flesh problem

2

flesh problem

offline
  • Pridružio: 26 Dec 2007
  • Poruke: 97

USBNoRisk 2.5 (26 July 2009) by bobby

Started at 12/30/2009 1:01:46 PM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
C: {ae9a5e84-384a-11de-bd56-806d6172696f}
D: {ae9a5e85-384a-11de-bd56-806d6172696f}
E: {ae9a5e86-384a-11de-bd56-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for ae9a5e84-384a-11de-bd56-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for ae9a5e85-384a-11de-bd56-806d6172696f
No Desktop.ini files found on D:
----------------------------------------

No blocked files found on E:
No Autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for ae9a5e86-384a-11de-bd56-806d6172696f
No Desktop.ini files found on E:
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 12/30/2009 1:01:53 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {bb2a70ca-d04c-11de-a772-0016e66f64ac}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
Blocked file found: H:\autorun.inf.blocked
----------------------------------------
Content of H:\autorun.inf.blocked
----------------------------------------
;aØ??ëÁ?á???[t??f??ÁVMm???à?_????Úü?ðèòÈúI?J?x?
[autorun
;sà?sg?Â_??gìxâþÍ??
open=KLIZAVI/sapun.exe
;b??è?s??g????:ý?)vÌ?x?m?X?E?O?üe,~?bFmw??é?O?W?Y??xo??ç???tä)&??`J??bNy?ÁwEd??À#}?ÓIOr?ñ??ìéÌ???OÖBwe??À???È??Ã]?àð&?üë?ÜÝ^Ý<?
icon=%SystemRoot%\system32\SHELL32.dll,4
;??tëCé?ùààtykY?Ãò??ÿIvÍCIò-L?m??ë???#?íD?Ý?ð??Eù?dm?@?FôkmÁ[M
shell\\open\\command=KLIZAVI/sapun.exe
;ré?d??fÏùùIC???CÁ??wâÓt?Ô?sðW?ÔwbfæeY???í?????Ãè?d?Æ????Êç?Áç+?t?[a?Ã?
shell\\explore\\command=KLIZAVI/sapun.exe
;????ò?ÖmíFÒ???Ã?r?à?fsWÌNE?????????a??ùs?LmaìÃk%:üZ??òÂ?Nä?A?ØCv??éí??f?åÁäs?èY?è???AjA
useautoplay=1
;Òeú?màò???*???%sFRCèY
----------------------------------------

Files referenced from H:\autorun.inf.blocked
----------------------------------------
None
----------------------------------------

----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for bb2a70ca-d04c-11de-a772-0016e66f64ac
----------------------------------------

----------------------------------------
Desktop.ini found at H:\curice\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------
Desktop.ini found at H:\KLIZAVI\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------

No mimics found on drive H:
========================================


Processing script
----------------------------------------
bb2a70ca-d04c-11de-a772-0016e66f64ac
Drive letter for GUID: H:
SectionStart = 0
SectionEnd = 6
----------------------------------------
Unhide superhidden for H:\
----------------------------------------
dra-- H:\Journey to the center of the earth > unhidden
dra-- H:\office2007 > unhidden
dra-- H:\RECYCLER > unhidden
dra-- H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033 > unhidden
--a-- H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\Desktop.ini > unhidden
dra-- H:\curice > unhidden
--a-- H:\curice\Desktop.ini > unhidden
-ra-- H:\curice\elena.exe > unhidden
dra-- H:\PINprobniTest > unhidden
dra-- H:\KLIZAVI > unhidden
--a-- H:\KLIZAVI\Desktop.ini > unhidden
-ra-- H:\KLIZAVI\sapun.exe > unhidden
----------------------------------------
Deleting blocked files:
----------------------------------------
Delete: H:\autorun.inf.blocked > Done!
----------------------------------------
Delete folder tree H:\\KLIZAVI\:
----------------------------------------
File lock detected:
USBNoRisk cannot find what locked the file
Delete: H:\\KLIZAVI\sapun.exe > Error!
Delete: H:\\KLIZAVI\Desktop.ini > Done!
Delete: H:\\KLIZAVI\ > Error!
Delete: H:\\KLIZAVI\ > Error!
----------------------------------------
Delete folder tree H:\\curice\:
----------------------------------------
File lock detected:
USBNoRisk cannot find what locked the file
Delete: H:\\curice\elena.exe > Error!
Delete: H:\\curice\Desktop.ini > Done!
Delete: H:\\curice\ > Error!
Delete: H:\\curice\ > Error!
----------------------------------------
Delete folder tree H:\\RECYCLER\:
----------------------------------------
Delete: H:\\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\Desktop.ini > Done!
Delete: H:\\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033 > Error!
Delete: H:\\RECYCLER\ > Error!
Delete: H:\\RECYCLER\ > Error!
----------------------------------------
Folder list for H:\:
----------------------------------------

