Indlela yokuhlaziya i-HijackLe miqulu

Ukutolika uLwazi lweNkcukacha ukuNceda ukususa i-Spyware kunye nabaHlengi beSiphequluli

UkuqhawulaLesi sixhobo samahhala e-Trend Micro. Yayisungulwe ekuqaleni nguMerijn Bellekom, umfundi waseNetherlands. Isofthiwe yokususa i- spyware njenge-Adaware okanye i-Spybot S & D yenza umsebenzi omuhle wokufumanisa nokususa iinkqubo ezininzi ze-spyware, kodwa ezinye i-spyware kunye nabahlaziyi-bhrawuza abayikhohlakeleyo nakwizinto ezintle zokulwa ne-spyware.

I-HijackLokhu kubhaliwe ngokukhethekileyo ukufumanisa nokususa i-hijacks ye-browser, okanye isofthiwe esithatha isiphequluli sakho sewebhu, iguqula ikhasi lakho lasekhaya kunye nenjini yokukhangela kunye nezinye izinto ezinobungozi. Ngokungafani nesofthiwe echasayo-spyware, i-hijackLokhu ayisebenzisi izityikityo okanye ijolise nayiphina inkqubo okanye i-URL yokuyijonga nokuyivimba. Kunoko, i-hijackThis ibheka iindlela kunye neendlela ezisetyenziswa yi- malware ukusulela inkqubo yakho kwaye uqondise kwakhona umkhangeli wakho.

Ayikho yonke into ebonakalayo kwi-HijackLezi zigodo zizinto ezimbi kwaye akufanele zonke zisuswe. Enyanisweni, ngokuchaseneyo. Kuqinisekisiwe ukuba ezinye zezinto kwi-Hijack yakhoLezigodo ziya kuba yi-software yolungileyo kwaye zisuse ezo zinto zingathintela kakubi inkqubo yakho okanye zenze ukuba zingasebenzi ngokupheleleyo. Ukusebenzisa i-hijack Kuninzi ukuhlela uRejista ye- Windows ngokwakho. Akuyiyo i-rocket yesayensi, kodwa akufanele nakanjani uyenze ngaphandle kwekhokelo lobuchwepheshe ngaphandle kokuba uyayazi into oyenzayo.

Emva kokuba ufake i-HijackThis kwaye uyisebenzise ukuze uvelise ifayile yelog, kukho iintlobo ezahlukeneyo zeeforamu kunye neziza apho ungathumela okanye ulayishe idatha yakho yelog. Iingcali ezikwazi ukuba zikhangele zingakunceda ukuba uhlalutye idatha yelogi kwaye ucebise ukuba yiziphi izinto ozozikhupha kunye nokuba ngubani ozohamba eyedwa.

Ukukhuphela inguqulelo yangoku ye-HijackThis, unga tyelela indawo esemthethweni kwi-Trend Micro.

Nantsi ingqamaniso ye-HijackLokhu okungenwa kwelogi ongayisebenzisa ukuzisela ulwazi olufunayo:

I-R0, R1, R2, R3-IE Qala kunye namaphepha oPhando

Oko kubonakala ngathi:
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Qala Page = http://www.google.com/
R1 - HKLM \ Software \ Microsoft \ InternetExplorer \ Main, Default_Page_URL = http://www.google.com/
R2 - (olu hlobo alusetyenziswe yiHijackThis okwamanje)
R3 - I-URL engapheliyoSearchHook ilahlekile

Kwenziwe ntoni:
Ukuba uqaphela i-URL ekugqibeleni njengekhasi lakho lasekhaya okanye injini yosesho, kulungile. Ukuba awukwazi, jonga kwaye wenze i-HijackLo lu lungisa. Ngezinto ezi-R3, uhlale uzilungisa ngaphandle kokuba ucacise inkqubo oyiqondayo, njengeCopernic.

F0, F1, F2, F3 - Iinkqubo zokulayisha ngokuzenzekelayo ezivela kwiifayile ze-INI

Oko kubonakala ngathi:
F0 - system.ini: Shell = Explorer.exe Openme.exe
F1 - win.ini: run = hpfsched

Kwenziwe ntoni:
Izinto ze-F0 zihlala zibi, ngoko zilungise. Izinto ze-F1 ziqhelekileyo iinkqubo ezindala ezikhuselekileyo, ngoko kufuneka ufumane ulwazi oluthe xaxa kwigama lefayile ukuze ubone ukuba lilungile okanye libi. Uludwe lwePayman's Startup luyakunceda ngokuchonga into.

