<<新主題 | 舊主題>>
娛樂滿紛 26FUN » 電腦區 » Help from spyware infection
返回列表 回復 發帖
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]

the other 2 items inside
"force active desktop on"  have  0X0000001 (1)
"no driver typpe autorun" have  0x000091 (145)

does that have probelm?
O4 - HKLM\..\Run: [TFNF5] TFNF5. exe
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar. exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK. exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY. EXE
O4 - HKLM\..\Run: [TFncKy] TFncKy. exe /Type 01
O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001. exe"
——i scanned, and cliked those item and click fix checked, it said i will permanantly remove those item..so i clicked no....,指上面呢幾個?呢幾個係咩SOFTWARE,你知唔知。
導出(EXPORT)/導入(IMPORT),喺註冊表編輯器嘅“REGISTRY(註冊表)”嗰度。


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"force active desktop on"  have  0X0000001 (1)
—— 改為0,睇下得唔得

PS:desktop background cannot be changed,具體係點?喺DESKTOP,RIGHT CLICK MOUSE,SELECT“PROPERTISE”,有冇“BACKGROUND”呢項?
http://filehost.to/files/2005-11-30_02/102358_faeuste_ballen.gif
http://filehost.to/files/2005-11-30_02/102807_vtffani.gif
http://www3.filehost.to/files/2006-02-22_01/055823_00000001.gif
for the desktop problem
i can open the propoerties, but it doesen't me to select other background from the list
i can click change colour but even i click apply , don't have effect
but change screensavers etc is ok

when i just got infected. the desktop change to blue with a large textbox saying  SPYWARE INFECTION. and cannot change background

after i used some other software , microsoft anti-spyware , norton etc to scan and remove the infected files , the desktop become white in background but still cannot change

[ Last edited by 147ak477 on 2006-1-15 at 11:59 AM ]
for the filter-031, those files doesn't seem familiar to me
i open registry and can see the functions to import and export

does that mean i should export one set of thoses filter-031 files to one location as backup?
then delete the orignal ones ?

also if change registy do i need to restart to take effect?
WHAT ABOUT THIS
HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurentVersion\\Policies\\Explores
“No Save Setting”若1 ,改為0

pop-up,maybe this one
O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001. exe"

#12嗰幾個software,知唔知係咩嚟。

[ Last edited by gergermen on 2006-1-15 at 12:13 PM ]
http://filehost.to/files/2005-11-30_02/102358_faeuste_ballen.gif
http://filehost.to/files/2005-11-30_02/102807_vtffani.gif
http://www3.filehost.to/files/2006-02-22_01/055823_00000001.gif
do not have “No Save Setting” in that folder ...


the names in #12 doesn't look familiar to me

[ Last edited by 147ak477 on 2006-1-15 at 12:16 PM ]
REG:system.ini: Shell=explorer. exe                                                                                                    "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001. exe"
HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001. exe"
——喺註冊表同呢個文件del曬佢。如果唔知,用HIJACKTHIS修復

HKLM\..\Run: [drsmartloadb] c:\\drsmartloadbfilter-031 —— 有冇掃過毒,呢個亦有可能,入註冊表,DEL咗呢項。

Winlogon Notify: Installer - C:\WINDOWS\system32\irl6l53s1.dll —— 呢個不少少懷疑?但唔肯定
http://filehost.to/files/2005-11-30_02/102358_faeuste_ballen.gif
http://filehost.to/files/2005-11-30_02/102807_vtffani.gif
http://www3.filehost.to/files/2006-02-22_01/055823_00000001.gif
Originally posted by gergermen at 2006-1-15 12:31 PM:
REG:system.ini: Shell=explorer. exe...
deleted all of them lu
see if it works
still have popo-ups
Originally posted by 147ak477 at 2006-1-15 15:26:
still have popo-ups
唔係啩~~~

CAP張圖睇下(下面幾張)

彈出嚟嘅係咩內容/ TASK MANAGER /  
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\启动

OR
用HIJACKTHIS再掃一次

[ Last edited by gergermen on 2006-1-15 at 03:58 PM ]
http://filehost.to/files/2005-11-30_02/102358_faeuste_ballen.gif
http://filehost.to/files/2005-11-30_02/102807_vtffani.gif
http://www3.filehost.to/files/2006-02-22_01/055823_00000001.gif
返回列表 回復 發帖
<<新主題 | 舊主題>>
娛樂滿紛 26FUN » 電腦區 » Help from spyware infection

重要聲明:26fun.com為一個討論區服務網站。本網站是以即時上載留言的方式運作,26fun.com對所有留言的真實性、完整性及立場等,不負任何法律責任。而一切留言之言論只代表留言者個人意見,並非本網站之立場,用戶不應信賴內容,並應自行判斷內容之真實性。於有關情形下,用戶應尋求專業意見(如涉及醫療、法律或投資等問題)。 由於本討論區受到「即時上載留言」運作方式所規限,故不能完全監察所有留言,若讀者發現有留言出現問題,請聯絡我們。26fun.com有權刪除任何留言及拒絕任何人士上載留言,同時亦有不刪除留言的權利。切勿撰寫粗言穢語、誹謗、渲染色情暴力或人身攻擊的言論,敬請自律。本網站保留一切法律權利。