1   1  /  1  页   跳转

致baohe版主,英文原文,谢谢

致baohe版主,英文原文,谢谢

Download Killbox here: http://www.downloads.subratam.org/KillBox.exe and put it on your desktop

Then,,

Download CCleaner HERE and install it.

Before first use, check under Options, Settings, and ensure "Only delete files in Windows Temp folder older than 48 hours" is unchecked.

Then open it and select the items you wish to clean up.

In the Windows Tab:

I recommend cleaning all entries in the "Internet Explorer" section except Cookies.
Clean all the entries in the "Windows Explorer" section
Clean all entries in the "System" section
Clean all entries in the "Advanced" section.

In the Applications Tab:

Clean all except cookies in the Firefox/Mozilla section if you use it.
Clean all in the Opera section if you use it.
Clean Sun Java in the Internet Section.
Clean any others that you choose.

Then click the "Run Cleaner" button

Then,,

Please Download and Install Ewido --

1. Download Ewido security suite from http://download.ewido.net/ewido-setup.exe
2. After the download is complete, double click on the file to launch the install process.
3. During installation under the Additonal Options menu, you will be asked if you want to "Install background guard (required for automatic updates)" and "Install scan via context menu". Please UNCHECK both of these options.
4. Once installation is complete, launch Ewido by double-clicking the big "E" icon on your desktop. The program will prompt you to update -- click the 'OK' button.
5. The program will now go to the main screen. On the left hand side of the main screen, click on Update and then click 'Start Update'. The update will start and a progress bar will show the updates being installed. After the updates are installed, you will see 'Update Successful' in the lower left corner.

Once the updates are installed do the following:

Please reboot into Safemode:
Turn on the computer.
Immediately begin tapping the F8 key (or F5 on some computers)
Use the arrow keys to highlight Safe Mode and press the Enter key.

Then,,

Close all windows and fix the following with hijackthis:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http:///

R3 - Default URLSearchHook is missing

O4 - HKLM\..\Run: [hGVc0] C:\documents and settings\owner\local settings\temp\hGVc0.exe
O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe"
O4 - HKLM\..\Run: [lmu] C:\WINDOWS\LMU.exe
O4 - HKLM\..\Run: [SearchUpgrader] C:\Program Files\Common files\SearchUpgrader\SearchUpgrader.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitepbr32.exe
O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka62.exe
O4 - HKLM\..\Run: [System service63] C:\WINDOWS\etb\pokapoka63.exe
O4 - HKLM\..\Run: [System service65] C:\WINDOWS\etb\pokapoka65.exe
O4 - HKLM\..\Run: [System service66] C:\WINDOWS\etb\pokapoka66.exe
O4 - HKLM\..\Run: [System service67] C:\WINDOWS\etb\pokapoka67.exe

O16 - DPF: v3cab - http://searchmiracle.com/cab/v3cab.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/14779908b45...xIE601.cab

Then Open Ewido,,

1. Click on 'Scanner' (the 3rd bar from the top on the left) and Choose 'Settings'
2. Please make sure 'Scan Every File' is selected. Finally, please click 'OK'
3. On the main screen, please select 'Complete System Scan' and the scan should begin.
4. While the scan is in progress, you will be prompted to clean the first infected file it finds. Choose clean, then put a check next to 'Perform action on all infections' in the left corner of the box so you don't have to sit and watch Ewido the whole time. Click OK.
5. When the scan is complete, click "Save Report". You scan results will be saved in a textfile. Please submit that with your next post.

If during your scan Ewido "crashes" or "hangs", please try scanning again. Before running the scan, click on 'Scanner' (the 3rd bar from the top on the left) and Choose 'Settings'. Uncheck 'Scan in NTFS Alternate Data Streams' as this can cause problems in overly infected systems. Click 'OK' and then follow the instructions from step #8 again.

Exclamation Note: Ewido is a free trial product for 14 days. Since Ewido is a trial version, the realtime guard and automatic update will stop functioning after 14 days (which is the reason we uncheck them during installation). You can use Ewido as an on-demand scanner (recommended) but you will have to manually update the definition file each time you scan.

If you decide to purchase Ewido, you can enable the 'Realtime Protect' and 'Automatic Update' functions by clicking on the 'Status' bar (Top left) and clicking on both items under "Your Security Status".

Now close ewido security suite.

Then,,

Open Killbox

Click on Tools>Delete Temp Files

Then,,

Check the following boxes:

Unregister .dll before deleting (unless it is greyed out)
Delete on Reboot

Highlight the entries in the quote box below and then Copy & paste them ONE at a time into the Killbox topmost box.
Quote:

C:\documents and settings\owner\local settings\temp\hGVc0.exe
C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe
C:\WINDOWS\LMU.exe
C:\Program Files\Common files\SearchUpgrader\SearchUpgrader.exe
C:\windows\system32\elitepbr32.exe
C:\WINDOWS\etb\pokapoka62.exe
C:\WINDOWS\etb\pokapoka63.exe
C:\WINDOWS\etb\pokapoka65.exe
C:\WINDOWS\etb\pokapoka66.exe
C:\WINDOWS\etb\pokapoka67.exe


After pasting them into the topmost textbox. Click the Red X ...and for the confirmation message that will appear, you will need to click Yes

A second message will ask to Reboot now? you will need to click No until you have pasted the last file at which time you click yes.

Note: Killbox will let you know if the file does not exist.

