Validnost logova van safe moda

2

Validnost logova van safe moda

offline
  • Velin 
  • Novi MyCity građanin
  • Pridružio: 21 Avg 2009
  • Poruke: 11

11/18/2011 2:55:07 PM > Scanning drive G: ( ~, HDD )...


>>> G:\nrhsg.pif - Malware > Deleted. (11.11.18. 14.55 nrhsg.pif.761105; MD5: 40024f2c51f4abd602a08afed2212ec1)

> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013
> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (MD5: 7457a5df1ff47c957acf1fa000d7d9ad)
> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svchost.exe (MD5: 733a906eb2ead42faef89ba4c8dc6d85)
> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\windowsupdate.com (MD5: 45c941fecceb99d704a903bf3f77760b)

>>> G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013 - Malware.Folder > Deleted. (11.11.18. 14.55 S-1-5-21-1482476501-1644491937-682003330-1013.946754)

> G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213
> G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\Desktop.ini (MD5: e783bdd20a976eaeaae1ff4624487420)
> G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe (MD5: f4e54486c56337fcf4ebb3667c51d98a)
> G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\USB-Helper.exe (MD5: b8cc670451849ee57ac8519bcdf0a32c)

>>> G:\recycler\s-1-6-21-2434476501-1644491937-600003330-1213 - Malware.Folder > Deleted. (11.11.18. 14.55 s-1-6-21-2434476501-1644491937-600003330-1213.94137)

>>> G:\recycler.exe - Suspicious > Renamed. (MD5: 625a36d37fe852c276ca3d95d05078ae)


=> Malicious files : 1/1 deleted.
=> Malicious folders : 2/2 deleted.
=> Suspicious files : 1/1 renamed.

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Da uradimo jos jednu proveru za USB flash

- Preuzmi USBNoRisk na Desktop i pokreni ga duplim klikom na ikonicu programa.
- Sacekaj koji sekund dok program izvrsi inicijalno skeniranje.
- Ubacuj sve USB memorijske uredjaje redom u USB slot i svaki zadrzi u slotu po 10 sekundi.
- Ukoliko imas vise uredjaja za proveru, onda na parcetu papira zapisi kojim redom su ubacivani jer ce nam kasnije trebati taj podatak
- Kada zavrsis sa svim uredjajima, klikni desno dugme misa na sred prozora programa i odaberi opciju Save scrambled log. To ce automatski otvoriti log u Notepadu. Iskopiraj nam taj log iz Notepada na forum.

Objasnjenje: U USB memorijske uredjaje spadaju svi oni uredjaji koji po prikljucivanju na kompjuter dobijaju svoju oznaku particije. Tu spadaju USB flash drajvovi, eksterni hard-diskovi, memorijske kartice, MP3 i MP4 plejeri, neki mobilni telefoni, neki GPS (navigacioni) uredjaji itd.

---------------------------------

Ukoliko imas vise uredjaja, zapisi redosled kojim ih prikljucujes, da znas ukoliko budem dao skriptu na koji se odnosi.

offline
  • Velin 
  • Novi MyCity građanin
  • Pridružio: 21 Avg 2009
  • Poruke: 11

USBNoRisk 2.7 (28 December 2010) by bobby

Started at 11/19/2011 11:47:49 AM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
D: {92917b24-10b8-11e1-96b7-806d6172696f}
C: {92917b26-10b8-11e1-96b7-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 92917b26-10b8-11e1-96b7-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for 92917b24-10b8-11e1-96b7-806d6172696f
----------------------------------------
Desktop.ini found at D:\RECYCLED\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 11/19/2011 11:48:03 AM

Scanning for connected USB mass storage...
----------------------------------------
G: {66640363-11ec-11e1-9320-0007951fccfb}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 66640363-11ec-11e1-9320-0007951fccfb
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

Mimics found on drive G:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive G:
========================================

========================================
Removed G:
========================================


New device connected at 11/19/2011 11:50:11 AM

Scanning for connected USB mass storage...
----------------------------------------
G: {40721870-129c-11e1-9323-0007951fccfb}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 40721870-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive G:
========================================



