Yuav ua li cas los soj ntsuam HijackThis Logs

Kev Tshawb Kho Sau Cov Ntaub Ntawv Tiv Thaiv Los Tshem Cov Tshem Tawm Cov Khaub Ncaws Spyware thiab Browser Hijackers

HijackThis yog ib qho cuab tam dawb los ntawm Trend Micro. Nws yog Ameslikas tsim los ntawm Merijn Bellekom, tus menyuam kawm ntawv hauv Netherlands. Spyware tshem tawm software xws li Adaware los yog Spybot S & D ua ib txoj hauj lwm zoo los nrhiav thiab tshem tawm feem ntau cov kev pabcuam spyware, tab sis qee qhov spyware thiab browser hijackers yog ib yam nkaus thiab insidious rau txawm tias cov kev pabcuam los tiv thaiv zoo heev.

HijackThis muab sau rau tshwjxeeb thiab tshem tawm lub browser hijacks, lossis software uas siv dua koj lub web browser, hloov koj lub vev xaib sab nrauv thiab nrhiav cav thiab lwm yam siab phem. Tsis zoo li cov raug anti-spyware software, HijackThis tsis siv kos npe los yog lub hom phiaj ntawm cov kev pabcuam tshwjxeeb lossis URL qhov txhom thiab thaiv. Theej, HijackThis zoo nkaus li rau lub tswv yim thiab txoj kev siv los ntawm malware los kis rau koj lub cev thiab rub koj tus browser.

Tsis yog txhua yam uas qhia hauv HijackThis cav yog khoom phem thiab nws yuav tsum tsis tag nrho yuav raug tshem tawm. Nyob rau hauv qhov tseeb, heev rov qab. Nws yuav luag lav paub tias qee yam ntawm cov khoom hauv koj HijackThis cav yuav yog ib qho yooj yim software thiab tshem cov khoom yuav cuam tshuam rau koj lub cev los yog ua kom tiav nws ua haujlwm tsis tiav. Siv HijackThis zoo li ntau qhov editing Windows Registry koj tus kheej. Nws tsis yog foob pob hluav taws kev kawm, tab sis koj yuav tsum tsis txhob ua nws tsis muaj kev cob qhia tshwj tsis yog koj yeej paub tias koj ua dab tsi.

Thaum koj nruab HijackThis thiab khiav nws los ua kom muaj cov ntaub ntawv cav, muaj ntau yam kev sib tham thiab qhov chaw uas koj tuaj yeem tso lossis xa koj cov ntaub ntawv teev cia. Cov kws kho mob uas paub tias yuav xyuas dab tsi yuav pab tau koj txheeb xyuas cov ntaub ntawv khaws tseg thiab tawm tswv yim rau koj seb yam khoom twg tshem tawm thiab cov twg yog cov uas tawm mus nyob ib leeg.

Yuav ua li cas mus download tau HijackThis version tam sim no, koj tuaj yeem mus xyuas lub chaw kawm ntawm Trend Micro.

Ntawm no yog cov ntsiab lus ntawm HijackThis nkag nkag uas koj siv tau los mus dhia mus rau cov ncauj lus uas koj tab tom nrhiav:

R0, R1, R2, R3 - IE Pib thiab Tshawb Nrhiav

Nws zoo li:
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Nplooj = http://www.google.com/
R1 - HKLM \ Software \ Microsoft \ InternetExplorer \ Main, Default_Page_URL = http://www.google.com/
R2 - (hom no tsis yog siv los ntawm HijackThis no)
R3 - Default URLSearchHook yog qhov uas ploj lawm

Yuav ua li cas:
Yog tias koj paub qhov URL ntawm qhov kawg thaum koj lub vas sab lossis kev tshawb fawb, nws zoo. Yog tias koj tsis ua, xyuas nws thiab muaj HijackThis txhim kho nws. Rau cov khoom R3, nco ntsoov kho lawv tshwj tsis yog tias nws hais txog qhov kev zov me nyuam koj pom, xws li Copernic.

