史萊姆論壇

史萊姆論壇 (http://forum.slime.com.tw/)
-   一般電腦疑難討論區 (http://forum.slime.com.tw/f17.html)
-   -   教我一下 (http://forum.slime.com.tw/thread141221.html)

^Rico^ 2005-01-31 02:50 AM

教我一下
 
請問各位大大,教我一下:
在我的電腦桌面右下方有一隻常註程式,我也不知道那是何時裝的,只知道那是我不知何時去過那個網站就被裝上的小程式,程式的圖案是一隻小狗的圖型游標指向牠會出現CashBack pays you to shop!對牠按右鍵選About CashBack會出現一個網站http://www.cashbackbuddy.com/
我想把這隻常註程式給移除,但我不知道要如何去移除它,因為那是英文網站~我的英文很爛看不懂~請大大教我一下~謝謝~
:(

adulttw 2005-01-31 03:38 AM

字可以小一點啦~:)

我翻了外國的解決方法 試試吧
下載HijackThis
http://www.greyknight17.com/spy/HijackThis.exe

Make sure to close any open browsers.
確定關閉所有的瀏覽器視窗(我看所有視窗都關閉比較保險)

Go into HijackThis->Config->Misc. Tools->Open process manager.
(照著步驟操作HijackThis)

Select the following and click Kill process for each one if they are still listed (they shouldn't be - but double check it):
選取底下的列出的所有程序
各別選取後 選kill process
(或許下面的程序不會全部出現 建議多做幾次)

就是底下這些程序
C:\Program Files\NaviSearch\bin\nls.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\Program Files\CashBack\bin\cashback.exe



Uninstall the following via the Add/Remove Panel (Start->(Settings)->Control Panel->Add/Remove Programs) if they exist:
去控制台中的"新增/移除"
如果有出現下面的程式 請移除


下面的這些程式
CashBack
BullsEye Network
NaviSearch
SpywareRemover - it’s rogueware and we highly recommend that you uninstall it. Rogue/Suspect means that these products are of unknown, questionable, or dubious value as anti-spyware protection.


Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any)

然後再執行HijackThis
這次選底下的scan 然後把下面這些框框打勾後
選"fix checked"


就是底下這些框框要選
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/googlesidesearch.html
R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {30A56549-9D5B-4D34-AFA7-440A7F0538A9} - (no file)
O2 - BHO: (no name) - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINNT\System32\nvms.dll
O2 - BHO: (no name) - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINNT\System32\mscb.dll
O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINNT\System32\msbe.dll
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKCU\..\Run: [BPSANTISPY] C:\Program Files\BulletProofSoft.com\SpywareRemover\Spyware.e xe /STARTUP
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/259747b8fc6b3a...tzip/RdxIE2.cab
O16 - DPF: {E62A47D8-74B1-4A93-963A-E5E43B7CC5C2} - http://www.zuvio.com/UCSearch.CAB



Reboot into Safe Mode (hit F8 key until menu shows up).
重新開機 按F8進入安全模式

Delete the following Files/Folders (delete folders if no filename is specified) according to their directory (if none, just do a search for them) and delete them if they exist:
刪除底下這些檔案和資料夾


C:\Program Files\NaviSearch\
C:\Program Files\BullsEye Network\
C:\Program Files\CashBack\
C:\WINNT\System32\nvms.dll
C:\WINNT\System32\mscb.dll
C:\WINNT\System32\msbe.dll
C:\Program Files\BulletProofSoft.com\
c:\counter.cab


Reboot into Normal Mode and post a new HijackThis log file so we can make sure it's clean.

再重新開機
用HijackThis再檢查一下



大體上是這樣
可能翻譯得很差 試試看吧

^Rico^ 2005-01-31 04:48 PM

大大~謝啦~
 
大大~謝啦~


所有時間均為台北時間。現在的時間是 01:00 PM

Powered by vBulletin® 版本 3.6.8
版權所有 ©2000 - 2024, Jelsoft Enterprises Ltd.

『服務條款』

* 有問題不知道該怎麼解決嗎?請聯絡本站的系統管理員 *


SEO by vBSEO 3.6.1