Results 1 to 21 of 21

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Registered User brnn's Avatar
    Join Date: Jun:2006
    Location: Ñîôèÿ
    Posts: 754

    Âèðóñ ïî ôëàøêèòå

    Èìàì ñëåäíèÿ ïðîáëåì - ïðè ñëàãàíå íà ôëàøêà íà êîìïþòúðà ñå îêàçâà, ÷å â íåÿ èìà autorun.inf è myfolder, êîèòî íå òðÿáâà äà ñà òàì. Òèÿ äâå ðàáîòè ñå ïîëçâàò îò explorer.exe è íå ìîãàò äà ñå èçòðèÿò áåç Unlocker. Ñëåä çàëè÷àâàíåòî èì èëè ôîðìàò íà ôëàø ïàìåòòà, ïðè íîâî âêëþ÷âàíå â êîìïþòúðà, òå ïàê ñå ïîÿâÿâàò. Òåêñòúò íà .inf ôàéëà å ñëåäíèÿò:

    Code:
    [autorun]
    useautoplay=1
    shellexecute=myfolder\myfile.exe
    myfile.exe ãî íÿìà â ïàïêàòà (äàæå è â ñêðèòèòå ôàéëîâå), âåðîÿòíî íÿìà âðåìå äà ñå ñúçäàäå... Íå íàìèðàì ïîäîçðèòåëíè ïðîöåñè è service-îâå. Ïðèëàãàì .log ôàéë îò HiJackThis:

    Code:
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 12:02:01, on 16.5.2010 ã.
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\RunDLL32.exe
    D:\Programs\Vista Drive Icon\DrvIcon.exe
    D:\Programs\Glass\Glass2k.exe
    C:\WINDOWS\system32\ctfmon.exe
    D:\Programs\TaskSwitch XP\TaskSwitchXP.exe
    C:\Program Files\Vista Rainbar\Rainmeter.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\BitMeter\BitMeter2.exe
    D:\Programs\TClock\tclock.exe
    D:\Programs\Wallpaper Master\Wallpaper.exe
    D:\Programs\Y'z Toolbar\YzToolBar.exe
    C:\WINDOWS\System32\svchost.exe
    D:\Programs\Glass\Glass2k.exe
    D:\Programs\Firefox\FirefoxPortable.exe
    D:\Programs\Firefox\App\firefox\firefox.exe
    C:\Documents and Settings\Name\Desktop\HiJackThis.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.skype.com/go/help.guides.ieaddon?lang=en
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
    O1 - Hosts: 66.98.148.65 auto.search.msn.com
    O1 - Hosts: 66.98.148.65 auto.search.msn.es
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [DrvIcon] D:\Programs\Vista Drive Icon\DrvIcon.exe
    O4 - HKLM\..\Run: [MOD] C:\Program Files\Microangelo\muamgr.exe
    O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
    O4 - HKLM\..\Run: [Glass2k] D:\Programs\Glass\Glass2k.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [TaskSwitchXP] D:\Programs\TaskSwitch XP\TaskSwitchXP.exe
    O4 - HKCU\..\Run: [Vista Rainbar] C:\Program Files\Vista Rainbar\Rainmeter.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [uTorrent] "D:\Programs\uTorrent\utorrent.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: TClock.lnk = D:\Programs\TClock\tclock.exe
    O4 - Startup: Wallpaper.lnk = D:\Programs\Wallpaper Master\Wallpaper.exe
    O4 - Startup: YzToolBar.lnk = D:\Programs\Y'z Toolbar\YzToolBar.exe
    O4 - Global Startup: Bitmeter2.lnk = C:\Program Files\BitMeter\BitMeter2.exe
    O4 - Global Startup: SystemExplorerDisabled
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted IP range: http://192.168.1.1
    O15 - ESC Trusted IP range: http://192.168.1.1
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    O23 - Service: gadzlI - Unknown owner - D:\Programs\PC Wizard\Data\pcwizntl.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    
    --
    End of file - 5613 bytes
    ÏÏ: Ïðîáâàõ ðàçíè àíòèâèðóñíè, íàìèðàõà íåêâè âèðóñè, ÷èñòèõà ãè, àìà òîâà ÷óäî íå ñå ìàõà. Îñâåí òîâà îò èçâåñòíî âðåìå ñå ïîÿâÿâà åäíî ïðîçîð÷å, äåòî ïèòà ñèãóðåí ëè ñúì, ÷å èñêàì äà ïóñíà .exe ôàéë (èìàøå ãî íà ñòàðè âåðñèè íà IE, íàïðèìåð); ïðîáëåìúò å, ÷å àç ïîëçâàì Firefox - íÿêàêâè èäåè îòêúäå ñå ÿâè ïà òîâà?

