Prelged log fajla

2

Prelged log fajla

offline
  • Pridružio: 21 Feb 2009
  • Poruke: 97
  • Gde živiš: Istocno Sarajevo

Evo mislim da je sada gotovo:

USBNoRisk 1.5 by bobby

Started at 22.2.2009 9:52:48

Scanning for connected USB Mass storage...
----------------------------------------
A: {7fdb65a0-8ca9-11dc-a884-806d6172696f}
========================================

Scanning for other storage...
----------------------------------------
C: {7fdb659e-8ca9-11dc-a884-806d6172696f}
========================================

Scanning removable storage for autorun.inf and desktop.ini files...
----------------------------------------
Autorun.inf on A: - None
----------------------------------------

Sanitizing Shell Menu...
----------------------------------------
No key found for 7fdb65a0-8ca9-11dc-a884-806d6172696f
========================================

----------------------------------------

Desktop.ini on A: - None
----------------------------------------

----------------------------------------

========================================


Scanning fixed storage for autorun.inf files...
----------------------------------------
Autorun.inf on C: - None
----------------------------------------

Sanitizing Shell Menu...
----------------------------------------
No key found for C:
No key found for 7fdb659e-8ca9-11dc-a884-806d6172696f
========================================



New device connected at 22.2.2009 9:53:31

Scanning for connected USB mass storage...
----------------------------------------
F: {864049ae-f9ae-11dd-af4a-000ffe1a00f0}
Added F:
========================================

Scanning USB mass storage for files...
----------------------------------------
----------------------------------------
Autorun.inf on F: - None
----------------------------------------

Sanitizing Shell Menu...
----------------------------------------
No key found for 864049ae-f9ae-11dd-af4a-000ffe1a00f0
========================================

----------------------------------------

Desktop.ini on F: - None
----------------------------------------

========================================

Processing script
----------------------------------------
Drive letter for GUID: A:\
No script to process for A:\
----------------------------------------

Drive letter for GUID: F:\
864049ae-f9ae-11dd-af4a-000ffe1a00f0
SectionStart = 0
SectionEnd = 3
File lock detected:
USBNoRisk cannot find what locked the file
Delete: F:\ur0.com > Error!
f_delete: file "F:\ur0.com" deleted successfully
----------------------------------------
Deleting blocked files:
----------------------------------------
None
----------------------------------------

========================================

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Hajde sada ugasi USBNoRisk, pa ga pokreni onda ponovo.
Ako si USB stick vec otkacio, ubaci ga ponovo da bi ga USBNoRisk ponovo skenirao. Interesuje me da li se infekcija vraca.
Znaci, kada budes imao log postavi ga ponovo na forum da ga pregledam.

offline
  • Pridružio: 21 Feb 2009
  • Poruke: 97
  • Gde živiš: Istocno Sarajevo

Evo cini mi se da nema infekcije ovaj put:

USBNoRisk 1.5 by bobby

Started at 22.2.2009 10:19:51

Scanning for connected USB Mass storage...
----------------------------------------
A: {7fdb65a0-8ca9-11dc-a884-806d6172696f}
========================================

Scanning for other storage...
----------------------------------------
C: {7fdb659e-8ca9-11dc-a884-806d6172696f}
========================================

Scanning removable storage for autorun.inf and desktop.ini files...
----------------------------------------
Autorun.inf on A: - None
----------------------------------------

Sanitizing Shell Menu...
----------------------------------------
No key found for 7fdb65a0-8ca9-11dc-a884-806d6172696f
========================================

----------------------------------------

Desktop.ini on A: - None
----------------------------------------

----------------------------------------

========================================


Scanning fixed storage for autorun.inf files...
----------------------------------------
Autorun.inf on C: - None
----------------------------------------

Sanitizing Shell Menu...
----------------------------------------
No key found for C:
No key found for 7fdb659e-8ca9-11dc-a884-806d6172696f
========================================



New device connected at 22.2.2009 10:20:01

Scanning for connected USB mass storage...
----------------------------------------
F: {864049ae-f9ae-11dd-af4a-000ffe1a00f0}
Added F:
========================================

Scanning USB mass storage for files...
----------------------------------------
----------------------------------------
Autorun.inf on F: - None
----------------------------------------

Sanitizing Shell Menu...
----------------------------------------
No key found for 864049ae-f9ae-11dd-af4a-000ffe1a00f0
========================================

----------------------------------------

Desktop.ini on F: - None
----------------------------------------

========================================

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Ovaj zadnji log je OK sto se tice USB sticka.
Ostatak ce da odradi kolega helen1 kada dodje na forum.

