onetruelove
Youtube Master Race
- 17/1/06
- 29
- 0
Máy tớ bị nhiễm nặng lắm rồi. Quét virus thì k thấy gì hết. Quét spyware thì ra một đống. Tớ vào safemode quét, tắt luôn system restore quét. Dùng Spy Remover quét xong thì nó bảo có mấy cái không fix được. Phải restart. Restart thì nó hiện ra chương trình spy pot gì đó giống giống spy remover. Quét thì nó báo lỗi phải tắt! Tự nhiên trong ổ C xuất hiện các floder lạ như : Network monitor, Deskbar,... còn nữa mà quên.
--- Search result list ---
CoolWWWSearch: IE Search page (Registry change, fixed)
HKEY_USERSS-1-5-21-789336058-1767777339-839522115-1004\Software\Microsoft\Internet Explorer\Main\Search Page=about:blank
CoolWWWSearch: IE Search page (Registry change, fixed)
HKEY_USERSS-1-5-21-789336058-1767777339-839522115-1004\Software\Microsoft\Internet Explorer\Main\Search Bar=about:blank
CoolWWWSearch: IE start page (Registry change, fixed)
HKEY_USERSS-1-5-21-789336058-1767777339-839522115-1004\Software\Microsoft\Internet Explorer\Main\Start Page=about:blank
CoolWWWSearch: IE Search page (Registry change, fixed)
HKEY_USERSS-1-5-21-789336058-1767777339-839522115-1004\Software\Microsoft\Internet Explorer\Main\Default_Search_URL=about:blank
CoolWWWSearch: IE Search page (Registry change, fixed)
HKEY_USERSS-1-5-21-789336058-1767777339-839522115-1004\Software\Microsoft\Internet Explorer\Search\SearchAssistant Explorer\Main\Default_Search_URL=about:blank
CoolWWWSearch: IE Search page (Registry change, fixed)
HKEY_LOCAL_MACHINESoftware\Microsoft\Internet Explorer\Main\Search Page=about:blank
CoolWWWSearch: IE Search page (Registry change, fixed)
HKEY_LOCAL_MACHINESoftware\Microsoft\Internet Explorer\Search\SearchAssistant=about:blank
Command Service: Temporary file (File, fixed)
C:\WINDOWS\system32\atmtd.dll.tmp
Command Service: Data (File, fixed)
C:\windows\newname.dat
Command Service: Autorun settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\newname
Command Service: Program file (File, fixing failed)
c:\\nwnmff_18.exe
Command Service: Uninstall settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}
Look2Me.Topconverting: Temporary file (File, fixed)
C:\WINDOWS\system32\guard.tmp
Smitfraud-C.: Executable (File, fixed)
c:\drsmartload.exe
Smitfraud-C.: Executable (File, fixed)
c:\drsmartload45a45r.exe
Smitfraud-C.: Executable (File, fixed)
c:\drsmartload46a46r.exe
Smitfraud-C.: Executable (File, fixed)
c:\drsmartload849a849r.exe
Smitfraud-C.: Settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
Smitfraud-C.: Settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\{645FF040-5081-101B-9F08-00AA002F954E}
Smitfraud-C.: Data (File, fixed)
c:\windows\teller2.chk
Smitfraud-C.: Executable (File, fixed)
c:\MTE3NDI6ODoxNg.exe
Network Monitor: Executable (File, fixed)
C:\Program Files\Network Monitor\netmon.exe
Network Monitor: Data (File, fixed)
C:\WINDOWS\uninstall_nmon.vbs
Network Monitor: Uninstall settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}
Network Monitor: <$REG_SERVICE> (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Network Monitor
Network Monitor: <$REG_SERVICE> (Registry key, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Network Monitor
Network Monitor: Program directory (Directory, fixing failed)
C:\Program Files\Network Monitor\
Windows.Security.InternetExplorer: Settings (Registry change, fixed)
HKEY_USERS\S-1-5-21-789336058-1767777339-839522115-1004\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe!=W=1
Tớ in đậm mấy cái mà fix k được.
Hu hu có ai chỉ cách diệt mấy con này không.
--- Search result list ---
CoolWWWSearch: IE Search page (Registry change, fixed)
HKEY_USERSS-1-5-21-789336058-1767777339-839522115-1004\Software\Microsoft\Internet Explorer\Main\Search Page=about:blank
CoolWWWSearch: IE Search page (Registry change, fixed)
HKEY_USERSS-1-5-21-789336058-1767777339-839522115-1004\Software\Microsoft\Internet Explorer\Main\Search Bar=about:blank
CoolWWWSearch: IE start page (Registry change, fixed)
HKEY_USERSS-1-5-21-789336058-1767777339-839522115-1004\Software\Microsoft\Internet Explorer\Main\Start Page=about:blank
CoolWWWSearch: IE Search page (Registry change, fixed)
HKEY_USERSS-1-5-21-789336058-1767777339-839522115-1004\Software\Microsoft\Internet Explorer\Main\Default_Search_URL=about:blank
CoolWWWSearch: IE Search page (Registry change, fixed)
HKEY_USERSS-1-5-21-789336058-1767777339-839522115-1004\Software\Microsoft\Internet Explorer\Search\SearchAssistant Explorer\Main\Default_Search_URL=about:blank
CoolWWWSearch: IE Search page (Registry change, fixed)
HKEY_LOCAL_MACHINESoftware\Microsoft\Internet Explorer\Main\Search Page=about:blank
CoolWWWSearch: IE Search page (Registry change, fixed)
HKEY_LOCAL_MACHINESoftware\Microsoft\Internet Explorer\Search\SearchAssistant=about:blank
Command Service: Temporary file (File, fixed)
C:\WINDOWS\system32\atmtd.dll.tmp
Command Service: Data (File, fixed)
C:\windows\newname.dat
Command Service: Autorun settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\newname
Command Service: Program file (File, fixing failed)
c:\\nwnmff_18.exe
Command Service: Uninstall settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}
Look2Me.Topconverting: Temporary file (File, fixed)
C:\WINDOWS\system32\guard.tmp
Smitfraud-C.: Executable (File, fixed)
c:\drsmartload.exe
Smitfraud-C.: Executable (File, fixed)
c:\drsmartload45a45r.exe
Smitfraud-C.: Executable (File, fixed)
c:\drsmartload46a46r.exe
Smitfraud-C.: Executable (File, fixed)
c:\drsmartload849a849r.exe
Smitfraud-C.: Settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
Smitfraud-C.: Settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\{645FF040-5081-101B-9F08-00AA002F954E}
Smitfraud-C.: Data (File, fixed)
c:\windows\teller2.chk
Smitfraud-C.: Executable (File, fixed)
c:\MTE3NDI6ODoxNg.exe
Network Monitor: Executable (File, fixed)
C:\Program Files\Network Monitor\netmon.exe
Network Monitor: Data (File, fixed)
C:\WINDOWS\uninstall_nmon.vbs
Network Monitor: Uninstall settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}
Network Monitor: <$REG_SERVICE> (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Network Monitor
Network Monitor: <$REG_SERVICE> (Registry key, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Network Monitor
Network Monitor: Program directory (Directory, fixing failed)
C:\Program Files\Network Monitor\
Windows.Security.InternetExplorer: Settings (Registry change, fixed)
HKEY_USERS\S-1-5-21-789336058-1767777339-839522115-1004\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe!=W=1
Tớ in đậm mấy cái mà fix k được.
Hu hu có ai chỉ cách diệt mấy con này không.