dra--   0   H:\JOURNE~1   H:\Journey to the center of the earth
dra--   0   H:\OFFICE~1   H:\office2007
dra--   0   H:\RECYCLER   H:\RECYCLER
dra--   0   H:\curice   H:\curice
dra--   0   H:\PINPRO~1   H:\PINprobniTest
dra--   0   H:\KLIZAVI   H:\KLIZAVI

----------------------------------------

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Moraćemo još jednom da ponovimo postupak.


- Pokrenuti USBNoRisk i sačekati da izvrši inicijalno skeniranje.

- Po završetku inicijalnog skeniranja priključiti USB memorijski uređaj.

- Kliknuti na karticu Script;

U beli okvir prozora iskopirati sledeći tekst:

{bb2a70ca-d04c-11de-a772-0016e66f64ac}
f_delete:%DRIVE%curice\elena.exe
f_delete:%DRIVE%KLIZAVI\sapun.exe
folder_delete:%DRIVE%curice\
folder_delete:%DRIVE%klizavi\
folder_delete:%DRIVE%RECYCLER\
folder_list:%DRIVE%


- Izvršiti komandu klikom na taster Run Script;



Po izvršenju komande USBNoRisk će se automatski vratiti na karticu Monitor;

- Uraditi desni klik unutar belog okvira prozora i odabrati opciju Save Log;

Otvoriće se prozor Notepad_a sa tekstom koji je potrebno iskopirati ovde u poruci.

offline
  • Pridružio: 26 Dec 2007
  • Poruke: 97

Napisano: 31 Dec 2009 11:49

USBNoRisk 2.5 (26 July 2009) by bobby

Started at 12/31/2009 11:40:07 AM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
C: {ae9a5e84-384a-11de-bd56-806d6172696f}
D: {ae9a5e85-384a-11de-bd56-806d6172696f}
E: {ae9a5e86-384a-11de-bd56-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for ae9a5e84-384a-11de-bd56-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for ae9a5e85-384a-11de-bd56-806d6172696f
No Desktop.ini files found on D:
----------------------------------------

No blocked files found on E:
No Autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for ae9a5e86-384a-11de-bd56-806d6172696f
No Desktop.ini files found on E:
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 12/31/2009 11:40:22 AM

Scanning for connected USB mass storage...
----------------------------------------
H: {bb2a70ca-d04c-11de-a772-0016e66f64ac}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for bb2a70ca-d04c-11de-a772-0016e66f64ac
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
========================================


Processing script
----------------------------------------
bb2a70ca-d04c-11de-a772-0016e66f64ac
Drive letter for GUID: H:
SectionStart = 1
SectionEnd = 7
f_delete:
file "H:\curice\elena.exe" deleted successfully
f_delete:
file "H:\KLIZAVI\sapun.exe" deleted successfully
----------------------------------------
Delete folder tree H:\curice\:
----------------------------------------
Folder tree is empty
Delete: H:\curice\ > Error!
----------------------------------------
Delete folder tree H:\klizavi\:
----------------------------------------
Folder tree is empty
Delete: H:\klizavi\ > Error!
----------------------------------------
Delete folder tree H:\RECYCLER\:
----------------------------------------
Delete: H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033 > Error!
Delete: H:\RECYCLER\ > Error!
Delete: H:\RECYCLER\ > Error!
----------------------------------------
Folder list for H:\:
----------------------------------------

dra--   0   H:\JOURNE~1   H:\Journey to the center of the earth
dra--   0   H:\OFFICE~1   H:\office2007
dra--   0   H:\RECYCLER   H:\RECYCLER
dra--   0   H:\curice   H:\curice
dra--   0   H:\PINPRO~1   H:\PINprobniTest
dra--   0   H:\KLIZAVI   H:\KLIZAVI

----------------------------------------

Dopuna: 31 Dec 2009 12:02

**********************************************************
evo nesto sto sam primetio:
jel treba da deinstaliram combofix?
na D particiji primetio sam da ima $RECYCLE.BIN(0 bytes) i RECYCLER(85 bytes) folder,inace su prazni.
na E particiji RECYCLER(85bytes) isto prazan.
to nije dosada bilo.

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Idemo još jednom, samo ovaj put isključi Anti-Virus zaštitu...

http://www.mycity.rs/Uputstva/Iskljucivanje-zastitnog-softvera.html


- Pokrenuti USBNoRisk i sačekati da izvrši inicijalno skeniranje.

- Po završetku inicijalnog skeniranja priključiti USB memorijski uređaj.

- Kliknuti na karticu Script;

U beli okvir prozora iskopirati sledeći tekst:

{bb2a70ca-d04c-11de-a772-0016e66f64ac}
folder_delete:%DRIVE%RECYCLER\
folder_delete:%DRIVE%KLIZAVI\
folder_delete:%DRIVE%curice\
folder_list:%DRIVE%


- Izvršiti komandu klikom na taster Run Script;



Po izvršenju komande USBNoRisk će se automatski vratiti na karticu Monitor;

- Uraditi desni klik unutar belog okvira prozora i odabrati opciju Save Log;

Otvoriće se prozor Notepad_a sa tekstom koji je potrebno iskopirati ovde u poruci.

offline
  • Pridružio: 26 Dec 2007
  • Poruke: 97

Napisano: 31 Dec 2009 15:48

USBNoRisk 2.5 (26 July 2009) by bobby

Started at 12/31/2009 3:33:40 PM

Searching for connected USB Mass storage...
----------------------------------------
========================================

Searching for other storage...
----------------------------------------
C: {ae9a5e84-384a-11de-bd56-806d6172696f}
D: {ae9a5e85-384a-11de-bd56-806d6172696f}
E: {ae9a5e86-384a-11de-bd56-806d6172696f}
========================================


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for ae9a5e84-384a-11de-bd56-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

No blocked files found on D:
No Autorun.inf files found on D:
No mountpoint found for D:
No mountpoint found for ae9a5e85-384a-11de-bd56-806d6172696f
No Desktop.ini files found on D:
----------------------------------------

No blocked files found on E:
No Autorun.inf files found on E:
No mountpoint found for E:
No mountpoint found for ae9a5e86-384a-11de-bd56-806d6172696f
No Desktop.ini files found on E:
----------------------------------------

========================================
Initial scan finished!
========================================


New device connected at 12/31/2009 3:33:49 PM

Scanning for connected USB mass storage...
----------------------------------------
H: {bb2a70ca-d04c-11de-a772-0016e66f64ac}
Added H:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on H:
----------------------------------------
No Autorun.inf files found on H:
No mountpoint found for bb2a70ca-d04c-11de-a772-0016e66f64ac
----------------------------------------

No Desktop.ini files found on H:
----------------------------------------

No mimics found on drive H:
========================================


Processing script
----------------------------------------
bb2a70ca-d04c-11de-a772-0016e66f64ac
Drive letter for GUID: H:
SectionStart = 1
SectionEnd = 5
----------------------------------------
Delete folder tree H:\RECYCLER\:
----------------------------------------
Delete: H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033 > Error!
Delete: H:\RECYCLER\ > Error!
Delete: H:\RECYCLER\ > Error!
----------------------------------------
Delete folder tree H:\KLIZAVI\:
----------------------------------------
Folder tree is empty
Delete: H:\KLIZAVI\ > Error!
----------------------------------------
Delete folder tree H:\curice\:
----------------------------------------
Folder tree is empty
Delete: H:\curice\ > Error!
----------------------------------------
Folder list for H:\:
----------------------------------------

dra--   0   H:\JOURNE~1   H:\Journey to the center of the earth
dra--   0   H:\OFFICE~1   H:\office2007
dra--   0   H:\RECYCLER   H:\RECYCLER
dra--   0   H:\curice   H:\curice
dra--   0   H:\PINPRO~1   H:\PINprobniTest
dra--   0   H:\KLIZAVI   H:\KLIZAVI

----------------------------------------

========================================
Removed H:
========================================

Dopuna: 31 Dec 2009 15:54

windows firewall iskljucio
avast,odbranbeni modul i stalnu zastitu iskljucio
spybot, iskljucio u rezidentu obe stavke i resetovan teatimer.

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Da probamo na drugi način...

Odradi po sledećem uputstvu...

http://www.mycity.rs/Uputstva/Kako-videti-skrivene-fajlove.html


Zatim obriši sledeće foldere:

- RECYCLER
- KLIZAVI
- curice




Kada to odradiš javi mi stanje.

offline
  • Pridružio: 26 Dec 2007
  • Poruke: 97

srecna nova!
e izvini ali ne znam gde da obrisem,daj mi upustvo,kamo srece da sam pripravnik kao ti:)
pokusao sam na kompu da obrisem recycler ali dobijam ovo:cennot delete recycler acess iz denied. make sure the disk iz not full or write-protected and that thefile iz not currently in use.
na C particiji je skriven a na E i D je obican folder
flesh nisam hteo da stavljam dok mi ne kazes...pozz

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Slobodno priključi usb uređaj i sa njega obriši foldere koje sam ti naveo.

Taj RECYCLER na kompjuteru je legitiman.

Znači samo sa usb uređaja ih obriši.


Srećna Nova...

offline
  • Pridružio: 26 Dec 2007
  • Poruke: 97

prikljucio i obrisao, i formatirao,radi sad kao pre:)
bio sam skenirao sa avastom kad nisu bili skriveni fajlovi i nasao je:C:\System Volume Information\_restore{F0C9D7D2-1A7A-444E-9401-EB1FE5439692}\RP20\A0008958.exe [L] Win32:Malware-gen (0)
Datoteka je uspešno premeštena u chest...
ali sve u svemu,hvala i sve najbolje

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Isprati još sledeće...


Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

ComboFix /Uninstall

Primeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.

Ko je trenutno na forumu
 

Ukupno su 1297 korisnika na forumu :: 65 registrovanih, 7 sakrivenih i 1225 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: alkatraz080, amaterSRB, Andrija357, Danijel99, DejanSt, dekan.m, Denaya, Dimitrise93, djboj, DonRumataEstorski, Dorcolac, DPera, Dragan1998, draganca, drazenm, dulleo, Georgius, GORDI, h8propaganda, havoc995, hologram, hooraay, Istman, ivica976, jukeboxer, Klecaviks, Krusarac, Krvava Devetka, Kubovac, kunktator, madza, mercedesamg, Mercury, Mi lao shu, milenko crazy north, milimoj, Mixelotti, mnn2, moldway, mrav pesadinac, Nemanja.M, Ognjen D., oldtimer, panzerwaffe, Petarvu, raptorsi, Recce, repac, robert1979, sasa87, Singidunumac, slonic_tonic, Smajser, Srle993, stegonosa, vathra, virked, VJ, vlajkox, voja64, vukovi, wolverined4, yufighter, zziko, 1107