F0, F1, F2, F3 - Autoloading cov kev pab cuam los ntawm INI ntaub ntawv

Nws zoo li:
F0 - system.ini: Plhaub = Explorer.exe Openme.exe
F1 - win.ini: khiav = hpfsched

Yuav ua li cas:
Cov khoom F0 yeej ib txwm phem, yog li kho lawv. Cov khoom F1 mas feem ntau cov kev pab cuam qub uas muaj kev ruaj ntseg, yog li koj yuav tsum nrhiav tau qee cov ntsiab lus ntxiv ntawm cov ntawv filename kom pom tias nws zoo los tsis zoo. Pacman's Startup List tuaj yeem pab nrog paub qhov khoom.

N1, N2, N3, N4 - Netscape / Mozilla Pib & Tshawb nrhiav

Nws zoo li:
N1 - Netscape 4: user_pref "browser.startup.homepage", "www.google.com"); (C: \ Program Files \ Netscape \ neeg \ default \ prefs.js)
N2 - Netscape 6: user_pref ("browser.startup.homepage", "http://www.google.com"); (C: \ Cov ntaub ntawv thiab chaw \ Cov neeg siv \ Daim ntaub ntawv \ Mozilla \ Profiles \ defaulto9t1tfl.slt \ prefs.js)
N2 - Netscape 6: user_pref ("browser.search.defaultengine", "engine: //C%3A%5CProgram%20Files%5CNetscape%206%5Csearchplugins%5CSBWeb_02.src"); (C: \ Cov ntaub ntawv thiab chaw \ Cov neeg siv \ Daim ntaub ntawv \ Mozilla \ Profiles \ defaulto9t1tfl.slt \ prefs.js)

Yuav ua li cas:
Feem ntau Netscape thiab Mozilla homepage thiab nplooj ntawv tshawb muaj kev nyab xeeb. Lawv tsis tshua raug hijacked, tsuas yog Lop.com tau paub tias ua li no. Koj yuav tsum pom ib tus URL uas koj tsis paub tias yog koj homepage los yog sab nraud, muaj HijackThis txhim kho nws.

O1 - Hostsfile redirections

Nws zoo li:
O1 - Hosts: 216.177.73.139 auto.search.msn.com
O1 - Hosts: 216.177.73.139 search.netscape.com
O1 - Hosts: 216.177.73.139 ieautosearch
O1 - Hosts cov ntaub ntawv nyob ntawm C: \ Windows \ Help \ hosts

Yuav ua li cas:
No hijack yuav redirect qhov chaw nyob rau sab xis rau IP chaw nyob rau sab laug. Yog tias tus IP tsis yog qhov chaw nyob, koj yuav raug xa mus rau qhov chaw tsis raug cai txhua zaus koj nkag mus rau qhov chaw nyob. Koj tuaj yeem yeej muaj HijackThis txhim kho cov no, tshwj tsis yog koj txhob txwm muab cov kab hauv koj cov ntaub ntawv Hosts.

Qho khoom kawg tau tshwm sim nyob rau hauv Windows 2000 / XP nrog Coolwebsearch kis kab mob. Nco ntsoov kho qhov khoom no, lossis muaj CWShredder kho nws li.

O2 - Browser Helper Objects

Nws zoo li:
O2 - BHO: Yahoo! Khub BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C: \ PROGRAM FILES \ YAHOO! COMPANION \ YCOMP5_0_2_4.DLL
O2 - BHO: (tsis muaj npe) - {1A214F62-47A7-4CA3-9D00-95A3965A8B4A} - C: \ PROGRAM FILES \ POPUP ELIMINATOR \ AUTODISPLAY401.DLL (ntaub ntawv ploj)
O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C: \ PROGRAM HAIS TXOG \ MEDIALOADS ENHANCED \ ME1.DLL

Yuav ua li cas:
Yog hais tias koj tsis ncaj qha rau lub npe Browser Helper Object lub npe, siv TonyK's BHO & Toolbar Daim ntawv mus nrhiav nws los ntawm hoob kawm ID (CLSID, tus najnpawb ntawm cov tsho kauj) thiab pom tias nws zoo lossis phem. Hauv BHO Sau, 'X' txhais tau hais tias spyware thiab 'L' txhais tau tias muaj kev ruaj ntseg.

