- Codice: Seleziona tutto
Driver::
cvjser5usjfyigsfhjhswybn4wgss80
dfgdjhse5rjfmkfsderhkldtd576ogd80;
ns6r4w84w35i4hq3h4jhq4wj64wqnasd80;
cvjser5usjfyigsfhjhswybn4wgss81
dfgdjhse5rjfmkfsderhkldtd576ogd81
ns6r4w84w35i4hq3h4jhq4wj64wqnasd81
File::
c:\windows\dfgdjhse5rjfmkfsderhkldtd576ogd81.exe
c:\windows\soc_1248896819.exe
c:\windows\[u]0[/u]10112010146118114.dat
c:\windows\ld10.exe
c:\windows\ns6r4w84w35i4hq3h4jhq4wj64wqnasd81.exe
c:\documents and settings\Administrator\system.exe
c:\windows\system32\xfpyalez.dll
c:\windows\system32\pbvcselg.dll
C:\lbpywwp.exe
c:\windows\system32\tsqsldkw.dat
c:\windows\system32\nmquddsw.dat
c:\windows\system32\ouxzaqin.dat
c:\windows\system32\jznytkcp.dat
C:\yjpyso.exe
C:\gbcjdrqu.exe
c:\windows\dfgdjhse5rjfmkfsderhkldtd576ogd81.exe
c:\windows\cvjser5usjfyigsfhjhswybn4wgss81.exe
c:\windows\system32\a247286bcfaf320fd2296054b4f5693b.sys
c:\windows\system32\_a247286bcfaf320fd2296054b4f5693b.sys_.vir
c:\windows\system32\48d27777c461b296554c5a7ec0d2d834.exe
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{000eb29f-90dd-41df-bca5-614124613bc6}]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"kell"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4af18a94-59d9-11de-abcb-00196638e0ce}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e57e710e-5b13-11de-abd5-00196638e0ce}]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\a247286bcfaf320fd2296054b4f5693b]
"ImagePath"=-
salvalo sul desktop con il nome obbligatorio di CFScript.txt
trascina con il puntatore del mouse sull'icona di combofix ; il programma avvierà una nuova scansione. Al termine di essa, riavvia e posta il nuovo report.