Sumnjam na zaraženost fleš memorije?

2

Sumnjam na zaraženost fleš memorije?

offline
  • Pridružio: 21 Feb 2011
  • Poruke: 385

Fix result of Farbar Recovery Scan Tool (x64) Version: 26-04-2017
Ran by Miki (26-04-2017 22:26:35) Run:2
Running from C:\Users\Miki\Desktop
Loaded Profiles: Miki (Available Profiles: Miki)
Boot Mode: Normal
==============================================

fixlist content:
*****************
HKU\S-1-5-21-1256282032-594660536-930673109-1000\...\Run: [Client Server Runtime Process] => C:\Users\Miki\AppData\Roaming\csrss.exe
HKU\S-1-5-21-1256282032-594660536-930673109-1000\...\CurrentVersion\Windows: [Load] C:\ProgramData\msqnnnkcj.exe <===== ATTENTION
C:\Users\Miki\AppData\Roaming\csrss.exe
C:\ProgramData\msqnnnkcj.exe
C:\Users\Miki\AppData\Local\Temp\KB00190040.exe
EmptyTemp:
*****************

HKU\S-1-5-21-1256282032-594660536-930673109-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Client Server Runtime Process => value removed successfully
HKU\S-1-5-21-1256282032-594660536-930673109-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load => value removed successfully
"C:\Users\Miki\AppData\Roaming\csrss.exe" => not found.
Could not move "C:\ProgramData\msqnnnkcj.exe" => Scheduled to move on reboot.
C:\Users\Miki\AppData\Local\Temp\KB00190040.exe => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 3766133 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 5714 B
Edge => 0 B
Chrome => 287063675 B
Firefox => 16805634 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 83519 B
systemprofile32 => 66356 B
LocalService => 66228 B
NetworkService => 1248 B
Miki => 43160125 B

RecycleBin => 0 B
EmptyTemp: => 342.8 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 26-04-2017 22:28:00)

C:\ProgramData\msqnnnkcj.exe => Is moved successfully

==== End of Fixlog 22:28:00 ====

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Preuzmi MCShield sa sljedeće adrese:

http://www.mcshield.net/download/MCShield-Setup.exe

Instaliraj MCShield i sačekaj da se završi uvodno skeniranje.

Kad se završi uvodno skeniranje, ubacuj sve USB memorijske uređaje redom u USB port i svaki zadrži u portu dok MCShield ne izbaci poruku da je skeniranje završeno. Ukoliko imaš više USB uređaja, zabilježi negdje kojim su redom ubacivani.

Objašnjenje: U USB memorijske uređaje spadaju svi oni uređaji koji po priključivanju na kompjuter dobijaju svoju oznaku particije. Tu spadaju USB flash drajvovi, eksterni hard-diskovi, memorijske kartice, MP3 i MP4 plejeri, neki mobilni telefoni, neki GPS (navigacioni) uređaji itd.

Idi na Start -> All Programs -> MCShield -> Logs -> AllScans

Otvoriće ti se izvještaj u Notepad-u čiji sadržaj treba da postaviš u poruku

offline
  • Pridružio: 21 Feb 2011
  • Poruke: 385

Trenutno mi je pri ruci bila fleška i mobilni telefon.

>>> MCShield AllScans.txt <<<

-----------------------------




MCShield ::Anti-Malware Tool:: http://www.mcshield.net/

>>> v 3.0.5.28 / DB: 2016.2.21.1 / Windows 7 <<<


4/26/2017 10:34:36 PM > Drive C: - scan started (New Volume ~56 GB, NTFS HDD )...



=> The drive is clean.


4/26/2017 10:34:36 PM > Drive D: - scan started (Local Disk ~409 GB, NTFS HDD )...



=> The drive is clean.





MCShield ::Anti-Malware Tool:: http://www.mcshield.net/

>>> v 3.0.5.28 / DB: 2016.2.21.1 / Windows 7 <<<


4/26/2017 10:37:46 PM > Drive G: - scan started (KINGSTON ~14762 MB, NTFS flash drive )...


>>> G:\KINGSTON (16GB).lnk - Suspicious > Renamed. (MD5: 0ca85398db1cb27b21f28fe09f02540b)

> Resetting attributes: G:\  < Successful.


=> Suspicious files : 1/1 renamed.
=> Hidden folders : 1/1 unhidden.

____________________________________________

::::: Scan duration: 1sec ::::::::::::::::::
____________________________________________

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Instaliraj neki AV program i reci mi kakvo je stanje sa fleš diskom (nakon što instaliraš AV program).

offline
  • Pridružio: 21 Feb 2011
  • Poruke: 385

Izgleda da sam rešio problem. Išao sam desni klik na fleš drajv pa Scan with Zemana AntiMalware. Posle skeniranja je našao nekog trojanca, obrisao sam ga i evo sad kad ubadam fleš nema više one glupe prečice da se pojavljuje.
Hvala druže na trudu Zagrljaj Ziveli

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Napisano: 26 Apr 2017 23:26

Instaliraj antivirusni program. Wink

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.


Dopuna: 26 Apr 2017 23:27

Umalo da zaboravim da ti napomenem da si imao keyloggera pa bi bilo poželjno da promjeniš lozinke koje si koristio proteklih dana.

offline
  • Pridružio: 21 Feb 2011
  • Poruke: 385

Kakav keylogger sam imao?

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

REFOG Keylogger.

https://www.refog.com/employee-monitoring/tutorial.html

Ko je trenutno na forumu
 

Ukupno su 1085 korisnika na forumu :: 49 registrovanih, 6 sakrivenih i 1030 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Apok, bankulen, bladesu, Bokiboks, cinoeye, darkangel, debeli, Dimitrije Paunovic, Dimitrise93, dragoljub11987, drimer, esx66, FileFinder, Fog of War, FOX, Georgius, goxin, ikan, ivan1973, jackreacher011011, Karla, Kibice, kokodakalo, kunktator, kybonacci, Marko Marković, mercedesamg, milenko crazy north, nebidrag, nemkea71, Nobunaga, NoOneEver Dreams, novator, ObelixSRB, offman, ozzy, Pikac-47, procesor, rajkoplje, rasok, RJ, Rogan33, slonic_tonic, Srle993, Stoilkovic, Trpe Grozni, vladulns, 125