UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; InfoPath.2; .NET CLR 3.5.30729; Maxthon 2.0)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.15) Gecko/20110303 Firefox/3.6.15
:OTL
O33 - MountPoints2\{f9e77a78-ad38-11df-9b55-0080c6e9ea65}\Shell\AutoRun\command - "" = F:\nekpukne\\\sveinapusti.exe
O33 - MountPoints2\{f9e77a78-ad38-11df-9b55-0080c6e9ea65}\Shell\explore\command - "" = F:\nekpukne\\\sveinapusti.exe
O33 - MountPoints2\{f9e77a78-ad38-11df-9b55-0080c6e9ea65}\Shell\Install\command - "" = F:\nekpukne\\\sveinapusti.exe
O33 - MountPoints2\{f9e77a78-ad38-11df-9b55-0080c6e9ea65}\Shell\open\command - "" = F:\nekpukne\\\sveinapusti.exe
O33 - MountPoints2\{6b8534dd-a94b-11df-9b45-0080c6e9ea65}\Shell\AutoRun\command - "" = F:\i00dvoym.exe
O33 - MountPoints2\{6b8534dd-a94b-11df-9b45-0080c6e9ea65}\Shell\open\Command - "" = F:\i00dvoym.exe
O33 - MountPoints2\{d7b2911e-3b19-11de-87ab-806d6172696f}\Shell - "" = AutoRun
[2011-03-14 09:59:58 | 000,017,878 | -H-- | M] () -- C:\WINDOWS\System32\vcmgcd32.dl_
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; InfoPath.2; .NET CLR 3.5.30729; Maxthon 2.0)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.15) Gecko/20110303 Firefox/3.6.15
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; InfoPath.2; .NET CLR 3.5.30729; Maxthon 2.0)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.15) Gecko/20110303 Firefox/3.6.15 ( )
Krok 4. Czyszczenie rejestrów z zainfekowanych komputerów w sieci domeny:
* pobierz ten plik Sality_RegKeys.zip
* rozpakuj go Sality_RegKeys.zip
* uruchom plik Disable_autorun.reg z archiwum Sality_RegKeys.zip
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.15) Gecko/20110303 Firefox/3.6.15
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; InfoPath.2; .NET CLR 3.5.30729; Maxthon 2.0)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.15) Gecko/20110303 Firefox/3.6.15
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; InfoPath.2; .NET CLR 3.5.30729; Maxthon 2.0)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.15) Gecko/20110303 Firefox/3.6.15
:OTL
:Files
C:\Documents and Settings\PC\Menu Start\Programy\Autostart\SalityKiller.lnk
C:\Documents and Settings\PC\fswagz.exe
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Taskman"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; InfoPath.2; .NET CLR 3.5.30729; Maxthon 2.0)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.15) Gecko/20110303 Firefox/3.6.15
Files to delete:
C:\Documents and Settings\PC\fswagz.exe
Registry values to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Taskman
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; InfoPath.2; .NET CLR 3.5.30729; Maxthon 2.0)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.15) Gecko/20110303 Firefox/3.6.15 ( )
Zarejestrowani użytkownicy: Bing [Bot]