O3 - IE toolbars

Nws zoo li:
O3 - Toolbar: & Yahoo! Sib Pua - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C: \ PROGRAM HAIS TXOG \ YHOO \ KEV TXHEEB \ YCOMP5_0_2_4.DLL
O3 - Toolbar: Popup Eliminator - {86BCA93E-457B-4054-AFB0-E428DA1563E1} - C: \ PROGRAM FILES \ POPUP ELIMINATOR \ PETOOLBAR401.DLL (ntaub ntawv ploj lawm)
O3 - Toolbar: rzillcgthjx - {5996aaf3-5c08-44a9-ac12-1843fd03df0a} - C: \ qhov \ APPLICATION DATA \ CKSTPRLLNQUL.DLL

Yuav ua li cas:
Yog hais tias koj tsis ncaj qha rau lub npe ntawm tus toolbar lub npe, siv TonyK's BHO & Toolbar Daim ntawv mus nrhiav nws los ntawm hoob kawm ID (CLSID, tus najnpawb ntawm cov tsho kauj) thiab pom tias nws zoo lossis phem. Hauv Toolbar List, 'X' txhais tau hais tias spyware thiab 'L' txhais tau tias muaj kev ruaj ntseg. Yog hais tias nws tsis nyob rau hauv daim ntawv thiab lub npe zoo li cov hlua ntawm cov cim thiab cov ntaub ntawv nyob rau hauv 'Daim Ntawv Thov Kev Siv' (zoo li qhov kawg hauv cov qauv saum toj no), nws yog Lop.com, thiab koj yuav tsum muaj HijackThis kho nws.

O4 - Autoloading cov kev pab cuam los ntawm Registry lossis Startup pab pawg

Nws zoo li:
O4 - HKLM \ .. \ Khiav: [ScanRegistry] C: \ WINDOWS \ scanregw.exe \ / autorun
O4 - HKLM \ .. \ Khiav: [SystemTray] SysTray.Exe
O4 - HKLM \ .. \ Khiav: [ccApp] \ "C: \ Cov ntaub ntawv \ Cov ntaub ntawv \ Symantec sib koom \ ccApp.exe"
O4 - Pib: Microsoft Office.lnk = C: \ Cov ntaub ntawv \ Microsoft Office \ Office \ OSA9.EXE
O4 - Thoob ntiajteb Startup: winlogon.exe

Yuav ua li cas:
Siv PacMan's Startup List mus nrhiav qhov nkag thiab pom tias nws zoo los tsis zoo.

Yog tias qhov khoom qhia tau hais tias ib qho kev pab cuam hauv lub Startup pab pawg (xws li cov khoom dhau los), HijackThis kho tsis tau qhov khoom yog qhov kev zov me nyuam tseem nco. Siv Windows Task Manager (TASKMGR.EXE) kaw cov txheej txheem ua ntej kho.

O5 - IE kev xaiv tsis pom nyob rau hauv Tswj Vaj Tse

Nws zoo li:
O5 - control.ini: inetcpl.cpl = tsis muaj

Yuav ua li cas:
Tshwj tsis yog tias koj lossis koj tus neeg ua haujlwm hauv tsev tau paub qhov teebmeem tawm ntawm lub Vajtse Pab Tswjhwm, muaj HijackThis txhim kho nws.

O6 - IE kev xaiv txwv kev txwv los ntawm Thawj Tswj Hwm

Nws zoo li:
O6 - HKCU \ Software \ Policies \ Microsoft \ Internet Explorer \ Restrictions present

Yuav ua li cas:
Tshwj tsis yog tias koj muaj Spybot S & D xaiv 'Ntsuas phoo homepage los ntawm kev hloov', los yog koj tus neeg khiav dej num hauv qhov chaw muab qhov no, muaj HijackThis txhim kho qhov no.

O7 - Regedit nkag tau txwv los ntawm Thawj Tswj Hwm

Nws zoo li:
O7 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System, DisableRegedit = 1

Yuav ua li cas:
Nco ntsoov HijackThis kho qhov no, tshwj tsis yog koj tus neeg saib xyuas kev ua haujlwm tau muab qhov kev txwv no rau hauv qhov chaw.

