mjukis skrev:
Har oxå antagit att det är deras program som e boven.. verkar knas.
Har oxå dragit hem ett program som heter Xoftspy och det verkar vara ngt lurt med det oxå.
Kan någon som inte har virus kolla upp följande:
1.Hur många services.exe som körs under "processer" (ctrl+alt+del --> processer) Jag har två st nämligen. (samt om det finns någon process som heter smss.exe)
2.Hur många strängar med services.exe det ligger i registret? Jag har ett antal och de som har namnet "xp_system" ska tydligen ha ngt med en trojan vid namnet Krepper-G att göra.
Om jag inte får bukt på detta ikväll blire format c!!
Har suttit o donat 10timmar totalt med detta nu.. vill göra ngt annat känns det som
Hittade detta om du inte redan formaterat:
Re: SpySheriff infection..
Jul 13th 2005, 01:34 AM | #3
This is one of the most annoying infections yet. It took me almost 30 minutes to remove.
Here is the easiest way to remove it. What you will need:
Antivirus (norton, or Mcaffe)
MS antispyware
Adaware
HijackThis.
First, the most crucial part of this is to stop the service running the spyware. To do this, click the start menu, click RUN. type in services.msc this is the service manager for windows. There shoudl be one service there called svchost.exe. Right click on it and select properties. Stop the service, and from the drop down menu select disable.
This stops the spyware from reappearing after reboot etc.
Next Run Ad-aware and MS antispyware. whatever they find, remove it. After both scans are done, run the softwares agian to make sure. Once thats done, run your anti-virus, and remove all viruses it finds.
Open up hijackthis and take a look through the listings. Now i dont exactly remember what listings are the ones you remove, there were almost a dozen when i went thru it. Your best bet is to post the hijackthis log here for people to look at it.
Delete this file also: c:\windows\desktop.html
that should get rid of that pesky desktop.
also look through those links above, they are useful (wish i looked at them before i went gunho on the spyware)
/M