02 Sie 2008, 22:57
03 Sie 2008, 05:54
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BSMediaBar.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
File::
C:\Program Files\BearShare Applications\BearShare MediaBar
zapisz jako
CFScript.txt (najwygodniej będzie, jeśli zapiszesz w takiej lokalizacji, by ikonka CFScript.txt znalazła się obok ikonki ComboFix.exe)
03 Sie 2008, 11:13
Folder::
C:\Program Files\BearShare Applications\BearShare MediaBar
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D023EBF-70B8-45A6-9ED5-556515FA0FE4}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=-
"Skype"=-
"ctfmon.exe"=-
"Orb"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"=-
"NeroFilterCheck"=-
"SunJavaUpdateSched"=-
"QuickTime Task"=-
"iTunesHelper"=-
"nwiz"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1cc459af-2a0d-11dc-b42d-b7d550e7ec01}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{244e60e6-2b1b-11dc-896b-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d2fac40-2b90-11dc-b4c0-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{32de3ee6-2a6d-11dc-afe9-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a02f90c-2b06-11dc-b19d-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4db8f705-2bcc-11dc-b4c2-8af57bed1007}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b131c0c-2afd-11dc-a69f-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{87ab011d-8ac5-11dc-b94e-abc003a82f00}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ba091ec2-887f-11dc-89c5-fd7a75b2c901}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c141c8e6-2a4b-11dc-9307-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c4dff58c-2afe-11dc-ae77-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd0d25d9-233f-11dc-980c-e4267bca4c00}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d361f565-2733-11dc-901e-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc2ca340-2b10-11dc-952e-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fad159c0-88b8-11dc-b944-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fad159c2-88b8-11dc-b944-a0f5ca5c3900}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fb029e9a-2a21-11dc-b742-806d6172696f}]
zapisz jako
CFScript.txt (najwygodniej będzie, jeśli zapiszesz w takiej lokalizacji, by ikonka CFScript.txt znalazła się obok ikonki ComboFix.exe)
03 Sie 2008, 12:16
Windows Registry Editor Version 5.00
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1cc459af-2a0d-11dc-b42d-b7d550e7ec01}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{244e60e6-2b1b-11dc-896b-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d2fac40-2b90-11dc-b4c0-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{32de3ee6-2a6d-11dc-afe9-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a02f90c-2b06-11dc-b19d-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4db8f705-2bcc-11dc-b4c2-8af57bed1007}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b131c0c-2afd-11dc-a69f-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{87ab011d-8ac5-11dc-b94e-abc003a82f00}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ba091ec2-887f-11dc-89c5-fd7a75b2c901}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c141c8e6-2a4b-11dc-9307-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c4dff58c-2afe-11dc-ae77-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd0d25d9-233f-11dc-980c-e4267bca4c00}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d361f565-2733-11dc-901e-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc2ca340-2b10-11dc-952e-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fad159c0-88b8-11dc-b944-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fad159c2-88b8-11dc-b944-a0f5ca5c3900}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fb029e9a-2a21-11dc-b742-806d6172696f}]
Plik
Zapisz jako
Zmień rozszerzenie z .txt na wszystkie pliki
zapisz pod nazwą Fix.reg 03 Sie 2008, 13:04
03 Sie 2008, 13:20
03 Sie 2008, 15:48
03 Sie 2008, 15:49
03 Sie 2008, 16:21
Files to delete:
C:\Documents and Settings\Jurek\Pulpit\1Sniffing-GG-UAP-inne.zip
C:\Program Files\SnadBoy's Revelation v2\Revelation.exe
C:\Program Files\SnadBoy's Revelation v2\RevelationHelper.dll
03 Sie 2008, 17:42
03 Sie 2008, 17:43
03 Sie 2008, 18:22
04 Sie 2008, 09:44