O8 - Ntxiv cov khoom nyob rau hauv IE txoj cai-nias lub tshuab raj

Nws zoo li:
O8 - Cov ntsiab lus ntawm lub ntsiab lus teb ntxiv: & Google Search - res: // C: \ WINDOWS \ DOWNLOADED PROGRAM FILES \ GOOGLETOOLBAR_EN_1.1.68-DELEON.DLL / cmsearch.html
O8 - Cov ntsiab lus ntawm lub ntsiab lus teb ntxiv: Yahoo! Tshawb nrhiav - cov ntaub ntawv: / / C: \ Program Files \ Yahoo! \ Common / ycsrch.htm
O8 - Cov ntsiab lus ntawm lub ntsiab lus teb ntxiv: Zoom & Hauv - C: \ WINDOWS \ WEB \ zoomin.htm
O8 - Ntaus ntsiab lus ntawm lub ntsiab lus teb: Zoom O & li - C: \ WINDOWS \ WEB \ zoomout.htm

Yuav ua li cas:
Yog hais tias koj tsis paub lub npe ntawm cov khoom nyob rau hauv txoj cai-nias lub tshuab raj IE, muaj HijackThis txhim kho nws.

O9 - Ntxiv nyees khawm ntawm lub ntsiab IE toolbar, lossis lwm yam khoom hauv IE & # 39; Cov cuab yeej & # 39; zaub mov

Nws zoo li:
O9 - Ntxiv khawm: Neeg xa xov liaison (HKLM)
O9 - Ntxiv 'Cuab Yeej': Neeg xa xov liaison (HKLM)
O9 - Ntxiv khawm: AIM (HKLM)

Yuav ua li cas:
Yog hais tias koj tsis paub lub npe ntawm lub pob los yog cov ntawv qhia zaub mov, muaj HijackThis txhim kho nws.

O10 - Winsock hijackers

Nws zoo li:
O10 - Hijacked Siv Internet los ntawm New.Net
O10 - Siv Internet vim hais tias ntawm LSP tus kws kho mob c: \ progra ~ 1 \ common ~ 2 \ toolbar \ cnmib.dll 'missing
O10 - Tsis paub cov ntaub ntawv hauv Winsock LSP: c: \ program files \ newton paub \ vmain.dll

Yuav ua li cas:
Nws yog qhov zoo tshaj plaws los kho cov kev siv LSPFix los ntawm Cexx.org, lossis Spybot S & D ntawm Kolla.de.

Nco ntsoov tias cov ntaub ntawv 'tsis paub' hauv LSP pawg yuav tsis raug kho los ntawm HijackThis, rau cov teeb meem kev nyab xeeb.

O11 - Ntxiv pab pawg hauv IE & # 39; Advanced Options & # 39; qhov rais

Nws zoo li:
O11 - Pawg xaiv: [CommonName] CommonName

Yuav ua li cas:
Tsuas hijacker li tam sim no uas ntxiv nws cov kev xaiv pab pawg mus rau IE Advanced Options qhov rai yog CommonName. Li ntawd, koj yeej ib txwm muaj HijackThis kho qhov no.

O12 - IE plugins

Nws zoo li:
O12 - Plugin rau .spop: C: \ Cov ntaub ntawv kev siv \ Internet Explorer \ Plugins \ NPDocBox.dll
O12 - Plugin rau .PDF: C: \ Program Files \ Internet Explorer \ PLUGINS \ nppdf32.dll

Yuav ua li cas:
Feem ntau cov sij hawm no muaj kev ruaj ntseg. Tsuas OnFlow ntxiv ib lub plugin no uas koj tsis xav (.ofb).

O13 - IE DefaultPrefix hijack

Nws zoo li:
O13 - DefaultPrefix: http://www.pixpox.com/cgi-bin/click.pl?url=
O13 - WWW Prefix: http://prolivation.com/cgi-bin/r.cgi?
O13 - WWW. Prefix: http://ehttp.cc/?

Yuav ua li cas:
Cov no yog ib txwm phem. HijackThis txhim kho lawv.

O14 - & # 39; Pib dua Web Sites & # 39; hijack

Nws zoo li:
O14 - IERESET.INF: START_PAGE_URL = http: //www.searchalot.com

Yuav ua li cas:
Yog tias qhov URL tsis yog tus muab kev pab ntawm koj lub computer lossis koj tus ISP, muaj HijackThis kho nws.