Pozz od mene

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Pozz,

Iskljuci AVG.

Otvoriti Notepad i iskopirati sledeci tekst:

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12231:TCP"=-


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 21 Feb 2009
  • Poruke: 97
  • Gde živiš: Istocno Sarajevo

Evo ga Smile

ComboFix 09-02-19.01 - Admin 2009-02-22 11:44:52.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.759.291 [GMT 1:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-01-22 to 2009-02-22 )))))))))))))))))))))))))))))))
.

2009-02-22 11:43 . 2009-02-22 11:43 389,120 --a------ c:\windows\system32\CF30637.exe
2009-02-21 12:31 . 2009-02-22 10:26 <DIR> d-------- C:\USBNoRisk
2009-02-18 14:32 . 2009-02-18 14:32 <DIR> d-------- c:\program files\Time Calculator v1.1
2009-02-15 17:37 . 2009-02-15 17:38 <DIR> d-------- c:\program files\SystemRequirementsLab
2009-02-15 17:37 . 2009-02-15 17:38 <DIR> d-------- c:\documents and settings\Admin\Application Data\SystemRequirementsLab
2009-02-13 13:11 . 2009-02-13 13:21 <DIR> d-------- c:\documents and settings\Admin\Application Data\SSH
2009-02-13 12:24 . 2009-02-13 12:24 <DIR> d-------- c:\program files\SSH Communications Security
2009-02-13 10:13 . 2009-02-18 18:00 <DIR> d-------- c:\program files\Norton Security Scan
2009-02-13 10:13 . 2009-02-15 18:15 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2009-02-12 18:27 . 2009-02-12 18:27 <DIR> d-------- c:\windows\SQLTools9_KB960089_ENU
2009-02-12 18:24 . 2009-02-12 18:24 <DIR> d-------- c:\windows\SQL9_KB960089_ENU
2009-02-12 18:09 . 2009-02-12 18:11 <DIR> d-------- c:\windows\system32\Adobe
2009-02-12 18:09 . 2009-01-16 18:34 499,712 --a------ c:\windows\system32\msvcp71.dll
2009-02-11 15:53 . 2009-02-11 15:54 <DIR> d-------- c:\program files\SpeedSim
2009-02-11 15:53 . 2009-02-11 15:54 <DIR> d-------- c:\documents and settings\Admin\Application Data\SpeedSim
2009-02-10 16:33 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-02-10 16:33 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-02-10 16:33 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-02-09 09:59 . 2009-02-22 09:24 <DIR> d-------- c:\documents and settings\Admin\Tracing
2009-02-09 09:56 . 2009-02-09 09:56 <DIR> d-------- c:\program files\Microsoft
2009-02-09 09:55 . 2009-02-09 09:55 <DIR> d-------- c:\program files\Windows Live SkyDrive
2009-02-09 09:43 . 2009-02-09 09:43 <DIR> d-------- c:\program files\Windows Live
2009-02-09 09:39 . 2009-02-09 09:39 <DIR> d-------- c:\program files\Common Files\Windows Live
2009-02-06 18:52 . 2009-02-06 18:52 49,504 --a------ c:\windows\system32\sirenacm.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-21 17:18 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-20 13:24 --------- d-----w c:\documents and settings\Admin\Application Data\Free Download Manager
2009-02-19 17:45 --------- d-----w c:\documents and settings\Admin\Application Data\uTorrent
2009-02-17 08:28 --------- d-----w c:\program files\Google
2009-02-16 19:54 --------- d-----w c:\documents and settings\Admin\Application Data\Skype
2009-02-16 16:45 --------- d-----w c:\documents and settings\Admin\Application Data\skypePM
2009-02-15 21:06 --------- d-----w c:\program files\Microsoft Works
2009-02-15 09:08 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-13 11:24 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-12 17:28 --------- d-----w c:\program files\Microsoft SQL Server
2009-02-10 15:29 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-09 08:24 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-02-09 08:23 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-09 08:23 107,272 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-02-09 08:23 10,520 ----a-w c:\windows\system32\avgrsstx.dll
2009-01-16 20:35 3,594,752 ------w c:\windows\system32\dllcache\mshtml.dll
2008-12-27 10:47 --------- d-----w c:\program files\Sparx Systems
2008-12-27 10:46 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-24 10:24 --------- d-----w c:\program files\AVG
2008-12-24 09:49 --------- d-----w c:\program files\AskBarDis
2008-12-24 09:49 --------- d-----w c:\program files\Advanced Registry Optimizer
2008-12-24 09:49 --------- d-----w c:\documents and settings\Admin\Application Data\Sammsoft
2008-12-24 08:51 --------- d-----w c:\documents and settings\Admin\Application Data\FileZilla
2008-12-23 07:55 --------- d-----w c:\program files\Macromedia
2008-12-19 09:10 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ------w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 10:57 333,952 ------w c:\windows\system32\dllcache\srv.sys
1999-04-23 22:22 12 -csha-w c:\windows\system\WININETICMP32.drv
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-08-06 15:20 279944 --a------ c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2006-03-01 90112]
"AROReminder"="c:\program files\Advanced Registry Optimizer\aro.exe" [2008-08-22 2084480]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"srmclean"="c:\cpqs\Scom\srmclean.exe" [2001-07-24 36864]
"SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-06 524800]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-09 1601304]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-09 09:23 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\xampp\\apache\\bin\\apache.exe"=
"c:\\xampp\\mysql\\bin\\mysqld.exe"=
"c:\\Program Files\\Zend\\ZendStudio-5.5.0\\jre\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-24 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-12-24 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-12-24 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-24 298264]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-06-29 42512]
S3 VSPerfDrv90;Performance Tools Driver 9.0;c:\program files\Microsoft Visual Studio 9.0\Team Tools\Performance Tools\VSPerfDrv90.sys [2007-09-04 55664]
.
Contents of the 'Scheduled Tasks' folder