N1, N2, N3, N4 - Netscape / Mozilla Qala & amp; Ikhasi lokusesha

Oko kubonakala ngathi:
N1 - Netscape 4: user_pref "isiphequluli.startup.homepage", "www.google.com"); (C: \ Inkqubo yeefayile \ Netscape \ Abasebenzisi \ default \ prefs.js)
N2 - Netscape 6: user_pref ("browser.startup.homepage", "http://www.google.com"); (C: \ Amaphepha kunye nezixhobo \ Umsebenzisi \ Ukwaziswa kwedatha \ Mozilla \ Profiles \ defaulto9t1tfl.slt \ prefs.js)
N2 - Netscape 6: user_pref ("browser.search.defaultengine", "injini: //C%3A%5CProgram%20Files%5CNetscape%206%5Csearchplugins%5CSBWeb_02.src"); (C: \ Amaphepha kunye nezixhobo \ Umsebenzisi \ Ukwaziswa kwedatha \ Mozilla \ Profiles \ defaulto9t1tfl.slt \ prefs.js)

Kwenziwe ntoni:
Ngokuqhelekileyo ikhasi lasekhaya laseNetscape neMozilla kunye nephepha lokukhangela likhuselekile. Akunakufaneka ukuba athabathe, iLap.com kuphela eyaziwayo ukwenza oku. Ukuba ubona i-URL ongayiboni njengekhasi lakho lasekhaya okanye iphepha lokukhangela, yiba ne-HijackLokhu ukulungisa.

I-O1 - i-Hosts i-refirections

Oko kubonakala ngathi:
O1 - Iimikhosi: 216.177.73.139 auto.search.msn.com
O1 - Iimikhosi: 216.177.73.139 search.netscape.com
I-O1 - Iimikhosi: 216.177.73.139
I-O1 - Iifayile zeMikhosi zifumaneka kwiC: \ Windows \ Uncedo \ iibhokhwe

Kwenziwe ntoni:
Le ngqungquthela iya kutshintsha idilesi ngakwesokudla kwidilesi ye-IP ngakwesobunxele. Ukuba i-IP ayilona idilesi, uya kuhanjiswa kwi-site engafanelekanga ngexesha lokungena kwakho kwidilesi. Unako ukuhlala u-Hijack Ukulungisa oku, ngaphandle kokuba ubeka ngokucacileyo loo mgca kwifayile yakho yamaHlathi.

Kwimpahla yokugqibela ngezinye ivela kwi-Windows 2000 / XP kunye ne-Coolwebsearch infection. Njalo ulungise le nto, okanye u-CWShredder ulungise ngokuzenzekelayo.

I-O2 - Iincwadi zeNcedisi zoKhenketho

Oko kubonakala ngathi:
O2 - BHO: Yahoo! Umhlobo we-BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C: \ IPROGRAM FILES \ YAHOO! \ COMPANION \ YCOMP5_0_2_4.DLL
O2 - BHO: (akukho gama) - {1A214F62-47A7-4CA3-9D00-95A3965A8B4A} - C: \ IPROGRAM FILES \ POPUP UMSEBENZI \ AUTODISPLAY401.DLL (ifayile engekho)
I-O2-BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C: \ INKQUBO YOKUBHALWA \ IMICWANGCISO YOKUSEBENZA \ ME1.DLL

Kwenziwe ntoni:
Ukuba awuqapheli ngokuqondile igama le-Object Browser, sebenzisa i-TonyK ye-BHO kunye noLuhlu lweBar Tool ukuze uluthole nge-ID yiklasi (CLSID, inani phakathi kwama-brackets) kwaye ubone ukuba kulungile okanye kubi. Kuluhlu lweBHO, 'X' ithetha i-spyware kunye ne- 'L' ithetha ngokukhuselekileyo.