  2. #2
    Registered User der's Avatar
    Join Date: Jun:2005
    Location: spain
    Posts: 185
    | ASUS P5K3 DELUXE/WIFI-AP | DDR3 Kingston 1600 4x2GB | INTEL CORE 2 QUAD QX9650 EXTREME | POWER APEX 800W | HDD 500GB WESTERN DIGITAL BLACK SATA II |HDD 500GB WESTERN DIGITAL CAVIAR BLUE SATA III | VGA PNY 8800 ULTRA 768MB DDR3 |

  3. #3
    Registered User brnn's Avatar
    Join Date: Jun:2006
    Location: Ñîôèÿ
    Posts: 754
    Quote Originally Posted by der View Post
    Äîáðî, äîáðî, ñâúðøè ÷óäåñíà ðàáîòà.

    Quote Originally Posted by bsb View Post
    è äà ïóñíåø àíòèâèðóñíà ïðîãðàìà ñ ïîâå÷å óñïåõ.
    Àç ñåãà èíñòàëèðàõ íà ïîæàð åäíè, äåòî ñàìî ÷èñòÿò, ïî ïðèíöèï íå ïîëçâàì àíòèâèðóñíè...

    ÏÏ: Ìíîãî áëàãîäàðÿ çà îòãîâîðèòå!

  4. #4
    HODL! der_meister's Avatar
    Join Date: Mar:2005
    Location: Ñîôèÿ
    Posts: 1,254
    http://research.pandasecurity.com/pa...rsion-1-0-1-4/

    Ïîíå ñïèðàé àóòîðúíà íà óèí-à, çà äà íå ñå çàðàçÿâà è îáðàáîòè ôëàøêàòà ñ íååäèòâàåì àóòîðúí.èíô Çà â áúäåùå áè òè ñïåñòèëî íîâè ïðîáëåìè îò òàçè ïîðîäà.

  5. #5
    Registered User brnn's Avatar
    Join Date: Jun:2006
    Location: Ñîôèÿ
    Posts: 754
    Ùå ãî ïóñíà òîâà Ïàíäîâîòî.

  6. #6
    Registered User
    Join Date: Oct:2003
    Location: Ñîôèÿ
    Posts: 4,317
    Íàé-âåðîÿòíî îñíîâíèÿò "äîìàêèí" íà âèðóñèòå å sdra64.exe, îïèñàíî íà ðåäà
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.ex e,C:\WINDOWS\system32\sdra64.exe,

    Òúé êàòî ôàéëúò å çàêëþ÷åí, íÿìà äà ìîæåø äà ãî èçòðèåø. Âåðîÿòíî ùå ìîæåø äà ãî ïðåèìåíóâàø îáà÷å. È èçòðèé ïúòÿ êúì íåãî â ãîðåïîñî÷åíèÿ êëþ÷ (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\W indows NT\CurrentVersion\Winlogon), íî âíèìàâàé äà íå èçòðèåø ïúòÿ êúì userinit.exe. È çàâúðøâàùàòà çàïåòàÿ òðÿáâà äà ñè îñòàíå.
    Ñëåä ðåñòàðò âå÷å áè òðÿáâàëî äà ìîæåø äà èçòðèåø sdra64 (ñòèãà äà íå ñå å çàãíåçäèë íÿêúäå äðóãàäå) è äà ïóñíåø àíòèâèðóñíà ïðîãðàìà ñ ïîâå÷å óñïåõ.

  7. #7
    Windows 8 Fanatic speedycars's Avatar
    Join Date: May:2005
    Location: Ñîôèÿ
    Posts: 3,090
    Kaspersky ìíîãî äîáðå ãè õâàùà è ãè ëåêóâà òàêèâà ôëàøêè.
    P35-DS3P|C2D E8500@4GHz L2-6MB|6GB DDR2@844MHz|GALAXY 9800GT 512MB DDR3|WD 1TB ×ÅÐ 'ÀÉÂÅÐ-32MB ÊÀØÅ|POWERED BY FORTRON BLUE STORM PRO 500W|M$ ÏËÚÕ+ÊËÀÂÈÐ|SAMSUNG 226BW|CREATIVE X-FI PLATINUM FATAL1TY CHAMPION+INSPIRE T7900
    BGPatch.com <-- Èãðèòå íà áúëãàðñêè! ツ