After the reboot,

Scan and post another hijackthis log and the report from ewido.
最后编辑2005-09-16 16:54:09
分享到:
gototop
 

O4 - HKLM\..\Run: [System service65] C:\WINDOWS\etb\pokapoka65.exe
O4 - HKLM\..\Run: [System service66] C:\WINDOWS\etb\pokapoka66.exe
O4 - HKLM\..\Run: [System service67] C:\WINDOWS\etb\pokapoka67.exe
我的机器中也经常出现这样的东西。
gototop
 

【回复“E的老公”的帖子】
翻译完了。
累死我了!!得让你的“E”陪陪我!!!!


译文:


Killbox下载地址: http://www.downloads.subratam.org/KillBox.exe 下载后,放到桌面。
然后自上面同一地址下载 CCleaner并安装。

使用前,请检查 Options、Settings的设置,确保 "Only delete files in Windows Temp folder older than 48 hours" 没被勾选。

然后,打开TCCleaner,选定您要清除的项目。

在Windows 标签下:

建议您清除"Internet Explorer" 部分的所有项目 (除了 Cookies)。
清除 "Windows Explorer" 部分的所有项目。
清除"System"部分的所有项目
清除 "Advanced" 部分的所有项目。

在 Applications 标签下:

清除除 Firefox/Mozilla 的cookies以外的所有项目。
清除Opera 部分的所有项目。
清除 Internet Section中的Sun Java .
清除您选定的其它所有项目。
然后,点击 "Run Cleaner" 按钮。

然后请下载并安装 Ewido --

1. Ewido security suite 下载地址http://download.ewido.net/ewido-setup.exe
2. 下载完成后, 双击文件名进行安装d。
3. 安装过程中,在 Additonal Options 菜单中, 您须回答是否 安装 " background guard (用于自动更新)" 以及是否安装"scan via context menu(从内容菜单扫描)"。请不要选定这两个选项。
4. 安装结束后, 双击运行Ewido(桌面上带"E" 图标者)。T程序会提示您是否需要更新。请点击 'OK' 按钮。
5. 程序进入主屏。请点击主屏左侧的'Start Update'按钮.更新完成后,您会看到屏幕左下角显示'Update Successful' 的提示。

更新完成后,请进行以下操作:

重启到安全模式(开机 时 F8 键,用上下箭头键移动光标至Safe Mode,按回车。)

然后,关闭所有窗口,用hijackthis修复下列项目:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http:///

R3 - Default URLSearchHook is missing

O4 - HKLM\..\Run: [hGVc0] C:\documents and settings\owner\local settings\temp\hGVc0.exe
O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe"
O4 - HKLM\..\Run: [lmu] C:\WINDOWS\LMU.exe
O4 - HKLM\..\Run: [SearchUpgrader] C:\Program Files\Common files\SearchUpgrader\SearchUpgrader.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitepbr32.exe
O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka62.exe
O4 - HKLM\..\Run: [System service63] C:\WINDOWS\etb\pokapoka63.exe
O4 - HKLM\..\Run: [System service65] C:\WINDOWS\etb\pokapoka65.exe
O4 - HKLM\..\Run: [System service66] C:\WINDOWS\etb\pokapoka66.exe
O4 - HKLM\..\Run: [System service67] C:\WINDOWS\etb\pokapoka67.exe

O16 - DPF: v3cab - http://searchmiracle.com/cab/v3cab.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/14779908b45...xIE601.cab

然后,打开Ewido,,

1. 点击 'Scanner' ,选定 'Settings'
2. 确认 'Scan Every File' 被选定. 最后,点击 'OK'
3. 在程序主界面,请选择'Complete System Scan' ,扫描即开始。
4. 扫描过程中, 如果发现被感染的文件,您会得到清除被感染文件的提示。 请选 clean, 然后在临近'Perform action on all infections'后做选定记号 。
5. 扫描结束后,请点击 "Save Report"(保存报告). 报告以文本文件保存。

I扫描期间,如果 Ewido崩溃和挂起 ,请重新开始扫描。扫描前, 点击'Scanner' 并选定 'Settings'。 不要勾选'Scan in NTFS Alternate Data Streams'。

然后开启Killbox
点击:Tools>Delete Temp Files

然后选定下列设置:
Unregister .dll before deleting (unless it is greyed out)
Delete on Reboot

然后,将下列文件逐一粘贴到KILLBOX的引用窗口中:


C:\documents and settings\owner\local settings\temp\hGVc0.exe
C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe
C:\WINDOWS\LMU.exe
C:\Program Files\Common files\SearchUpgrader\SearchUpgrader.exe
C:\windows\system32\elitepbr32.exe
C:\WINDOWS\etb\pokapoka62.exe
C:\WINDOWS\etb\pokapoka63.exe
C:\WINDOWS\etb\pokapoka65.exe
C:\WINDOWS\etb\pokapoka66.exe
C:\WINDOWS\etb\pokapoka67.exe


每粘贴一个文件,点击一下红色的X ...此后,会显示确认信息,请点击 Yes。

此后会提问是否现在就重启 ( Reboot now? ),请点击 No,直到一一删除所有待删文件 。最后一次询问 Reboot now?时,请点击 yes。

注: Killbox会提示您待删除文件是否存在。

重启系统

贴上再次扫描hijackthis日志。
gototop
 

感谢ing
gototop
 

翻译的很好呀~~是pokapoka67.exe ,呵呵
gototop
 

呵呵,班竹厉害。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT