Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

problem sa virusom na flash kartici

[es] :: Zaštita :: problem sa virusom na flash kartici

[ Pregleda: 2249 | Odgovora: 4 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

gogi100
Goran Ljubic

Član broj: 40722
Poruke: 1064
87.250.47.*



+3 Profil

icon problem sa virusom na flash kartici11.04.2008. u 10:22 - pre 195 meseci
imam flash karticu od 1gb kingston. skenirao sam je sa antivirus programom mwav koji sadrzi najnovije definicije od 11.04.2008. pronasao mi je neke viruse na njoj i obrisao. kad sam ga opet ukljucio opet ponavlja isto izbacuje mi sledece.

Code:

File G:\auto.exe//PE_Patch//UPack infected by "Trojan-Downloader.Win32.Flux.fm" Virus! Action Taken: File Deleted.
File G:\autorun.inf infected by "Virus.Win32.AutoRun.mg" Virus! Action Taken: File Renamed.


flash karticu sam formatirao. Opet sam startovao mwav i opet izbacuje isto. da li zaista na kartici postoji virus ili to mwav brlja? i ako postoji kako da ga sklonim?
hvala
 
Odgovor na temu

Flash411

Član broj: 53039
Poruke: 1846
*.adsl.net.t-com.hr.

Jabber: flash411@jid.pl
ICQ: 296417234
Sajt: www.etfos.hr/~mgavlik/goo..


+4 Profil

icon Re: problem sa virusom na flash kartici11.04.2008. u 10:44 - pre 195 meseci
Takve viruse na karticu upisuje ili tvoje racunalo ili racunalo kod nekog drugoga kod
koga ubacujes karticu. Da bi eliminirali sumnju na tvoje racunalo,okaci ovdje hijackthis
log da pregledamo.
Gone insane,be right back..... | Malo drugacija google pretraga
http://poremecenum.blog.hr/ | http://www.etfos.hr/~mgavlik/googledirectorysearch/
____________________________________________________
Failure is not an option. It comes bundled with Windows.
 
Odgovor na temu

gogi100
Goran Ljubic

Član broj: 40722
Poruke: 1064
79.101.200.*



+3 Profil

icon Re: problem sa virusom na flash kartici11.04.2008. u 15:59 - pre 195 meseci
Hijacks log izgleda ovako


Logfile of HijackThis v1.99.1
Scan saved at 4:50:35 PM, on 4/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\mafija75\Desktop\virusi\TR3.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 127.255.255.255 www.getright.com
O1 - Hosts: 127.255.255.255 pro.getright.com
O1 - Hosts: 127.255.255.255 www.headlightinc.com
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [BMdbb61280] Rundll32.exe "C:\WINDOWS\system32\hmkllrgk.dll",s
O4 - HKLM\..\Run: [d885211c] rundll32.exe "C:\WINDOWS\system32\muygvtrw.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Program Files\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Prevedi sa Di recnikom - C:\Program Files\Di recnik\diie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: urqOGVpO - C:\WINDOWS\SYSTEM32\urqOGVpO.dll
O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe" -k runservice (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

mod:uklonjeni [ code ] tagovi zbog preglednosti

[Ovu poruku je menjao Flash411 dana 12.04.2008. u 12:16 GMT+1]
 
Odgovor na temu

Flash411

Član broj: 53039
Poruke: 1846
*.adsl.net.t-com.hr.

Jabber: flash411@jid.pl
ICQ: 296417234
Sajt: www.etfos.hr/~mgavlik/goo..


+4 Profil

icon Re: problem sa virusom na flash kartici12.04.2008. u 11:22 - pre 195 meseci
Sljedece unose popravi unutar hijackthis-a
O20 - Winlogon Notify: urqOGVpO - C:\WINDOWS\SYSTEM32\urqOGVpO.dll
O4 - HKLM\..\Run: [BMdbb61280] Rundll32.exe "C:\WINDOWS\system32\hmkllrgk.dll",s
O4 - HKLM\..\Run: [d885211c] rundll32.exe "C:\WINDOWS\system32\muygvtrw.dll",b

Za ovaj nisam siguran sta je,ako znas sta je i siguran si da je fajl ok,ostavi,u suprotnom-brisi.
C:\Documents and Settings\mafija75\Desktop\virusi\TR3.exe
Gone insane,be right back..... | Malo drugacija google pretraga
http://poremecenum.blog.hr/ | http://www.etfos.hr/~mgavlik/googledirectorysearch/
____________________________________________________
Failure is not an option. It comes bundled with Windows.
 
Odgovor na temu

[es] :: Zaštita :: problem sa virusom na flash kartici

[ Pregleda: 2249 | Odgovora: 4 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.