  8. #8
    Registered User brnn's Avatar
    Join Date: Jun:2006
    Location: Ñîôèÿ
    Posts: 754
    Quote Originally Posted by speedycars View Post
    Kaspersky ìíîãî äîáðå ãè õâàùà è ãè ëåêóâà òàêèâà ôëàøêè.
    Ìè àç ñ íÿêàêúâ íåãîâ áåçïëàòåí Virus Remover îò ñàéòà òðåòèðàõ, àìà íàìèðà, äåçèíôåêöèðà, íàêðàÿ ïàê ñè áåøå òàì ãàäèíàòà.

  9. #9
    Registered User jossbomon's Avatar
    Join Date: Nov:2008
    Location: Áúëãàðèÿ
    Posts: 226
    Èçòåãëåòå ñè òîâà è ñè èìóíèçèðàéòå ôëàøêèòå ñ íåãî.Çà äÿëîâå íå ãî ïðåïîðú÷âàì,çàùîòî ïðåìàõâà íàèìåíóâàíèåòî íà äÿëà è îñòàâà "Local Disk".

  10. #10
    Banned
    Join Date: Oct:2003
    Location: Ñîôèÿ
    Posts: 5,259
    ×å òî îòäàâíà èìà 100% åôåêòèâíè íà÷èíè äà çàùèòèø ôëàøîâåòå ñè îò âèðóñè, äîñòà ñà, íî åòî 2òà êîèòî ïîëçâàì àç:

    - ôëàø óñòðîéñòâî ñ êëþ÷ çà read-only

    -
    Fsutil file createnew G:\dummy 450256729
    (òàçè êîìàíäà ïðàâè ôàéë ñ íóëè, êîéòî çàåìà öÿëîòî ñâîáîäíî ïðîñòðàíñòâî íà ôëàø äðàéâà, çà äà íÿìà êúäå è êàê äà ïèøå âèðóñà, ðàçìåðà å ïðèìåðåí, ëåñíî ìîæå äà âèäèòå êîëêî ñâîáîäíè áàéòîâå èìàòå íà ôëàøà)


    Ðàçíàñÿì ñè 4 ôëàøà - 2 õ 16GB è 2 x 32GB - âèðóñè íÿìàì îò äà êàæà ãîäèíà ïî òÿõ êúäåòî è äà ãè ðú÷êàì
    Íå òè ñå íàëàãà äà ñïèðàø èëè äà ïóñêàø ñúïîðòà íà êàêâèòî è äà å autorun-è è äð.
    Last edited by Softman; 17th May 2010 at 15:24.

  11. #11
    Registered User brnn's Avatar
    Join Date: Jun:2006
    Location: Ñîôèÿ
    Posts: 754
    Quote Originally Posted by Softman View Post
    ×å òî îòäàâíà èìà 100% åôåêòèâíè íà÷èíè äà çàùèòèø ôëàøîâåòå ñè îò âèðóñè, äîñòà ñà, íî åòî 2òà êîèòî ïîëçâàì àç:

    - ôëàø óñòðîéñòâî ñ êëþ÷ çà read-only

    - (òàçè êîìàíäà ïðàâè ôàéë ñ íóëè, êîéòî çàåìà öÿëîòî ñâîáîäíî ïðîñòðàíñòâî íà ôëàø äðàéâà, çà äà íÿìà êúäå è êàê äà ïèøå âèðóñà, ðàçìåðà å ïðèìåðåí, ëåñíî ìîæå äà âèäèòå êîëêî ñâîáîäíè áàéòîâå èìàòå íà ôëàøà)

    Ðàçíàñÿì ñè 4 ôëàøà - 2 õ 16GB è 2 x 32GB - âèðóñè íÿìàì îò äà êàæà ãîäèíà ïî òÿõ êúäåòî è äà ãè ðú÷êàì
    Íå òè ñå íàëàãà äà ñïèðàø èëè äà ïóñêàø ñúïîðòà íà êàêâèòî è äà å autorun-è è äð.
    Àìà íå ìîæåø äà èìàø ïðåíîñèìè ïðîãðàìè, êîèòî äà ïóñêàø îò ôëàø ïàìåòòà.