O15 - Cov chaw tsis xav pauv hauv Trusted Zone

Nws zoo li:
O15 - Lub Zos Trusted: http://free.aol.com
O15 - Lub Zos Trusted: * .coolwebsearch.com
O15 - Lub Zos Trusted: * .msn.com

Yuav ua li cas:
Feem ntau ntawm cov sij hawm tsuas yog AOL thiab Coolwebsearch twj ywm ntxiv qhov chaw rau lub koom haum Trusted. Yog tias koj tsis tau ntxiv cov npe sau rau hauv lub Trusted Zone koj tus kheej, muaj HijackThis txhim kho nws.

O16 - ActiveX khoom (aka Downloaded Program Files)

Nws zoo li:
O16 - DPF: Yahoo! Tham - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Yuav ua li cas:
Yog tias koj tsis paub lub npe ntawm tus kwv, lossis qhov URL nws tau downloaded los ntawm, muaj HijackThis txhim kho nws. Yog hais tias lub npe lossis URL muaj cov lus zoo li 'dialer', 'twv txiaj yuam pov', 'free_plugin' thiab lwm yam, nws yeej txhim kho nws. Javacool's SpywareBlaster muaj lub database loj heev ntawm ActiveX cov khoom uas yuav raug siv los nrhiav CLSIDs. (Txoj cai-nias lub npe los siv Kev Tshawb Nrhiav.)

O17 - Lop.com domain hijacks

Nws zoo li:
O17 - HKLM \ System \ CCS \ Cov kev pab cuam \ VxD \ MSTCP: Domain = aoldsl.net
O17 - HKLM \ System \ CCS \ Cov kev pab cuam \ Tcpip \ Parameters: Domain = W21944.find-quick.com
O17 - HKLM \ Software \ .. Xov tooj: DomainName = W21944.find-quick.com
O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ {D196AB38-4D1F-45C1-9108-46D367F19F7E}: Sau = W21944.find-quick.com
O17 - HKLM \ System \ CS1 \ Cov kev pab cuam \ Tcpip \ Parameters: SearchList = gla.ac.uk
O17 - HKLM \ System \ CS1 \ Services \ VxD \ MSTCP: NameServer = 69.57.146.14,69.57.147.175

Yuav ua li cas:
Yog hais tias tus sau tsis yog los ntawm koj lub ISP lossis lub lag luam network, muaj HijackThis txhim kho nws. Tib yam mus rau qhov 'SearchList' nkag. Rau qhov 'NameServer' ( DNS servers ) nkag, Google rau IP los yog IPs thiab nws yuav yooj yim los saib seb lawv puas zoo los yog phem.

O18 - Ntxiv cov kev cai thiab cov txheej txheem hijackers

Nws zoo li:
O18 - Txhim kho: kev sib txuas: - 5AB65DD4-01FB-44D5-9537-3767AB80F790} - C: \ PROGRA ~ 1 \ COMMON ~ 1 \ MSIETS \ msielink.dll
O18 - Raws tu qauv: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82}
O18 - Protocol hijack: http - {66993893-61B8-47DC-B10D-21E0C86DD9C8}

Yuav ua li cas:
Tsuas yog qee tus neeg hijackers tuaj ntawm no. Cov baddies paub yog 'cn' (CommonName), 'ayb' (Lop.com) thiab 'associatedlinks' (Huntbar), koj yuav tsum muaj HijackThis kho cov neeg. Lwm yam uas tshwm tawm yog tsis paub tseeb hais tias tsis muaj kev ruaj ntseg, los yog raug tua (xws li CLSID tau hloov lawm) los ntawm spyware. Nyob rau hauv rooj plaub kawg, muaj HijackThis txhim kho nws.

O19 - Tus neeg siv daim ntawv ntaus ntawv hijack

Nws zoo li:
O19 - Tus neeg siv cov ntawv style: c: \ windows \ my.css

Yuav ua li cas:
Nyob rau hauv cov ntaub ntawv ntawm qhov browser slowdown thiab nquag popups, muaj HijackThis kho qhov khoom no yog nws qhia tau hais tias nyob rau hauv lub cav. Txawm li cas los, vim Coolwebsearch tsuas yog qhov no, nws zoo dua los siv CWShredder txhawm rau txhim kho nws.

