Nod mi wykryl trojana Kryptik.XL w pliku userinit.exe i nie moze go usunac. Oto logi z hijackthis i otl
http://wklej.eu/index.php?id=50d608f6bc
http://wklej.eu/index.php?id=733ac40e3f
Pomozcie dobrzy ludzie

Pozdrawiam
UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2
FCopy::
c:\userinit.exe | c:\winnt\system32\userinit.exe
c:\userinit.exe | c:\winnt\system32\dllcache\userinit.exe
c:\beep.sys | c:\winnt\system32\drivers\beep.sys
c:\beep.sys | c:\winnt\system32\dllcache\beep.sys
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"=-
"Odkurzacz-MCD"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LanguageShortcut"=-
"Adobe Reader Speed Launcher"=-
"QuickTime Task"=-
"SoundMan"=-
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2
Files to delete:
c:\winnt\Internet Logs\xDB2.tmp
c:\winnt\Internet Logs\xDB1.tmp
c:\winnt\Internet Logs\xDB3.tmp
Files to move:
c:\userinit.exe | c:\winnt\system32\userinit.exe
c:\userinit.exe | c:\winnt\system32\dllcache\userinit.exe
c:\beep.sys | c:\winnt\system32\drivers\beep.sys
c:\beep.sys | c:\winnt\system32\dllcache\beep.sys
UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2
UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2
EXPAND X:\i386\USERINIT.EX_ C:\WINNT\SYSTEM32
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20 (.NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2
Folder::
c:\recycler
c:\program files\MyPlayCity
c:\windows\temp
File::
C:\mtyfncck.exe
C:\lqjbmsj.exe
C:\higlc.exe
C:\ilyuoeyw.exe
C:\delnis.bat
c:\documents and settings\Admin\Menu Start\Programy\Autostart\ihaupd32.exe
c:\documents and settings\Admin\Menu Start\Programy\Autostart\uecupd32.exe
Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}"=-
[-HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}"=-
[-HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{4724C5D8-DFA7-417A-A2F5-1EABFEE9B4AC}"=-
[-HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"=-
"H/PC Connection Agent"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"=-
"NeroCheck"=-
"WheelMouse"=-
"SunJavaUpdateSched"=-
"High Definition Audio Property Page Shortcut"=-
"nwiz"=-
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników