chrome被hao123主页绑架的解决

有些东西,本身也许不讨厌,但是你强迫我,那就非解决不可。


比如,hao123,用什么东西后台修改chrome的快捷方式,将hao123的主页作为启动参数来绑定,这样修改chrome本身的设定无效。

查到百度的各种方案都无效,问了下谷歌,只扫到一个答案,非常简洁,用 AdwCleaner可除。

果然,附带清了很多广告。


附上我的清除记录……等下,把QQ也整个删除了?QQ,你到底干什么了?

# AdwCleaner v6.044 - Logfile created 08/03/2017 at 07:57:22
# Updated on 28/02/2017 by Malwarebytes
# Database : 2017-03-07.1 [Server]
# Operating System : Windows 10 Pro  (X64)
# Username : mikde - SURFACE
# Running from : C:\Users\mikde\Downloads\AdwCleaner.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support






***** [ Services ] *****


[-] Service deleted: QPCore
[-] Service deleted: QDAntiDrv




***** [ Folders ] *****


[-] Folder deleted: C:\Users\mikde\AppData\Local\PackageAware
[-] Folder deleted: C:\Users\mikde\AppData\Local\SysassistByHotWheel
[-] Folder deleted: C:\Users\mikde\AppData\Local\hao123
[-] Folder deleted: C:\Users\mikde\AppData\Local\Kuaizip
[-] Folder deleted: C:\Users\mikde\AppData\Local\Tencent
[-] Folder deleted: C:\Users\mikde\AppData\LocalLow\Tencent
[-] Folder deleted: C:\Users\mikde\AppData\Roaming\IQIYI Video
[-] Folder deleted: C:\Users\mikde\AppData\Roaming\Kuaizip
[-] Folder deleted: C:\Users\mikde\AppData\Roaming\Tencent
[-] Folder deleted: C:\Users\mikde\AppData\Roaming\Softlink
[-] Folder deleted: C:\Users\mikde\AppData\Roaming\YouKu
[-] Folder deleted: C:\Users\mikde\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
[-] Folder deleted: C:\Users\mikde\AppData\Local\VirtualStore\Program Files (x86)\Tencent
[-] Folder deleted: C:\ProgramData\Tencent
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Tencent
[-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
[-] Folder deleted: C:\Users\Public\Documents\Rising
[-] Folder deleted: C:\Users\Public\Documents\Tencent
[-] Folder deleted: C:\Program Files (x86)\Tencent
[-] Folder deleted: C:\Program Files (x86)\YouKu
[-] Folder deleted: C:\Program Files (x86)\Common Files\Tencent
[-] Folder deleted: c:\Temp\Tencent
[-] Folder deleted: C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\Tencent
[-] Folder deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pnaiinchjaonopoejhknmgjingcnaloc
[-] Folder deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjpieolhcmajmolkhbbeljknkcdcmffk




***** [ Files ] *****


[-] File deleted: C:\Users\mikde\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\UC浏览器.lnk
[-] File deleted: C:\WINDOWS\SysNative\drivers\KuaiZipDrive.sys
[-] File deleted: C:\WINDOWS\SysWOW64\kz.exe
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxps_ke.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxps_ke.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxps_kuaibao.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxps_kuaibao.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxps_mail.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxps_mail.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxps_www.hao123.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxps_www.hao123.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxps_xui.ptlogin2.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxps_xui.ptlogin2.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_cn.qzs.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_cn.qzs.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_cnc.qzs.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_cnc.qzs.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_coral.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_coral.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_db.house.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_db.house.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_finance.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_finance.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_jn.house.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_jn.house.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_mail.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_mail.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_mp.weixin.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_mp.weixin.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_news.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_news.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_rc.qzone.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_rc.qzone.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_sports.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_sports.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_tech.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_tech.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_user.qzone.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_user.qzone.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_v.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_v.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.120ask.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.120ask.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.bookask.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.bookask.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.hao123.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.hao123.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.ithao123.cn_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.ithao123.cn_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_www.qq.com_0.localstorage-journal
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_xui.ptlogin2.qq.com_0.localstorage
[-] File deleted: C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_xui.ptlogin2.qq.com_0.localstorage-journal




