Results 1 to 21 of 21
Thread: Âèðóñ ïî ôëàøêèòå
Hybrid View
-
16th May 2010 12:05 #1
Âèðóñ ïî ôëàøêèòå
Èìàì ñëåäíèÿ ïðîáëåì - ïðè ñëàãàíå íà ôëàøêà íà êîìïþòúðà ñå îêàçâà, ÷å â íåÿ èìà autorun.inf è myfolder, êîèòî íå òðÿáâà äà ñà òàì. Òèÿ äâå ðàáîòè ñå ïîëçâàò îò explorer.exe è íå ìîãàò äà ñå èçòðèÿò áåç Unlocker. Ñëåä çàëè÷àâàíåòî èì èëè ôîðìàò íà ôëàø ïàìåòòà, ïðè íîâî âêëþ÷âàíå â êîìïþòúðà, òå ïàê ñå ïîÿâÿâàò. Òåêñòúò íà .inf ôàéëà å ñëåäíèÿò:
myfile.exe ãî íÿìà â ïàïêàòà (äàæå è â ñêðèòèòå ôàéëîâå), âåðîÿòíî íÿìà âðåìå äà ñå ñúçäàäå... Íå íàìèðàì ïîäîçðèòåëíè ïðîöåñè è service-îâå. Ïðèëàãàì .log ôàéë îò HiJackThis:Code:[autorun] useautoplay=1 shellexecute=myfolder\myfile.exe
ÏÏ: Ïðîáâàõ ðàçíè àíòèâèðóñíè, íàìèðàõà íåêâè âèðóñè, ÷èñòèõà ãè, àìà òîâà ÷óäî íå ñå ìàõà. Îñâåí òîâà îò èçâåñòíî âðåìå ñå ïîÿâÿâà åäíî ïðîçîð÷å, äåòî ïèòà ñèãóðåí ëè ñúì, ÷å èñêàì äà ïóñíà .exe ôàéë (èìàøå ãî íà ñòàðè âåðñèè íà IE, íàïðèìåð); ïðîáëåìúò å, ÷å àç ïîëçâàì Firefox - íÿêàêâè èäåè îòêúäå ñå ÿâè ïà òîâà?Code:Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 12:02:01, on 16.5.2010 ã. Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RunDLL32.exe D:\Programs\Vista Drive Icon\DrvIcon.exe D:\Programs\Glass\Glass2k.exe C:\WINDOWS\system32\ctfmon.exe D:\Programs\TaskSwitch XP\TaskSwitchXP.exe C:\Program Files\Vista Rainbar\Rainmeter.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\BitMeter\BitMeter2.exe D:\Programs\TClock\tclock.exe D:\Programs\Wallpaper Master\Wallpaper.exe D:\Programs\Y'z Toolbar\YzToolBar.exe C:\WINDOWS\System32\svchost.exe D:\Programs\Glass\Glass2k.exe D:\Programs\Firefox\FirefoxPortable.exe D:\Programs\Firefox\App\firefox\firefox.exe C:\Documents and Settings\Name\Desktop\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.skype.com/go/help.guides.ieaddon?lang=en R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe, O1 - Hosts: 66.98.148.65 auto.search.msn.com O1 - Hosts: 66.98.148.65 auto.search.msn.es O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [DrvIcon] D:\Programs\Vista Drive Icon\DrvIcon.exe O4 - HKLM\..\Run: [MOD] C:\Program Files\Microangelo\muamgr.exe O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe O4 - HKLM\..\Run: [Glass2k] D:\Programs\Glass\Glass2k.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [TaskSwitchXP] D:\Programs\TaskSwitch XP\TaskSwitchXP.exe O4 - HKCU\..\Run: [Vista Rainbar] C:\Program Files\Vista Rainbar\Rainmeter.exe O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [uTorrent] "D:\Programs\uTorrent\utorrent.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: TClock.lnk = D:\Programs\TClock\tclock.exe O4 - Startup: Wallpaper.lnk = D:\Programs\Wallpaper Master\Wallpaper.exe O4 - Startup: YzToolBar.lnk = D:\Programs\Y'z Toolbar\YzToolBar.exe O4 - Global Startup: Bitmeter2.lnk = C:\Program Files\BitMeter\BitMeter2.exe O4 - Global Startup: SystemExplorerDisabled O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted IP range: http://192.168.1.1 O15 - ESC Trusted IP range: http://192.168.1.1 O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe O23 - Service: gadzlI - Unknown owner - D:\Programs\PC Wizard\Data\pcwizntl.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe -- End of file - 5613 bytes
-
16th May 2010 12:25 #2
Ïðîáâàé ñ òîâà,
http://download.bleepingcomputer.com/sUBs/ComboFix.exe| ASUS P5K3 DELUXE/WIFI-AP | DDR3 Kingston 1600 4x2GB | INTEL CORE 2 QUAD QX9650 EXTREME | POWER APEX 800W | HDD 500GB WESTERN DIGITAL BLACK SATA II |HDD 500GB WESTERN DIGITAL CAVIAR BLUE SATA III | VGA PNY 8800 ULTRA 768MB DDR3 |
-
16th May 2010 12:50 #3
-
16th May 2010 13:00 #4
http://research.pandasecurity.com/pa...rsion-1-0-1-4/
Ïîíå ñïèðàé àóòîðúíà íà óèí-à, çà äà íå ñå çàðàçÿâà è îáðàáîòè ôëàøêàòà ñ íååäèòâàåì àóòîðúí.èíô
Çà â áúäåùå áè òè ñïåñòèëî íîâè ïðîáëåìè îò òàçè ïîðîäà.