Iibhokisi zeetayiti ze-O3-IE

Oko kubonakala ngathi:
O3 - Ibar yomncedisi: & Yahoo! Umhlobo - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C: \ IPROGRAM FILES \ YAHOO! \ COMPANION \ YCOMP5_0_2_4.DLL
I-O3-Ibar yebarbar: I-Output Eliminator - {86BCA93E-457B-4054-AFB0-E428DA1563E1} - C: \ IPROGRAM FILES \ POPUP UMSEBENZI \ PETOOLBAR401.DLL (ifayile engekho)
I-O3-Ibar yebarbar: rzillcgthjx - {5996aaf3-5c08-44a9-ac12-1843fd03df0a} - C: \ IINDLELA \ IINKXELO ZEMICELO \ CKSTPRLLNQUL.DLL

Kwenziwe ntoni:
Ukuba awuyiqondi ngqo igama lebarbar, sebenzisa i-TonyK ye-BHO kunye noLuhlu lweBar Tool ukuze lufumane nge-ID yiklasi (CLSID, inani phakathi kwama-brackets angama-curly) kwaye ubone ukuba lilungile okanye libi. Uluhlu lweBar Tool, 'X' lithetha i-spyware kunye ne- 'L' lithetha ukhuselekile. Ukuba akukho kwiluhlu kwaye igama libonakala luchungechunge oluthile lokubhaliweyo kunye nefayili kwifolda ye 'Data Data' ifolda (njengowokugqibela kwimimiselo engentla), mhlawumbi i-Lop.com, kwaye ngokuqinisekileyo kufuneka ube ne-HijackLokhu kulungisa .

O4 - Iinkqubo zokulayisha ngokuzenzekelayo ukusuka kwiRejista okanye iqela lokuqalisa

Oko kubonakala ngathi:
O4 - HKLM \ .. \ Run: [ScanRegistry] C: \ WINDOWS \ scanregw.exe / autorun
O4 - HKLM \ .. \ Run: [SystemTray] SysTray.Exe
O4 - HKLM \ .. \ Run: [ccApp] "C: \ Inkqubo yeefayile \ iiFayile eziqhelekileyo \ Symantec Kwabiwe \ ccApp.exe"
O4 - Ukuqalisa: iMicrosoft Office.lnk = C: \ Iifayile zoNyaka \ Microsoft Office \ Office \ OSA9.EXE
I-O4 - Ukuqalisa kwe-Global: winlogon.exe

Kwenziwe ntoni:
Sebenzisa uLuhlu lokuQala kwePomMan ukufumana ukungena uze ubone ukuba luhle okanye lubi.

Ukuba le nto ibonisa inkqubo ehleli kwiqela lokuqalisa (njengento yokugqibela engenhla), i-HijackLokhu ayikwazi ukulungisa into ukuba le nkqubo isasesikhumbuzweni. Sebenzisa uMphathi weeWindows (TASKMGR.EXE) ukuvala inkqubo ngaphambi kokulungisa.

I-O5 - IE Izinketho ezingabonakali kwiPaneli yokuLawula

Oko kubonakala ngathi:
O5 - control.ini: inetcpl.cpl = ayi

Kwenziwe ntoni:
Ngaphandle kokuba wena okanye umlawuli wakho wenethiwekhi uye wazifihla ngokucacileyo i icon ukusuka kwi-Control Panel, yiba ne-HijackLokhu ukulungisa.

I-O6-IE Iinketho zokufikelela ezikhutshwe nguMlawuli

Oko kubonakala ngathi:
I-O6-HKCU \ Software \ Iipolisi \ I-Microsoft \ Internet Explorer \ izithintelo zikhoyo

Kwenziwe ntoni:
Ngaphandle kokuba unokhetho lwe - Spybot S & D 'Khuphela iphepha lasekhaya ukusuka kutshintsho' esebenzayo, okanye umlawuli wakho wendlela ubeka le ndawo, yiba neHackyThis fix this.

I-O7 - Ukufikelela kweReedit ivalwe nguMlawuli

Oko kubonakala ngathi:
O7 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Iinkqubo \ Inkqubo, Khubaza iRegedit = 1

Kwenziwe ntoni:
Hlalani nisigxinaLokhu kulungise oku, ngaphandle kokuba umlawuli wakho wenkqubo ebeke le mithintelo endaweni.