New device connected at 11/19/2011 11:50:13 AM

Scanning for connected USB mass storage...
----------------------------------------
H: {40721871-129c-11e1-9323-0007951fccfb}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No autorun.inf files found on H:
No mountpoint found for 40721871-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive H:
========================================

========================================
Removed G:
========================================


New device connected at 11/19/2011 11:50:28 AM

Scanning for connected USB mass storage...
----------------------------------------
G: {40721870-129c-11e1-9323-0007951fccfb}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 40721870-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive G:
========================================

========================================
Removed H:
========================================


New device connected at 11/19/2011 11:50:31 AM

Scanning for connected USB mass storage...
----------------------------------------
H: {40721871-129c-11e1-9323-0007951fccfb}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No autorun.inf files found on H:
No mountpoint found for 40721871-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive H:
========================================

========================================
Removed G:
========================================


New device connected at 11/19/2011 11:50:33 AM

Scanning for connected USB mass storage...
----------------------------------------
G: {40721870-129c-11e1-9323-0007951fccfb}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 40721870-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive G:
========================================

========================================
Removed H:
========================================


New device connected at 11/19/2011 11:50:35 AM

Scanning for connected USB mass storage...
----------------------------------------
H: {40721871-129c-11e1-9323-0007951fccfb}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No autorun.inf files found on H:
No mountpoint found for 40721871-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive H:
========================================

========================================
Removed H:
========================================


New device connected at 11/19/2011 11:51:01 AM

Scanning for connected USB mass storage...
----------------------------------------
G: {40721872-129c-11e1-9323-0007951fccfb}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No autorun.inf files found on G:
No mountpoint found for 40721872-129c-11e1-9323-0007951fccfb
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive G:
========================================

========================================

========================================


New device connected at 11/19/2011 11:51:34 AM

Scanning for connected USB mass storage...
----------------------------------------
Removed G:
========================================
New drive connected, but USBNoRisk can't find it
========================================

========================================

========================================

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Pokreni USBNoRisk i sacekaj koji sekund dok program izvrsi inicijalno skeniranje.
Sada ubodi problematicni USB stick br. 1 u komp, prebaci se na karticu Script i tamo kopiraj sledeci tekst:

{66640363-11ec-11e1-9320-0007951fccfb}
delete_mimics:
no_sh:
folder_list: %DRIVE%



Klikni na Run Script i sacekaj da USBNoRisk obavi svoje.
Na kartici monitor klikni desno dugme misa na sred prozora programa i odaberi opciju Save log.
Iskopiraj mi taj log iz Notepada na forum.

offline
  • Velin 
  • Novi MyCity građanin
  • Pridružio: 21 Avg 2009
  • Poruke: 11

Automatski se pokrenuo, odradio proces i izbacio sledeci izvestaj:
11/19/2011 3:49:47 PM > Scanning drive G: (no label ~4 GB, FAT32 flash drive )...


> G:\RECYCLER

>>> G:\recycler - Malware.Folder > Deleted. (11.11.19. 15.50 recycler.640454)


=> Malicious folders : 1/1 deleted.





A ovaj log koji ste trazili:

USBNoRisk 2.7 (28 December 2010) by bobby

Started at 11/19/2011 3:49:25 PM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
D: {92917b24-10b8-11e1-96b7-806d6172696f}
C: {92917b26-10b8-11e1-96b7-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 92917b26-10b8-11e1-96b7-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for 92917b24-10b8-11e1-96b7-806d6172696f
----------------------------------------
Desktop.ini found at D:\RECYCLED\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 11/19/2011 3:49:40 PM

Scanning for connected USB mass storage...
----------------------------------------
G: {66640363-11ec-11e1-9320-0007951fccfb}
Added G:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No Autorun.inf files found on G:
No mountpoint found for 66640363-11ec-11e1-9320-0007951fccfb
----------------------------------------

No Desktop.ini files found on G:
----------------------------------------

No mimics found on drive G:
----------------------------------------

No .lnk/.pif/.com/.scr files found on drive G:
========================================