-
16th May 2010 13:18 #5
-
16th May 2010 12:28 #6Registered User
Join Date: Oct:2003
Location: Ñîôèÿ
Posts: 4,317
Íàé-âåðîÿòíî îñíîâíèÿò "äîìàêèí" íà âèðóñèòå å sdra64.exe, îïèñàíî íà ðåäà
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.ex e,C:\WINDOWS\system32\sdra64.exe,
Òúé êàòî ôàéëúò å çàêëþ÷åí, íÿìà äà ìîæåø äà ãî èçòðèåø. Âåðîÿòíî ùå ìîæåø äà ãî ïðåèìåíóâàø îáà÷å. È èçòðèé ïúòÿ êúì íåãî â ãîðåïîñî÷åíèÿ êëþ÷ (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\W indows NT\CurrentVersion\Winlogon), íî âíèìàâàé äà íå èçòðèåø ïúòÿ êúì userinit.exe. È çàâúðøâàùàòà çàïåòàÿ òðÿáâà äà ñè îñòàíå.
Ñëåä ðåñòàðò âå÷å áè òðÿáâàëî äà ìîæåø äà èçòðèåø sdra64 (ñòèãà äà íå ñå å çàãíåçäèë íÿêúäå äðóãàäå) è äà ïóñíåø àíòèâèðóñíà ïðîãðàìà ñ ïîâå÷å óñïåõ.
-
16th May 2010 13:26 #7
Kaspersky ìíîãî äîáðå ãè õâàùà è ãè ëåêóâà òàêèâà ôëàøêè.
P35-DS3P|C2D E8500@4GHz L2-6MB|6GB DDR2@844MHz|GALAXY 9800GT 512MB DDR3|WD 1TB ×ÅÐ 'ÀÉÂÅÐ-32MB ÊÀØÅ|POWERED BY FORTRON BLUE STORM PRO 500W|M$ ÏËÚÕ+ÊËÀÂÈÐ|SAMSUNG 226BW|CREATIVE X-FI PLATINUM FATAL1TY CHAMPION+INSPIRE T7900
BGPatch.com <-- Èãðèòå íà áúëãàðñêè! ツ
-
16th May 2010 15:38 #8
-
17th May 2010 14:59 #9
Èçòåãëåòå ñè òîâà è ñè èìóíèçèðàéòå ôëàøêèòå ñ íåãî.Çà äÿëîâå íå ãî ïðåïîðú÷âàì,çàùîòî ïðåìàõâà íàèìåíóâàíèåòî íà äÿëà è îñòàâà "Local Disk".