O8 - Izinto ezongezelelweyo kwi-IE imenyu yokunqakraza imenyu

Oko kubonakala ngathi:
I-O8 - Intetho yemenyu yenkcazelo engakumbi: & I-Google Usesho - i-:: C: \ IWINDOWS \ DOWNLOADED INKQUBO YEZICWADI \ GOOGLETOOLBAR_EN_1.1.68-DELEON.DLL / cmsearch.html
I-O8 - Imveliso yenkalo engakumbi yemeko: Yahoo! Ukukhangela - ifayile: /// C: \ Inkqubo yeefayile \ Yahoo! \ Eqhelekileyo / ycsrch.htm
I-O8 - Imveliso yenkalo engaphezulu yenkcazelo: Zoom & In-C: \ WINDOWS \ WEB \ zoomin.htm
I-O8 - Imveliso yenkalo engakumbi yenkcazelo: Cwangcisa i-O & ut-C: \ WINDOWS \ WEB \ zoomout.htm

Kwenziwe ntoni:
Ukuba awuyiqapheli igama lento kwimenyu yokunqakraza e-IE, yiba ne-HijackLokhu ukulungisa.

I-O9 - Iimpawu ezingaphezulu kwiibar yomthamo oyi-IE, okanye izinto ezongezelelweyo kwi-IE & # 39; Izixhobo & # 39; imenyu

Oko kubonakala ngathi:
O9 - Inkinobho eyongezelelweyo: Umthunywa (HKLM)
I-O9 - Iimpawu ezongezelelweyo 'Izixhobo': Umthunywa (HKLM)
O9 - Inkinobho eyongezelelweyo: AIM (HKLM)

Kwenziwe ntoni:
Ukuba awuqapheli igama leqhosha okanye imenyu yohlu, yenza i-HijackLungisa loo nto.

Abaculi be-O10 - Winsock

Oko kubonakala ngathi:
I-O10 - Ukungena kwi-intanethi kwiNew.Net
I-O10 - Ukufikelela kwe-Intanethi ephukileyo ngenxa ye-LSP umnikezeli 'c: \ progra ~ 1 \ oqhelekileyo \ 2 \ ibar yomthamo \ cnmib.dll' ekhoyo
I-O10 - Ifayile engaziwayo kwi- Winsock LSP: c: \ program files} i-newton iyazi \ vmain.dll

Kwenziwe ntoni:
Kungcono ukulungisa oku usebenzisa i-LSPFix kwiCexxxx.org, okanye i-Spybot S & D esuka ku-Kolla.de.

Qaphela ukuba iifayile 'ezingaziwa' kwikhompyutheni ye-LSP ayiyi kugqitywa nguHiackThis, malunga nemiba yokhuseleko.

O11 - Iqela elongezelelweyo kwi-IE & # 39; Iinketho eziphambili kunye # 39; iwindow

Oko kubonakala ngathi:
Iqela le-O11 - Inketho: [CommonName] CommonName

Kwenziwe ntoni:
Umqhubi wedwa kuphela okwangoku owongeza iqela lakhe lokukhetha kwi window ye-IE Advanced Options yi-CommonName. Ngoko unako ukuhlala u-HijackLokhu kulungise oku.

I-O12-IE iifowuni

Oko kubonakala ngathi:
O12 - I-Plugin ye .spop: C: \ Inkqubo yeefayile \ i-Internet Explorer \ Plugin \ NPDocBox.dll
I-O12 - Iplagi yePDF: C: \ Inkqubo yeefayile \ Internet Explorer \ PLUGINS \ nppdf32.dll

Kwenziwe ntoni:
Uninzi lwexesha ezi zikhuselekileyo. I-OnFlow kuphela yongeza iplagin apha ongayifuni (.ofb).

O13 - IE DefaultPrefix hijack

Oko kubonakala ngathi:
O13 - DefaultPrefix: http://www.pixpox.com/cgi-bin/click.pl?url=
O13 - WWW Prefix: http://prolivation.com/cgi-bin/r.cgi?
O13 - WWW. Isiqalo: http://ehttp.cc/?

Kwenziwe ntoni:
Ezi zihlala zibi. Yenza i-HijackLungiselela loo nto.

O14 - & # 39; Hlaziya izicwangciso zewebhu kunye # 39; ukuhlawula

Oko kubonakala ngathi:
O14 - IERESET.INF: START_PAGE_URL = http: //www.searchalot.com

Kwenziwe ntoni:
Ukuba i-URL ayikho umboneleli wekhompyutheni yakho okanye i-ISP yakho, yiba ne-HijackLokhu kuyilungisa.