O20 - AppInit_DLLs Registry nqi autorun

Nws zoo li:
O20 - AppInit_DLLs: msconfd.dll

Yuav ua li cas:
No Registry tus nqi nyob hauv HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Windows loads DLL rau hauv nco thaum tus neeg siv cav, tom qab uas nws nyob qis qis txog logoff. Cov kev pab cuam tsawg heev yog siv nws (Norton CleanSweep siv APITRAP.DLL), feem ntau nws yog siv los ntawm cov neeg thoj cov qhauj los yog kev nyiag nkos.

Nyob rau hauv cov ntaub ntawv ntawm ib tug 'muab zais' DLL loading ntawm no Registry nqi (tsuas pom thaum twg siv 'Kho kom raug binary cov ntaub ntawv' xaiv nyob hauv Regedit) lub dll lub npe yuav prefixed nrog lub yeeb nkab '|' kom nws pom nyob rau hauv lub cav.

O21 - ShellServiceObjectDelayLoad

Nws zoo li:
O21 - SSODL - AUHOOK - {11566B38-955B-4549-930F-7B7482668782} - C: \ qhov TSEEB \ System \ auhook.dll

Yuav ua li cas:
Qhov no yog ib txoj kev siv autorun uas tsis muaj ntaub ntawv, feem ntau siv los ntawm ob peb yam khoom siv hauv Windows. Cov khoom uas tau teev tseg ntawm HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ ShellServiceObjectDelayLoad yog loaded los ntawm Explorer thaum lub qhov rais pib. HijackThis siv lub whitelist ntawm ntau yam khoom SSODL heev, yog thaum twg ib qho khoom tshwm nyob rau hauv lub cav nws tsis paub thiab tejzaum nws siab phem. Kho nrog kev kho mob siab heev.

O22 - Sib Koom Thoob Plaws

Nws zoo li:
O22 - SharedTaskScheduler: (tsis muaj npe) - {3F143C3A-1457-6CCA-03A7-7AA23B61E40F} - c: \ windows \ system32 \ mtwirl32.dll

Yuav ua li cas:
Qhov no yog qhov autorun uas tsis muaj npe nyob rau Windows NT / 2000 / XP nkaus xwb, uas yog siv tsawg heev. Yog li ntawd xwb CWS.Smartfinder siv nws. Kho nrog kev kho mob.

O23 - NT Kev Pabcuam

Nws zoo li:
O23 - Kev pab: Kerio Personal Firewall (PersFw) - Kerio yees - C: \ Cov ntaub ntawv \ Kerio \ Personal Firewall \ persfw.exe

Yuav ua li cas:
Nov yog cov npe ntawm cov kev pabcuam tsis yog Microsoft. Daim ntawv yuav tsum yog tib yam li qhov koj pom hauv Msconfig chaw tso dej ntawm Windows XP. Muaj ntau cov neeg ua txhaum kev cai ntawm Truvian siv cov kev pab hauv tsev rau hauv adittion rau lwm cov pib ua haujlwm kom rov tsim lawv tus kheej. Lub npe tag nrho yog qhov tseem ceeb-xws li 'Network Security Service', 'Workstation Logon Service' lossis 'Procedure Remote Procedure Caller', tab sis lub npe sab hauv (nruab nrab ntawm cov ntawv) yog ib txoj hlua khi, xws li "Ort". Qhov thib ob ntawm txoj kab yog tus tswv ntawm cov ntaub ntawv kawg, raws li pom hauv cov ntaub ntawv cov khoom.

Nco ntsoov tias kho O23 yam khoom yuav tsuas nres cov kev pab cuam thiab lov tes taw nws. Qhov kev pabcuam yuav tsum tau muab tshem tawm ntawm Registry ntawm kev tswj lossis lwm yam cuab yeej. Hauv HijackThis 1.99.1 lossis siab dua, lub pob 'Delete NT Service' nyob rau hauv cov cuab yeej Misc tseem siv tau rau qhov no.