opet recycler

1

opet recycler

offline
  • Pridružio: 20 Mar 2009
  • Poruke: 300
  • Gde živiš: Republic Of Srpska Banjaluka

stvarno mi nije drago sto sam opet ovdje ali sta ces
davao sam svoj usb na koriscenje i naravno vracen mi je sa nekim djavolom
cim sam ga ustekao nod je pocrvenio ali bez mogucnosti brisanja
na sledeci sken nodom dao je opciju delete i navodno je obrisan
malver bajts je nasao neka cetiri trojan agenta u nekim recyclerima obrisao ih i na ponovni sken ih ne prijavljuje
ali usb se nastavio cudno ponasati
kad ga ustekam neda mi otvoriti na dupli klik vec na explore i ikonica nije kao hard disk vec folder(ikona od usb-a)
na format odreaguje pusti dupli klik i pojavi se ikona od diska ali cim ga ponovo prijavim ista stvar kaze K is not a valid win32 application
jos jednom izvinjenje zabog mog treceg dolaska u ambulantu

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:57, on 12/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ClocX\ClocX.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\PST\Desktop\New Folder\TR3.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{81D323A9-3773-4DF3-972D-1E5BD598DEAB}: NameServer = 62.68.96.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

--
End of file - 4858 bytes

tek cu se ujutro moci javiti!sljakam!pozdrav

Dopuna: 25 Dec 2008 23:30

ovo sam izbrisao
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...



Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 20 Mar 2009
  • Poruke: 300
  • Gde živiš: Republic Of Srpska Banjaluka

nisam mogao ranije sad sam ustao
evo ga
samo da ti napomenem bila mi je konekcija aktivna i digao se nod al je nestao i instalirao je recovery konzolu

ComboFix 08-12-25.04 - PST 2008-12-26 17:03:18.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1535.1051 [GMT 1:00]
Running from: c:\documents and settings\PST\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\dumphive.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((( Files Created from 2008-11-26 to 2008-12-26 )))))))))))))))))))))))))))))))
.

2008-12-25 22:21 . 2008-12-25 22:21 5,777,139 --a------ C:\goca trzan - kad ponos ubije ljubav iz nehata.mp3
2008-12-15 22:12 . 2008-12-15 22:12 512,096 --a------ c:\windows\system32\drivers\amon.sys
2008-12-15 22:12 . 2008-12-15 22:12 299,392 --a------ c:\windows\system32\imon.dll
2008-12-15 22:12 . 2008-12-15 22:12 15,424 --a------ c:\windows\system32\drivers\nod32drv.sys
2008-12-15 22:11 . 2008-12-25 22:22 <DIR> d-------- c:\program files\ESET
2008-12-15 22:02 . 2008-12-15 22:03 <DIR> d-------- c:\windows\system32\updfiles
2008-12-15 22:01 . 2008-12-15 22:01 87 --a------ c:\windows\system32\EpfwUser.dat
2008-12-15 20:13 . 2008-12-15 20:13 <DIR> d-------- c:\program files\Common Files\eSellerate
2008-12-15 20:13 . 2008-12-15 20:13 360,580 --a------ c:\windows\eSellerateEngine.dll
2008-12-15 20:13 . 2008-12-15 20:17 135 --ah----- c:\documents and settings\PST\Application Data\lakerda1967.sys
2008-12-04 06:14 . 2008-12-04 06:14 2,432 --a------ c:\documents and settings\cc_20081204_0614.reg

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-26 15:56 --------- d-----w c:\documents and settings\PST\Application Data\uTorrent
2008-12-21 21:34 25,992 ----a-w c:\windows\system32\pgdfgsvc.exe
2008-12-20 18:50 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-20 18:50 --------- d-----w c:\program files\SpywareBlaster
2008-12-20 18:48 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-12 18:08 --------- d-----w c:\documents and settings\PST\Application Data\Skype
2008-12-12 16:35 --------- d-----w c:\documents and settings\PST\Application Data\skypePM
2008-12-06 17:06 12,524 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-12-04 05:12 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-03 18:52 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-03 18:52 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-12-01 16:47 --------- d-----w c:\program files\Opera
2008-11-30 11:55 --------- d-----w c:\documents and settings\All Users\Application Data\nView_Profiles
2008-11-09 13:29 --------- d-----w c:\program files\Corel
2008-11-09 13:28 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-09 13:27 --------- d-----w c:\documents and settings\PST\Application Data\Corel
2008-11-09 13:06 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-09 13:06 --------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2008-11-08 13:06 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-08 00:55 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-07 20:19 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-11-07 20:19 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-11-02 03:04 --------- d-----w c:\program files\Common Files\Adobe
2008-10-28 17:19 --------- d-----w c:\documents and settings\All Users\Application Data\NVIDIA
2008-10-27 17:34 --------- d-----w c:\documents and settings\PST\Application Data\Steinberg
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2005-01-26 270336]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-12-15 950664]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 c:\windows\system32\nvmctray.dll]

c:\documents and settings\PST\Start Menu\Programs\Startup\
Cyber-shot Viewer Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-01-17 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.DVSD"= pdvcodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Native Instruments\\Traktor DJ Studio 2\\TraktorDJStudio2.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\PST\\Desktop\\Skype.exe"=