-
17th May 2010 15:14 #10Banned
Join Date: Oct:2003
Location: Ñîôèÿ
Posts: 5,259
×å òî îòäàâíà èìà 100% åôåêòèâíè íà÷èíè äà çàùèòèø ôëàøîâåòå ñè îò âèðóñè, äîñòà ñà, íî åòî 2òà êîèòî ïîëçâàì àç:
- ôëàø óñòðîéñòâî ñ êëþ÷ çà read-only
-(òàçè êîìàíäà ïðàâè ôàéë ñ íóëè, êîéòî çàåìà öÿëîòî ñâîáîäíî ïðîñòðàíñòâî íà ôëàø äðàéâà, çà äà íÿìà êúäå è êàê äà ïèøå âèðóñà, ðàçìåðà å ïðèìåðåí, ëåñíî ìîæå äà âèäèòå êîëêî ñâîáîäíè áàéòîâå èìàòå íà ôëàøà)Fsutil file createnew G:\dummy 450256729
Ðàçíàñÿì ñè 4 ôëàøà - 2 õ 16GB è 2 x 32GB - âèðóñè íÿìàì îò äà êàæà ãîäèíà ïî òÿõ êúäåòî è äà ãè ðú÷êàì
Íå òè ñå íàëàãà äà ñïèðàø èëè äà ïóñêàø ñúïîðòà íà êàêâèòî è äà å autorun-è è äð.Last edited by Softman; 17th May 2010 at 15:24.
-
17th May 2010 16:27 #11
-
17th May 2010 15:29 #12
Òîçè ôàéë äåòî ãî ñúçäàâàø âëèÿå ëè àêî èñêàì äà äîáàâÿ èëè èçòðèÿ íåùî, òðÿáâà ëè äà ãî ïðîìåíÿì ïðåäè/ñëåä òîâà ?
-
17th May 2010 15:37 #13Banned
Join Date: Oct:2003
Location: Ñîôèÿ
Posts: 5,259
Àêî äîáàâÿø - ïðàâèø ãî íàíîâî (òðèåø ãî çà äà èìà ìÿñòî çà íîâèÿ ôàéë êîéòî èñêàø äà äîáàâèø)
Àêî ìàõàø - ïðàâèø ãî íàíîâî (çàùîòî ùå èìà ñâîáîäíî ìÿñòî, êîåòî íèå íå èñêàìå äà èìà)
Ñòàâà áúðçî, íî àêî ïèøåø/òðèåø 50 ïúòè íà äåí, ïî-äîáðå ñè âçåìè ñ êëþ÷ ôëàøà (8GB ñà 42ëâ â Ìóëòèðàìà)
-
17th May 2010 16:27 #14
ßñíî, çàïúëâàìå âñè÷êîòî ìÿñòî çà äà íÿìà êúäå äà ñå çàïèøå âèðóñà.
Àêî èñêàì äà èíñòàëèðàì íÿêàêâà ïðîãðàìà îò ôëàøêàòà è òÿ èñêà íÿêàêâî òåìï ìÿñòî âåðîÿòíî ùå ìè äàäå ãðåøêà, çà ôëàøêè ñàìî çà ÷åòåíå å ðåøåíèå.
-
2nd May 2011 21:51 #15Registered User
Join Date: Feb:2008
Location: Ñîôèÿ
Posts: 5,585
Ñúùîòî êàòî è ïðè òåáå-êîïèðàò ñå íà êàêâàòî ôëàø ïàìåò èëè õàðä èì âêàðàø.Èíà÷å îò òèÿ ôëàø÷åòà íåùàòà êîèòî ñúì âèæäàë äà ïðàâÿò êàòî ïîðàçèè ñà äà çàáðàíÿâàò îïöèÿòà äà ñå âèæäàò ñêðèòèòå ôàéëîâå,ñïèðàò äîñòúïà äî ñàéòîâå íà àíòèâèðóñíè è ìàéêðîñîôò è ñëàãàò êàòî äåôîëòíà ,ïúðâà, îïöèÿ autorun íà õàðäîâåòå äà íå ìîæå äà ñå âëèçà ñ äâîåí êëèê.Çà äðóãî íå ñå ñåùàì â ìîìåíòà.
-
2nd May 2011 21:56 #16
Ïðîáâàé ñ Panda vaccine. Ïðåäîòâðàòÿâà àóòîðúíà íà ôëàøêèòå, ïî êîèòî íàé-÷åñòî âëèçàò âèðóñè.
Asrock B450 Steel Legend / Ryzen 5 3600 stock w/ Jonsbo CR-1000 / TeamForce 32GB (4x8GB) 3200 MHz / SP 512GB + 14TB int & 10TB ext / ASRock RX 5600 XT Phantom Gaming 6GB OC / CM Silent Pro 700W / Acer V277 IPS @FullHD 75Hz + HP w2207 / Corsair 600T + 2x 200mm / Mad Catz R.A.T. TE / 'ñè÷êî ëàåðëåñ




Reply With Quote


Ïðîáëåìíà R9 280, àðòåôàêòè
7th May 2023, 21:28 in Âèäåîêàðòè