***** [ DLL ] *****






***** [ WMI ] *****






***** [ Shortcuts ] *****


[-] Shortcut disinfected: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[-] Shortcut disinfected: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[-] Shortcut disinfected: C:\Users\mikde\Desktop\chrome.lnk
[-] Shortcut disinfected: C:\Users\mikde\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[-] Shortcut disinfected: C:\Users\mikde\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[-] Shortcut disinfected: C:\Users\mikde\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[-] Shortcut disinfected: C:\Users\mikde\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\chrom.lnk
[-] Shortcut disinfected: C:\Users\mikde\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\UC浏览器 (2).lnk
[!] Shortcut not deleted: C:\Users\mikde\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\UC浏览器.lnk




***** [ Scheduled Tasks ] *****






***** [ Registry ] *****


[-] Key deleted: HKU\S-1-5-21-2394173474-310465021-4167403336-1001\Software\Classes\Tencent
[#] Key deleted on reboot: HKCU\Software\Classes\Tencent
[-] Key deleted: HKLM\SOFTWARE\Classes\Baidu.BaiduMusic.9
[-] Key deleted: HKLM\SOFTWARE\Classes\baidumusic
[-] Key deleted: HKLM\SOFTWARE\Classes\BaiduYunGuanjia.torrent
[-] Key deleted: HKLM\SOFTWARE\Classes\metnsd
[-] Key deleted: HKLM\SOFTWARE\Classes\QZipShell.ContextMenuExt
[-] Key deleted: HKLM\SOFTWARE\Classes\QZipShell.ContextMenuExt.1
[-] Key deleted: HKLM\SOFTWARE\Classes\QZipShell.DragDropMenu
[-] Key deleted: HKLM\SOFTWARE\Classes\QZipShell.DragDropMenu.1
[-] Key deleted: HKLM\SOFTWARE\Classes\QZipShell.KYDropHandler
[-] Key deleted: HKLM\SOFTWARE\Classes\QZipShell.KYDropHandler.1
[-] Key deleted: HKLM\SOFTWARE\Classes\QZipShell.KzShlobj
[-] Key deleted: HKLM\SOFTWARE\Classes\QZipShell.KzShlobj.1
[-] Key deleted: HKLM\SOFTWARE\Classes\QZipShell.PropertyExt
[-] Key deleted: HKLM\SOFTWARE\Classes\QZipShell.PropertyExt.1
[-] Key deleted: HKLM\SOFTWARE\Classes\Tencent
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Tencent
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Baidu.BaiduMusic.9
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\baidumusic
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\BaiduYunGuanjia.torrent
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\metnsd
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\QZipShell.ContextMenuExt
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\QZipShell.ContextMenuExt.1
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\QZipShell.DragDropMenu
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\QZipShell.DragDropMenu.1
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\QZipShell.KYDropHandler
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\QZipShell.KYDropHandler.1
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\QZipShell.KzShlobj
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\QZipShell.KzShlobj.1
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\QZipShell.PropertyExt
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\QZipShell.PropertyExt.1
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Tencent
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{9CC34070-3A38-4C7A-89CB-EF8177EF07A1}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{004B0726-A010-4ABF-8556-FCDB7F1FCA1E}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{B9E49847-9822-4139-BC55-7173ED1ADA11}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{AE3D5C7A-413F-4CDB-9331-0E1894637310}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{6B3732AA-F6D4-4F16-9E22-49EDC52C9514}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{B9E49847-9822-4139-BC55-7173ED1ADA11}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{86C4C3BA-4EA4-4CF8-98B9-6B07B477B835}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{004B0726-A010-4ABF-8556-FCDB7F1FCA1E}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE3D5C7A-413F-4CDB-9331-0E1894637310}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FB4F6285-4C32-49F2-950F-A5998F9CEC6C}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{004B0726-A010-4ABF-8556-FCDB7F1FCA1E}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE3D5C7A-413F-4CDB-9331-0E1894637310}
[-] Key deleted: HKU\S-1-5-21-2394173474-310465021-4167403336-1001\Software\SNDA
[-] Key deleted: HKU\S-1-5-21-2394173474-310465021-4167403336-1001\Software\KuaiZipSFX
[-] Key deleted: HKU\S-1-5-21-2394173474-310465021-4167403336-1001\Software\Thunder Network
[-] Key deleted: HKU\S-1-5-21-2394173474-310465021-4167403336-1001\Software\AppDataLow\Thunder Network
[#] Key deleted on reboot: HKCU\Software\SNDA
[#] Key deleted on reboot: HKCU\Software\KuaiZipSFX
[#] Key deleted on reboot: HKCU\Software\Thunder Network
[#] Key deleted on reboot: HKCU\Software\AppDataLow\Thunder Network
[-] Key deleted: HKLM\SOFTWARE\Thunder Network
[#] Key deleted on reboot: [x64] HKCU\Software\SNDA
[#] Key deleted on reboot: [x64] HKCU\Software\KuaiZipSFX
[#] Key deleted on reboot: [x64] HKCU\Software\Thunder Network
[#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\Thunder Network
[-] Data restored: HKU\S-1-5-21-2394173474-310465021-4167403336-1001\Software\Microsoft\Internet Explorer\Main [Start Page] 
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] 
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] 
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] 
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\duba.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\hotnews.duba.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\qq.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\adm.funshion.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\duba.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\funshion.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\mp.weixin.qq.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\qq.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\qzs.qq.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.duba.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\xui.ptlogin2.qq.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\adm.funshion.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\duba.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\funshion.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\mp.weixin.qq.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\qq.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\qzs.qq.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.duba.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\xui.ptlogin2.qq.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\duba.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\hotnews.duba.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\qq.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\adm.funshion.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\duba.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\funshion.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\mp.weixin.qq.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\qq.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\qzs.qq.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.duba.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\xui.ptlogin2.qq.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\adm.funshion.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\duba.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\funshion.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\mp.weixin.qq.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\qq.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\qzs.qq.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.duba.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\xui.ptlogin2.qq.com
[-] Value deleted: HKU\S-1-5-21-2394173474-310465021-4167403336-1001\Software\Microsoft\Windows\CurrentVersion\Run [Wechat]
[-] Value deleted: HKU\S-1-5-21-2394173474-310465021-4167403336-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Wechat]
[#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Wechat]
[#] Value deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Wechat]
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
[-] Value deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [QyBrowser.exe]
[-] Key deleted: HKLM\SOFTWARE\MozillaPlugins\@qq.com/TXSSO
[-] Value deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [AndroidServer.exe]
[#] Value deleted on reboot: HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION [QyBrowser.exe]
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\QZipShell.DLL
[-] Key deleted: HKCU\Software\MozillaPlugins\@1.qq.com/npqqwebgame
[-] Key deleted: HKLM\SOFTWARE\MozillaPlugins\@qq.com/npqscall
[-] Key deleted: HKLM\SOFTWARE\MozillaPlugins\@qq.com/QQPhotoDrawEx
[-] Key deleted: HKLM\SOFTWARE\MozillaPlugins\@qq.com/QzoneMusic