O15 - Amasayithi angafunekiyo kuMmandla oThenjiweyo

Oko kubonakala ngathi:
I-O15 - Indawo eThenjwayo: http://free.aol.com
I-O15 - Indawo eThenjwayo: * .coolwebsearch.com
I-O15 - Indawo yokuThenjwa: * .msn.com

Kwenziwe ntoni:
Ininzi yexesha kuphela i-AOL kunye ne-Coolwebsearch yodwa yenza iiwebhusayithi kwiNdawo ethembekileyo. Ukuba awunakongeza idilesi eluhlu kwiSikhulu esithembekileyo, yenza i-HijackLokhu kukulungiselele.

I-O16 - I-ActiveX Objects (iFayile eFowuniweyo yeeFayile)

Oko kubonakala ngathi:
O16 - DPF: Yahoo! Ingxoxo - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (iShockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Kwenziwe ntoni:
Ukuba awuyiqapheli igama lento, okanye i-URL ikhutshwe kuyo, yiba ne-HijackLokhu kuyilungisa. Ukuba igama okanye i-URL iqulethe amagama afana ne-'dialer ',' casino ',' free_plugin 'njll, ngokuqinisekileyo uyilungise. I-Javacool's SpywareBlaster ine-database enkulu yezinto ezinobungozi ze-ActiveX ezingasetyenziselwa ukujonga ii-CLSID. (Cofa iqhosha kuloluhlu usebenzise umsebenzi wokuFumana.)

I-O17-Lop.com domain domain hijacks

Oko kubonakala ngathi:
O17 - HKLM \ System \ CCS \ IiNkonzo \ VxD \ MSTCP: Idilesi = aoldsl.net
O17 - HKLM \ System \ CCS \ IiNkonzo \ Tcpip \ Parameters: I-Domain = W21944.find-quick.com
O17 - HKLM \ Software \ .. \ Telephony: DomainName = W21944.find-quick.com
O17 - HKLM \ System \ CCS \ IiNkonzo \ Tcpip \ .. \ {D196AB38-4D1F-45C1-9108-46D367F19F7E}: I-Domain = W21944.find-quick.com
O17 - HKLM \ System \ CS1 \ IiNkonzo \ Tcpip \ Parameters: SearchList = gla.ac.uk
O17 - HKLM \ System \ CS1 \ Iinkonzo \ VxD \ MSTCP: NameServer = 69.57.146.14,69.57.147.175

Kwenziwe ntoni:
Ukuba i-domain ayikho kwi- ISP yakho okanye inethiwekhi yenkampani, yiba ne-HijackLokhu ukulungisa. Kuyafana okufakwe kwi-'LowListL '. Ngegama elithi 'NameServer' (i- DNS servers ) ukungena, i-Google ye-IP okanye i-IP kwaye kuya kuba lula ukubona ukuba zilungile okanye zibi.

I-O18 - Iiprotokholi ezingeziwe kunye nabagijimi beprotocol

Oko kubonakala ngathi:
I-O18 - iProtokholi: i-relatedlinks - {5AB65DD4-01FB-44D5-9537-3767AB80F790} - C: \ IPOGRA ~ 1 \ OKUQHELEKILEYO \ \ IMSIETS \ msielink.dll
I-O18 - iProtokholi: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82}
I-O18 - iProjan Protocol: http - {66993893-61B8-47DC-B10D-21E0C86DD9C8}

Kwenziwe ntoni:
Kuphela abagijimi abonakalisa apha. Baddies abaziwayo 'cn' (CommonName), 'ayb' (Lop.com) kunye ne 'relatedlink' '(Huntbar), kufuneka ube ne-HijackLokhu kulungisa loo nto. Ezinye izinto ezibonakaliswayo aziqinisekisiwanga ngokukhuselekileyo, okanye zitshitshiswa (okt i-CLSID ishintshiwe) yi-spyware. Kwimeko yokugqibela, yiba ne-HijackLokhu ukulungisa.

I-O19 - I-hijack yesitayela somsebenzisi

Oko kubonakala ngathi:
O19 - Ifayile yomsebenzisi: c: \ WINDOWS \ Java \ my.css

Kwenziwe ntoni:
Kwimeko yeqhosha lokukhangela umgca kunye nokuphambuka kwexesha eliqhelekileyo, yenza i-HijackLungisa le nto ukuba ibonisa kwi-log. Nangona kunjalo, ekubeni kuphela i-Coolwebsearch yenza oku, kungcono ukusebenzisa i-CWShredder ukuyilungisa.