R0 viasraid;viasraid;c:\windows\system32\DRIVERS\viasraid.sys [2005-05-31 77056]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-12-15 15424]
R2 Asapi;Asapi;c:\windows\system32\drivers\Asapi.sys [2005-06-01 8768]
R2 MarxDev1;MarxDev1;c:\windows\system32\drivers\MarxDev1.sys [2005-06-01 8864]
R2 MarxDev2;MarxDev2;c:\windows\system32\drivers\MarxDev2.sys [2005-06-01 8864]
R2 MarxDev3;MarxDev3;c:\windows\system32\drivers\MarxDev3.sys [2005-06-01 8864]
S2 Tdlpt;Tdlpt;\??\c:\windows\system32\drivers\Tdlpt.sys [2005-06-01 8012]
S3 usb2vcom;USB Data Cable;c:\windows\system32\DRIVERS\usb2vcom.sys [2006-05-16 29152]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
TCP: {81D323A9-3773-4DF3-972D-1E5BD598DEAB} = 62.68.96.2
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-26 17:04:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(688-)
c:\windows\system32\imon.dll
.
Completion time: 2008-12-26 17:05:32
ComboFix-quarantined-files.txt 2008-12-26 16:05:13

Pre-Run: 8,090,284,032 bytes free
Post-Run: 8,077,885,440 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

128

Dopuna: 26 Dec 2008 17:16

i nisam disejblovao nod u toku skeniranja
i nisu mi bili ukljuceni ext hard disk i usb drajv

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Skini sledeci program - http://amf.mycity.rs/personal/bobby/USB_blocker/usb_blocker.exe
- startuj ga i odaberi opciju Auto block
- ubaci USB stick u komp i sacekaj koji sekund (recimo 5-10 sekundi)
- program je sada uradio analizu sticka (vidi se u donjem delu programa, u logu)
- gore levo klikni duplo na slovo koje oznacava particiju, tj. tvoj USB stick
- dole kraj sata ce se pojaviti poruka da smes da izvadis USB stick iz kompa
- ne gasi program, vec ubaci sledeci USB stick i za njega isto sacekaj par sekundi, i tako redom za sve stickove, MP3 plejere, mobilni
- zapamti kojim redom su ubacivani stickovi

Kada sve to zavrsis, log u donjem delu programa ce sadrzati sve podatke koji su meni potrebni da bih video koji stick je zarazen.
Klikni desnim dugmetom misa na log/izvestaj i odaberi Save log.
Automatski ce se otvoriti Notepad i u njemu izvestaj.
Iskopiraj mi taj izvestaj ovde na forum.

offline
  • Pridružio: 20 Mar 2009
  • Poruke: 300
  • Gde živiš: Republic Of Srpska Banjaluka

evo ga druze kad sam ubo telefon nod je pocrvenio
i prikazao da ima nesto na telefonu ali ne i na kartici
evo log

USB_blocker by bobby

Started at 12/26/2008 10:53:31 PM

Scanning for connected USB Mass storage...
========================================
========================================
Scanning for other storage...
========================================
C: 554182df-d20c-11d9-b070-806d6172696f
E: 554182e0-d20c-11d9-b070-806d6172696f
F: 554182e1-d20c-11d9-b070-806d6172696f
H: 5858e082-fe43-11d5-8517-00112fb41aa6
I: 5858e083-fe43-11d5-8517-00112fb41aa6
========================================

Scanning fixed storage for autorun.inf files...
========================================
========================================



New device connected at 12/26/2008 10:53:56 PM

Scanning for connected USB Mass storage...
========================================
K: 3e79412a-a51e-11dd-8514-00112fb41aa6
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 3e79412a-a51e-11dd-8514-00112fb41aa6
========================================


New device connected at 12/26/2008 10:56:18 PM

Scanning for connected USB Mass storage...
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================

autorun.inf found on J:
File J:\autorun.inf renamed successfully
Sanitizing Shell Menu...
No key for GUID: 612cc46f-d30c-11dd-8552-00112fb41aa6
========================================


New device connected at 12/26/2008 10:56:22 PM

Scanning for connected USB Mass storage...
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6
K: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 612cc46f-d30c-11dd-8552-00112fb41aa6
No key for GUID: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================
K: 612cc470-d30c-11dd-8552-00112fb41aa6


New device connected at 12/26/2008 10:56:32 PM

Scanning for connected USB Mass storage...
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6
K: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 612cc46f-d30c-11dd-8552-00112fb41aa6
No key for GUID: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================
K: 612cc470-d30c-11dd-8552-00112fb41aa6


New device connected at 12/26/2008 10:56:37 PM

Scanning for connected USB Mass storage...
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6
K: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 612cc46f-d30c-11dd-8552-00112fb41aa6
No key for GUID: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6


New device connected at 12/26/2008 10:56:43 PM

Scanning for connected USB Mass storage...
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6
K: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 612cc46f-d30c-11dd-8552-00112fb41aa6
No key for GUID: 612cc470-d30c-11dd-8552-00112fb41aa6
========================================
J: 612cc46f-d30c-11dd-8552-00112fb41aa6