  12. #12
    Registered User SeT's Avatar
    Join Date: Aug:2002
    Location: Sofia
    Posts: 6,865
    Òîçè ôàéë äåòî ãî ñúçäàâàø âëèÿå ëè àêî èñêàì äà äîáàâÿ èëè èçòðèÿ íåùî, òðÿáâà ëè äà ãî ïðîìåíÿì ïðåäè/ñëåä òîâà ?

  13. #13
    Banned
    Join Date: Oct:2003
    Location: Ñîôèÿ
    Posts: 5,259
    Quote Originally Posted by SeT View Post
    Òîçè ôàéë äåòî ãî ñúçäàâàø âëèÿå ëè àêî èñêàì äà äîáàâÿ èëè èçòðèÿ íåùî, òðÿáâà ëè äà ãî ïðîìåíÿì ïðåäè/ñëåä òîâà ?
    Àêî äîáàâÿø - ïðàâèø ãî íàíîâî (òðèåø ãî çà äà èìà ìÿñòî çà íîâèÿ ôàéë êîéòî èñêàø äà äîáàâèø)
    Àêî ìàõàø - ïðàâèø ãî íàíîâî (çàùîòî ùå èìà ñâîáîäíî ìÿñòî, êîåòî íèå íå èñêàìå äà èìà)
    Ñòàâà áúðçî, íî àêî ïèøåø/òðèåø 50 ïúòè íà äåí, ïî-äîáðå ñè âçåìè ñ êëþ÷ ôëàøà (8GB ñà 42ëâ â Ìóëòèðàìà)

  14. #14
    Registered User SeT's Avatar
    Join Date: Aug:2002
    Location: Sofia
    Posts: 6,865
    ßñíî, çàïúëâàìå âñè÷êîòî ìÿñòî çà äà íÿìà êúäå äà ñå çàïèøå âèðóñà.
    Àêî èñêàì äà èíñòàëèðàì íÿêàêâà ïðîãðàìà îò ôëàøêàòà è òÿ èñêà íÿêàêâî òåìï ìÿñòî âåðîÿòíî ùå ìè äàäå ãðåøêà, çà ôëàøêè ñàìî çà ÷åòåíå å ðåøåíèå.

  15. #15
    Registered User
    Join Date: Feb:2008
    Location: Ñîôèÿ
    Posts: 5,585
    Ñúùîòî êàòî è ïðè òåáå-êîïèðàò ñå íà êàêâàòî ôëàø ïàìåò èëè õàðä èì âêàðàø.Èíà÷å îò òèÿ ôëàø÷åòà íåùàòà êîèòî ñúì âèæäàë äà ïðàâÿò êàòî ïîðàçèè ñà äà çàáðàíÿâàò îïöèÿòà äà ñå âèæäàò ñêðèòèòå ôàéëîâå,ñïèðàò äîñòúïà äî ñàéòîâå íà àíòèâèðóñíè è ìàéêðîñîôò è ñëàãàò êàòî äåôîëòíà ,ïúðâà, îïöèÿ autorun íà õàðäîâåòå äà íå ìîæå äà ñå âëèçà ñ äâîåí êëèê.Çà äðóãî íå ñå ñåùàì â ìîìåíòà.

  16. #16
    Registered User Shnureaga's Avatar
    Join Date: Jun:2008
    Location: Ñòîëè÷íî
    Posts: 2,002
    Ïðîáâàé ñ Panda vaccine. Ïðåäîòâðàòÿâà àóòîðúíà íà ôëàøêèòå, ïî êîèòî íàé-÷åñòî âëèçàò âèðóñè.
    Asrock B450 Steel Legend / Ryzen 5 3600 stock w/ Jonsbo CR-1000 / TeamForce 32GB (4x8GB) 3200 MHz / SP 512GB + 14TB int & 10TB ext / ASRock RX 5600 XT Phantom Gaming 6GB OC / CM Silent Pro 700W / Acer V277 IPS @FullHD 75Hz + HP w2207 / Corsair 600T + 2x 200mm / Mad Catz R.A.T. TE / 'ñè÷êî ëàåðëåñ

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Copyright © 1999-2011 Õàðäóåð ÁÃ. Âúçìîæíî å ñúäúðæàíèåòî íà òàçè ñòðàíèöà äà å îáåêò íà àâòîðñêè ïðàâà.
iskamPC.com | mobility.BG | Bloody's Techblog | Êðèïòîâàëóòè è ìàéíèíã | 3D Vision Blog | Ìàãàçèí çà åëåêòðîííè öèãàðè