主題: 教我一下
查看單個文章
舊 2005-01-31, 03:38 AM   #2 (permalink)
adulttw
註冊會員
 
adulttw 的頭像
榮譽勳章
UID - 75630
在線等級: 級別:1 | 在線時長:11小時 | 升級還需:1小時
註冊日期: 2003-06-09
VIP期限: 2007-04
住址: Limbo
文章: 1176
精華: 0
現金: 1818 金幣
資產: 1818 金幣
預設

字可以小一點啦~

我翻了外國的解決方法 試試吧
下載HijackThis
http://www.greyknight17.com/spy/HijackThis.exe

Make sure to close any open browsers.
確定關閉所有的瀏覽器視窗(我看所有視窗都關閉比較保險)

Go into HijackThis->Config->Misc. Tools->Open process manager.
(照著步驟操作HijackThis)

Select the following and click Kill process for each one if they are still listed (they shouldn't be - but double check it):
選取底下的列出的所有程序
各別選取後 選kill process
(或許下面的程序不會全部出現 建議多做幾次)

就是底下這些程序
C:\Program Files\NaviSearch\bin\nls.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\Program Files\CashBack\bin\cashback.exe



Uninstall the following via the Add/Remove Panel (Start->(Settings)->Control Panel->Add/Remove Programs) if they exist:
去控制台中的"新增/移除"
如果有出現下面的程式 請移除


下面的這些程式
CashBack
BullsEye Network
NaviSearch
SpywareRemover - it’s rogueware and we highly recommend that you uninstall it. Rogue/Suspect means that these products are of unknown, questionable, or dubious value as anti-spyware protection.


Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any)

然後再執行HijackThis
這次選底下的scan 然後把下面這些框框打勾後
選"fix checked"


就是底下這些框框要選
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/googlesidesearch.html
R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {30A56549-9D5B-4D34-AFA7-440A7F0538A9} - (no file)
O2 - BHO: (no name) - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINNT\System32\nvms.dll
O2 - BHO: (no name) - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINNT\System32\mscb.dll
O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINNT\System32\msbe.dll
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKCU\..\Run: [BPSANTISPY] C:\Program Files\BulletProofSoft.com\SpywareRemover\Spyware.e xe /STARTUP
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/259747b8fc6b3a...tzip/RdxIE2.cab
O16 - DPF: {E62A47D8-74B1-4A93-963A-E5E43B7CC5C2} - http://www.zuvio.com/UCSearch.CAB



Reboot into Safe Mode (hit F8 key until menu shows up).
重新開機 按F8進入安全模式

Delete the following Files/Folders (delete folders if no filename is specified) according to their directory (if none, just do a search for them) and delete them if they exist:
刪除底下這些檔案和資料夾


C:\Program Files\NaviSearch\
C:\Program Files\BullsEye Network\
C:\Program Files\CashBack\
C:\WINNT\System32\nvms.dll
C:\WINNT\System32\mscb.dll
C:\WINNT\System32\msbe.dll
C:\Program Files\BulletProofSoft.com\
c:\counter.cab


Reboot into Normal Mode and post a new HijackThis log file so we can make sure it's clean.

再重新開機
用HijackThis再檢查一下



大體上是這樣
可能翻譯得很差 試試看吧
adulttw 目前離線  
送花文章: 0, 收花文章: 7 篇, 收花: 8 次
回覆時引用此帖