New device connected at 12/26/2008 10:58:16 PM

Scanning for connected USB Mass storage...
========================================
J: 9478dbf4-b5bf-11dd-852f-00112fb41aa6
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 9478dbf4-b5bf-11dd-852f-00112fb41aa6
========================================

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Na uređaju koji si priključio drugi po redu se nalazi file autorun.inf.blocked - otvori ga u Notepad-u i iskopiraj ovde njegov sadržaj.

offline
  • Pridružio: 20 Mar 2009
  • Poruke: 300
  • Gde živiš: Republic Of Srpska Banjaluka

eb ga na poslu sam do sest ujutro
jeste drugi je uredjaj po redu bio telefon ali nije mi jasno kako cu naci na telefonu fajl
nista probacu ujutro
pozdrav

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Čim spojiš telefon, on će biti prikazan kao neki drive u My Computer.

Čim ga otvoriš (dvoklikom na ikonicu), taj file odmah treba da bude vidljiv.

offline
  • Pridružio: 20 Mar 2009
  • Poruke: 300
  • Gde živiš: Republic Of Srpska Banjaluka

i jos sam da dodam telefon sam redovno ukopcavao i prebacivao fajlove ali nikad nista nije pokazalo da je zarazen majku mu poljubim

Dopuna: 27 Dec 2008 6:54

uh znao sam ja da ovo nece biti lako
e ovako
kad sam upalio komp sa sistemom se upalio i externi hd
prvo sam probao naci na telefonu fajl autorun.inf kao sto si rekao ali usb blocker mi prijavljuje na local disc L (a to je ext hd) istoimeni fajl koji si ti spominjao
a na telefonu (skenirao sam ga nodom) prijavljuje fajl
Adober.exe - Win32/RJump.A worm
kaze da se fajl ne moze obrisati ali ga obrise i na ponovnom skernu ga ne prijavljuje a evo ti log od usb blockera jos jednom

USB_blocker by bobby

Started at 12/27/2008 6:42:02 AM

Scanning for connected USB Mass storage...
========================================
========================================
Scanning for other storage...
========================================
C: 554182df-d20c-11d9-b070-806d6172696f
E: 554182e0-d20c-11d9-b070-806d6172696f
F: 554182e1-d20c-11d9-b070-806d6172696f
H: 5858e082-fe43-11d5-8517-00112fb41aa6
I: 5858e083-fe43-11d5-8517-00112fb41aa6
========================================

Scanning fixed storage for autorun.inf files...
========================================
========================================



New device connected at 12/27/2008 6:42:36 AM

Scanning for connected USB Mass storage...
========================================
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
========================================


New device connected at 12/27/2008 6:42:37 AM

Scanning for connected USB Mass storage...
========================================
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
========================================
K: 612cc470-d30c-11dd-8552-00112fb41aa6


New device connected at 12/27/2008 6:44:41 AM

Scanning for connected USB Mass storage...
========================================
J: 3e79412a-a51e-11dd-8514-00112fb41aa6
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 3e79412a-a51e-11dd-8514-00112fb41aa6
========================================


New device connected at 12/27/2008 6:45:42 AM

Scanning for connected USB Mass storage...
========================================
J: 9478dbf4-b5bf-11dd-852f-00112fb41aa6
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: 9478dbf4-b5bf-11dd-852f-00112fb41aa6
========================================


New device connected at 12/27/2008 6:46:35 AM

Scanning for connected USB Mass storage...
========================================
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
========================================

s tim da mi nije prikazao u lijevom prozoru samo od telefona ikone i nisam ih mogao iskljuciti na dupli klik vec standardnom procedurom

dr boro sta se ovo desava

Dopuna: 27 Dec 2008 7:06

ovo je autorun sa diska i cini mi se da je njegov fabricki fajl al evo ovako izgleda u notepadu (samo sam ga prevukao u note pad)
jel tako trebalo

[autorun]
ICON=AUTORUN\WDLOGO.ICO

Dopuna: 27 Dec 2008 7:36

i da nisam uspio naci na telefonu taj fajl
prikaze samo foldere s tim da je jedan imenom system osjencen vjerovatno hidiran
nadam se da te necu smoriti

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Citat:ovo je autorun sa diska i cini mi se da je njegov fabricki fajl al evo ovako izgleda u notepadu (samo sam ga prevukao u note pad)
jel tako trebalo

[autorun]
ICON=AUTORUN\WDLOGO.ICO


Ovaj možeš da preimenuješ nazad u autorun.inf (to jeste fabrički file).


Što se tiče telefona: priključi ga a zatim idi na Start > Run i ukucaj:


notepad X:\autorun.inf.blocked

Slovo X zameni onim slovom koje bude dodeljeno telefonu.


Javi da li je ovo gore uspelo i da li ti sada AV nešto detektuje.

Ko je trenutno na forumu
 

Ukupno su 566 korisnika na forumu :: 7 registrovanih, 1 sakriven i 558 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Alibaba1981, Lazarus, Mi lao shu, Milos82, suton, uruk, zziko