UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
O4 - HKLM\\..\\Run: [SDFix] C:\\SDFix\\RunThis.bat /second
O4 - HKLM\\..\\Run: [combofix] C:\\WINDOWS\\system32\\CF21356.exe /c C:\\ComboFix\\Combobatch.bat
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
Files to delete:
c:\windows\system32\CF21356.exe
C:\autorun.inf
c:\windows\PEV.exe
Folders to delete:
c:\windows\system32\ED162B
c:\windows\system32\BDD55D
c:\windows\system32\A01FDB
c:\windows\system32\2C079A
Drivers to delete:
Memctl
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
ComboFix.exe/data002\32788R22FWJFW\FIND3M.bat R:\ComboFix.exe/data002 Prawdopodobnie BATCH.Virus
data002 R:\ Archiwum zawierające zainfekowane obiekty
ComboFix.exe R:\ Kontener zawiera zainfekowane obiekty Przeniesiony.
A0001096.exe/data002\32788R22FWJFW\FIND3M.bat R:\System Volume Information\_restore{7B5A35F0-C8DC-48ED-868B-E56225E1FB8D}\RP1\A0001096.exe/data002 Prawdopodobnie BATCH.Virus
data002 R:\System Volume Information\_restore{7B5A35F0-C8DC-48ED-868B-E56225E1FB8D}\RP1 Archiwum zawierające zainfekowane obiekty
A0001096.exe R:\System Volume Information\_restore{7B5A35F0-C8DC-48ED-868B-E56225E1FB8D}\RP1 Kontener zawiera zainfekowane obiekty Przeniesiony.
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
Zarejestrowani użytkownicy: Bing [Bot]