UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; PL; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12

UA: Opera/9.52 (Windows NT 5.1; U; pl)
File::
C:\Documents and Settings\ze\Ustawienia lokalne\Temp\~vis0000\fsg_4104.exe
E:\RECYCLER\S-1-5-21-1757981266-583907252-839522115-1003\De7.zip
E:\sty08\SoftCam_v.plug.2.2.0_v_keys by KM_AES Fix_BEV Fix_Seca Fix_Polsat _ Premiere all OK_03.04.2008.zip_UPLOAD.DVHK.PL.ZIP
E:\szefzapas\Pulpit\win32.bmp
Folder::
E:\System Volume Information\_restore{77FE4BEA-EDE2-416D-AE97-80ABD9F51DEB}\RP273
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"=-
"RemoteControl"=-
"NeroFilterCheck"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2f479680-c42f-11dc-96d2-000c763eda47}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7caa3b14-70ba-11dc-837b-000c763eda47}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b2ababb8-8791-11dc-8391-000c763eda47}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b2ababba-8791-11dc-8391-000c763eda47}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b3232764-480a-11dd-81a8-000c763eda47}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f2f66cc8-da23-11dc-8141-000c763eda47}]
zapisz jako
CFScript.txt (najwygodniej będzie, jeśli zapiszesz w takiej lokalizacji, by ikonka CFScript.txt znalazła się obok ikonki ComboFix.exe)


UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; PL; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12

UA: Opera/9.52 (Windows NT 5.1; U; pl)
Windows Registry Editor Version 5.00
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
Plik
Zapisz jako
Zmień rozszerzenie z .txt na wszystkie pliki
zapisz pod nazwą Fix.reg 
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; PL; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12

UA: Opera/9.52 (Windows NT 5.1; U; pl)

UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; PL; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12

UA: Opera/9.52 (Windows NT 5.1; U; pl)
Files to delete:
C:\Documents and Settings\ze\Ustawienia lokalne\Temp\~vis0000\fsg_4104.exe
E:\sty08\SoftCam_v.plug.2.2.0_v_keys by KM_AES Fix_BEV Fix_Seca Fix_Polsat _ Premiere all OK_03.04.2008.zip_UPLOAD.DVHK.PL.ZIP
E:\szefzapas\Pulpit\win32.bmp
Folders to delete:
E:\System Volume Information\_restore{77FE4BEA-EDE2-416D-AE97-80ABD9F51DEB}(2)\RP273

UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; PL; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12

UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; PL; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12

UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; PL; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12

UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; PL; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12

UA: Opera/9.60 (Windows NT 5.1; U; pl) Presto/2.1.1
File::
C:\Documents and Settings\Ja\Ustawienia lokalne\Temporary Internet Files\Content.IE5\OPKBCV03\v53[1].js
C:\Program Files\BPFTP Server\bpftpserver.exe
Folder::
C:\Recycled
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{93bea266-a6f8-11dc-aabc-00105a043e50}]
zapisz jako
CFScript.txt (najwygodniej będzie, jeśli zapiszesz w takiej lokalizacji, by ikonka CFScript.txt znalazła się obok ikonki ComboFix.exe)


Zarejestrowani użytkownicy: Bing [Bot]