I-O20 - AppInit_DLL yexabiso lokubhalisa imvume

Oko kubonakala ngathi:
O20 - AppInit_DLLs: msconfd.dll

Kwenziwe ntoni:
Ixabiso loRejista elifumaneka kwiHKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Windows ilayisha i-DLL kwimemori xa umsebenzisi engena kuyo, emva koko uhlala ekhunjini kuze kube yilapho i-logoff. Iiprogram ezincinane kakhulu ezisetyenziswayo (i-Norton CleanSweep isebenzisa i-APITRAP.DLL), ngokuqhelekileyo isetyenziselwa iidrojans okanye izigqeba ezigqithisileyo.

Xa kwenzeka 'ukufihla' i-DLL yokulayisha kule xabiso yeRejista (kuphela ebonakalayo xa usebenzisa i-'Hlela yeDatha yeDatha yeDatha 'kwiRededit) igama le-dll linokuthi lifakwe kwangaphambili ngepayipi' | ' ukwenza ukuba kubonakale kwilogi.

O21 - ShellServiceObjectDelayLoad

Oko kubonakala ngathi:
O21 - SSODL - UHOHO - {11566B38-955B-4549-930F-7B7482668782} - C: \ WINDOWS \ System \ auhook.dll

Kwenziwe ntoni:
Le ndlela ye-autorun indlela engavumelekanga, esetyenziswa ngokuqhelekileyo ngamacandelo ambalwa eenkqubo zeWindows. Izinto ezifakwe kwiHKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ ShellServiceObjectDelayLoad zilayishwe nguMhloli xa iWindows iqalisa. Ukuqhaqhaqhasela oku kusebenzisa i-whitelist yezinto ezininzi eziqhelekileyo ze-SSODL, ngoko nayiphi na into xa kukho into eboniswe kwilogi ayifumene kwaye mhlawumbi iyingozi. Yiphatha ngokunyamekela.

O22 - SharedTaskScheduler

Oko kubonakala ngathi:
O22 - SharedTaskScheduler: (akukho igama) - {3F143C3A-1457-6CCA-03A7-7AA23B61E40F} - c: \ windows \ system32 \ mtwirl32.dll

Kwenziwe ntoni:
Le ngu-permun autorun ye-Windows NT / 2000 / XP kuphela, esetyenziswa kakhulu kangako. Okwangoku kuphela iCWS.Smartfinder isebenzisa. Ukunyamekela ngononophelo.

Iinkonzo ze-O23-NT

Oko kubonakala ngathi:
O23-IiNkonzo: I-Kerio Personal Firewall (PersFw) - i-Kerio Technologies - C: \ Inkqubo yeefayile \ i-Kerio \ Personal Firewall \ persfw.exe

Kwenziwe ntoni:
Olu luhlu lweenkonzo ezingezizo zeMicrosoft. Uluhlu lufanele lufane nelo libonayo kwiNkxaso ye-Msconfig yeWindows XP. Abaphangi abaninzi be-trojan basebenzise inkonzo eyenziwe ngokwenzela ukulungiswa kwezinye iindawo zokuqalisa ukuzibuyisela. Igama elipheleleyo lidla ngokubalulekayo-ukubetha, njenge 'Inkonzo yoKhuseleko lweNethwekhi', 'iNkonzo yoLondolozo lweNkonkonti yeSebenzi' okanye 'iNkqubo yoKhuseleko lweNcedisi yoLwazi', kodwa igama langaphakathi (phakathi kweebakaki) ngumtya wentyala, njenge 'Ort'. Inxalenye yesibini yomgca ngumnini wefayile ekupheleni, njengoko kuboniswe kwiipropati zefayile.

Qaphela ukuba ukulungisa into e-O23 iya kuyeka kuphela inkonzo kwaye uyikhubaza. Inkonzo kufuneka isuswe kwiRejista ngesandla okanye esinye isixhobo. Kwi-HijackThis 1.99.1 okanye ngaphezulu, iqhosha elithi 'Susa iNkonzo yeNkonzo' kwiCandelo leZiko leMisc lingasetyenziselwa oku.