UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; InfoPath.1; UserABC123)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
File::
c:\windows\system32\drivers\hkfcv.sys
c:\windows\system32\drivers\sjcebdq.sys
c:\windows\Tasks\AppleSoftwareUpdate.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
Driver::
hkfcv
sjcebdq
gupdate
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=-
"nwiz"=-
"QPService"=-
"HP Software Update"=-
"QlbCtrl"=-
"Cpqset"=-
"Acrobat Assistant 8.0"=-
"High Definition Audio Property Page Shortcut"=-
"AdobeCS4ServiceManager"=-
"EverioService"=-
"CloneCDTray"=-
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hkfcv]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sjcebdq]
UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; InfoPath.1; UserABC123)
UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; InfoPath.1; UserABC123)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
Files to delete:
c:\documents and settings\LocalService\Application Data\jasltw.dat
UA: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
Skad w ogole taki syf sie bierze w komputerze i jak sprawdzic co to bylo, tak aby zaspokoic ciekawosc
UA: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
No action taken.
UA: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Zarejestrowani użytkownicy: Bing [Bot]