2009-02-18 c:\windows\Tasks\Norton Security Scan for Admin.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.msn.com
mSearch Bar = hxxp://go.compaq.com/1Q00CDT/0409/bl8.asp
uInternet Settings,ProxyOverride = 127.0.0.1
IE: &NeoTrace It! - c:\progra~1\VISUAL~1\NTXcontext.htm
IE: + Offline &Explorer: Download the link - file://e:\offline explorer\Portable Offline Browser\Add_UrlO.htm
IE: + Offline E&xplorer: Download the current page - file://e:\offline explorer\Portable Offline Browser\Add_AllO.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Preuzmi odabrano Free Download Manager-om - file://c:\program files\Free Download Manager\dlselected.htm
IE: Preuzmi sa Free Download Managerom - file://c:\program files\Free Download Manager\dllink.htm
IE: Preuzmi sve sa Free Download Manager-om - file://c:\program files\Free Download Manager\dlall.htm
IE: Zend Studio - Debug current page - c:\program files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugCurrent.html
IE: Zend Studio - Debug next page - c:\program files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugNext.html
TCP: {0C7693F0-CD5E-498D-AEA1-89EF43612BFC} = 81.93.89.195,81.93.89.194
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\p1b45o4o.default\
FF - prefs.js: browser.search.selectedEngine - YouTube Video Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1399.3742\npCIDetect13.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-02-22 11:51:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
Completion time: 2009-02-22 11:55:41
ComboFix-quarantined-files.txt 2009-02-22 10:54:24
ComboFix2.txt 2009-02-21 11:19:53
ComboFix3.txt 2009-02-21 10:21:55

Pre-Run: 3.304.476.672 bytes free
Post-Run: 3,290,509,312 bytes free

168 --- E O F --- 2009-02-15 21:09:24

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Kolega kako sad radi?

offline
  • Pridružio: 21 Feb 2009
  • Poruke: 97
  • Gde živiš: Istocno Sarajevo

Malo sam se zanio citajuci o autorun.inf pa nisam vidio da si odgovorio. Sad je sve uredu, cini mi se da radi dobro. Hvala na vremenu kolega Smile

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Jos ovo:

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore

Ko je trenutno na forumu
 

Ukupno su 1166 korisnika na forumu :: 40 registrovanih, 7 sakrivenih i 1119 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: airsuba, amaterSRB, babaroga, cavatina, draganl, flash12, HrcAk47, Karla, kikisp, krkalon, Kubovac, ladro, laganini123, Lieutenant, milenko crazy north, Milos ZA, milutin134, MiroslavD, mnn2, nemkea71, nenad81, pein, Pohovani_00, procesor, Romibrat, S1Mk3, saputnik plavetnila, Shinobi, Simon simonović, slonic_tonic, suton, tomigun, Trpe Grozni, tubular, vaso1, vladetije, vladulns, Webb, YU-UKI, šumar bk2