Processing script
----------------------------------------
66640363-11ec-11e1-9320-0007951fccfb
Drive letter for GUID: G:
SectionStart = 0
SectionEnd = 3
----------------------------------------
Deleting mimics:
----------------------------------------
f_delete: C:\Win\lsass.exe > File does not exist!
----------------------------------------
Unhide superhidden for G:\
----------------------------------------
dra-- G:\za stampu > unhidden
dra-- G:\RECYCLER > unhidden
d-a-- G:\FOUND.000 > unhidden
dra-- G:\PPTUSB > unhidden
dra-- G:\svega > unhidden
dra-- G:\Password Protect USB > unhidden
--a-- G:\Password Protect USB\+ > unhidden
--a-- G:\Password Protect USB\ncfpsys.exe > unhidden
dra-- G:\seminarski biologija-cula > unhidden
dra-- G:\Prekrsajno pravo > unhidden
dra-- G:\Engleski jezik 4 > unhidden
dra-- G:\Interna kontrola i revizija > unhidden
dra-- G:\Kriminalistika > unhidden
----------------------------------------
Folder list for G:\:
----------------------------------------

dra--   0   G:\ZASTAM~1   G:\za stampu
dra--   0   G:\RECYCLER   G:\RECYCLER
d-a--   0   G:\FOUND.000   G:\FOUND.000
dra--   0   G:\PPTUSB   G:\PPTUSB
dra--   0   G:\svega   G:\svega
dra--   0   G:\PASSWO~1   G:\Password Protect USB
dra--   0   G:\SEMINA~1   G:\seminarski biologija-cula
--a--   546   G:\op.txt   G:\op.txt
--a--   43520   G:\UPUTST~1.DOC   G:\Uputstvo za izradu seminarskog rada (pravni predmeti).doc
dra--   0   G:\PREKRS~1   G:\Prekrsajno pravo
dra--   0   G:\ENGLES~1   G:\Engleski jezik 4
dra--   0   G:\INTERN~1   G:\Interna kontrola i revizija
dra--   0   G:\KRIMIN~1   G:\Kriminalistika

----------------------------------------


Processing script
----------------------------------------
66640363-11ec-11e1-9320-0007951fccfb
Drive letter for GUID: G:
SectionStart = 0
SectionEnd = 3
----------------------------------------
Deleting mimics:
----------------------------------------
f_delete: C:\Win\lsass.exe > File does not exist!
----------------------------------------
Unhide superhidden for G:\
----------------------------------------
----------------------------------------
Folder list for G:\:
----------------------------------------

dra--   0   G:\ZASTAM~1   G:\za stampu
d-a--   0   G:\FOUND.000   G:\FOUND.000
dra--   0   G:\PPTUSB   G:\PPTUSB
dra--   0   G:\svega   G:\svega
dra--   0   G:\PASSWO~1   G:\Password Protect USB
dra--   0   G:\SEMINA~1   G:\seminarski biologija-cula
--a--   546   G:\op.txt   G:\op.txt
--a--   43520   G:\UPUTST~1.DOC   G:\Uputstvo za izradu seminarskog rada (pravni predmeti).doc
dra--   0   G:\PREKRS~1   G:\Prekrsajno pravo
dra--   0   G:\ENGLES~1   G:\Engleski jezik 4
dra--   0   G:\INTERN~1   G:\Interna kontrola i revizija
dra--   0   G:\KRIMIN~1   G:\Kriminalistika

----------------------------------------

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Otvori flesku i obrisi ova dva foldera

G:\RECYCLER
G:\FOUND.000

Imas li sada bilo kakvih problema sa racunarom?

offline
  • Velin 
  • Novi MyCity građanin
  • Pridružio: 21 Avg 2009
  • Poruke: 11

Sada radi sasvim dobro, nemam nikakvih problema.
Hvala mnogo.

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Da ne zaboravis Antivirus da instaliras i sp3, dao sam ti link. Preuzmes i samo pokrenes instalaciju sa desktopa.

Pozdrav.

Ko je trenutno na forumu
 

Ukupno su 472 korisnika na forumu :: 11 registrovanih, 1 sakriven i 460 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Bane san, cikadeda, Despot1, ILGromovnik, LUDI, mikki jons, mushroom, Radiša, Sale.S, Simon simonović, Snorks