-11dd-ab27-806e6f6e6963}
========================================
Scanning fixed storage...
----------------------------------------
No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 46ea5fb1-922c-11dd-ab27-806e6f6e6963
No Desktop.ini files found on C:
----------------------------------------
No blocked files found on E:
No Autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for 46ea5fb2-922c-11dd-ab27-806e6f6e6963
No Desktop.ini files found on E:
----------------------------------------
========================================
Initial scan finished!
========================================
New device connected at 3.6.2010 23:59:42
Scanning for connected USB mass storage...
----------------------------------------
D: {9ca85e83-9bc1-11dd-ab3c-001f3c96cb06}
Added D:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on D:
----------------------------------------
No Autorun.inf files found on D:
Sanitized mountpoint for 9ca85e83-9bc1-11dd-ab3c-001f3c96cb06
----------------------------------------
----------------------------------------
Desktop.ini found at D:\ljutis\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\shell32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\shell32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\imageres.dll,-55
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\imageres.dll,-55
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\imageres.dll,-54
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = %SystemRoot%\system32\shell32.dll
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\Open CCleaner...\command,@ = C:\Program Files\CCleaner\ccleaner.exe
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\Run CCleaner\command,@ = C:\Program Files\CCleaner\ccleaner.exe /AUTO
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\shell32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\shell32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\imageres.dll,-55
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\imageres.dll,-55
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\imageres.dll,-54
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = %SystemRoot%\system32\shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\Open CCleaner...\command,@ = C:\Program Files\CCleaner\ccleaner.exe
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\Run CCleaner\command,@ = C:\Program Files\CCleaner\ccleaner.exe /AUTO
----------------------------------------
No mimics found on drive D:
========================================
Processing script
----------------------------------------
9ca85e83-9bc1-11dd-ab3c-001f3c96cb06
Drive letter for GUID: D:
SectionStart = 0
SectionEnd = 3
----------------------------------------
Unhide superhidden for D:\
----------------------------------------
f_delete:
file "D:\autorun.exe" deleted successfully
f_delete:
file "D:\app1.EXE" deleted successfully
----------------------------------------
|
|
|
|
Poslao: 04 Jun 2010 00:13
|
offline
- Bogdan-Tc
- Anti Malware Fighter
Rank 1
- Pridružio: 04 Jan 2009
- Poruke: 2168
|
Sad već bolje izgleda...
Pronađi na USB-u folder pod nazivom ljutis i obriši ga.
Takođe ako bi hteo još nešto da pogledamo na onom drugom USB uređaju ako si voljan?
- Pokrenuti USBNoRisk i sačekati da izvrši inicijalno skeniranje.
- Po završetku inicijalnog skeniranja priključiti USB memorijski uređaj (drugi).
- Kliknuti na karticu Script;
U beli okvir prozora iskopirati sledeći tekst:
{95f32563-0ce7-11de-93a2-001e335bb81f}
folder_list: %DRIVE%
- Izvršiti komandu klikom na taster Run Script;
Po izvršenju komande USBNoRisk će se automatski vratiti na karticu Monitor;
- Uraditi desni klik unutar belog okvira prozora i odabrati opciju Save Log;
Otvoriće se prozor Notepad_a sa tekstom koji je potrebno iskopirati ovde u poruci.
|
|
|
|
Poslao: 04 Jun 2010 00:19
|
offline
- Pridružio: 21 Okt 2007
- Poruke: 127
- Gde živiš: somewhere...
|
ObrisaT. Drugi USB uređaj je mobilni.
USBNoRisk 2.5 (26 July 2009) by bobby
Started at 4.6.2010 0:19:13
Searching for connected USB Mass storage...
----------------------------------------
========================================
Searching for other storage...
----------------------------------------
C: {46ea5fb1-922c-11dd-ab27-806e6f6e6963}
E: {46ea5fb2-922c-11dd-ab27-806e6f6e6963}
========================================
Scanning fixed storage...
----------------------------------------
No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 46ea5fb1-922c-11dd-ab27-806e6f6e6963
No Desktop.ini files found on C:
----------------------------------------
No blocked files found on E:
No Autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for 46ea5fb2-922c-11dd-ab27-806e6f6e6963
No Desktop.ini files found on E:
----------------------------------------
========================================
Initial scan finished!
========================================
New device connected at 4.6.2010 0:19:23
Scanning for connected USB mass storage...
----------------------------------------
D: {95f32563-0ce7-11de-93a2-001e335bb81f}
Added D:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on D:
----------------------------------------
No Autorun.inf files found on D:
Sanitized mountpoint for 95f32563-0ce7-11de-93a2-001e335bb81f
----------------------------------------
No Desktop.ini files found on D:
----------------------------------------
No mimics found on drive D:
========================================
Processing script
----------------------------------------
95f32563-0ce7-11de-93a2-001e335bb81f
Drive letter for GUID: D:
SectionStart = 0
SectionEnd = 1
----------------------------------------
Folder list for D:\:
----------------------------------------
--a-- 8515782 D:\05-GRE~1.MP3 D:\05 - Greensleeves.mp3
d---- 0 D:\mobile D:\mobile
----------------------------------------
|
|
|
|
Poslao: 04 Jun 2010 00:27
|
offline
- Bogdan-Tc
- Anti Malware Fighter
Rank 1
- Pridružio: 04 Jan 2009
- Poruke: 2168
|
Ovo je sad ok što se tiče malware-a, a što se tiče navedenih problema možeš se raspitati u odgovarajućem delu MyCity foruma.
Pozdrav...
|
|
|
|
|