***** [ Web browsers ] *****


[-] Firefox preferences cleaned: "extensions.cpmanager@mozillaonline.com.qvod_hao123_ts" -  17221
[-] [C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1] [extension] Deleted: mjpieolhcmajmolkhbbeljknkcdcmffk
[-] [C:\Users\mikde\AppData\Local\Google\Chrome\User Data\Profile 1] [extension] Deleted: pnaiinchjaonopoejhknmgjingcnaloc




*************************


:: "Tracing" keys deleted
:: Winsock settings cleared


*************************


C:\AdwCleaner\AdwCleaner[C0].txt - [24829 Bytes] - [08/03/2017 07:57:22]
C:\AdwCleaner\AdwCleaner[S0].txt - [24099 Bytes] - [08/03/2017 07:49:01]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [24977 Bytes] ##########

还原被劫持的浏览器。 以下 6 个提示可帮助还原您的浏览器设置: 1 - 停止级联弹出窗口 如果您的屏幕上出现了看似无穷无尽的弹出窗口,则可能需要首先停止泛滥势头。 为此,在 Microsoft Windows XP 或 Windows 2000 中使用 Internet Explorer 时: 1. 按 Ctrl+Alt+Del,单击“任务管理器”,然后单击“进程”选项卡。 2. 单击 IEXPLORE.EXE,然后单击“结束进程”按钮。 这样做将关闭 Internet Explorer 的所有实例。 然后,您可以重新打开该程序,继续照常浏览。 要帮助预防潜在攻击,您还应该启用弹出窗口阻止程序。 在 Internet Explorer 中启用弹出窗口阻止程序: 1.在“工具”菜单上,单击“Internet 选项”,然后单击“隐私”选项卡。 2.在“弹出窗口阻止程序”框中,选择“阻止弹出窗口”复选框。 单击“确定”。 如果您仍然遇到被劫持的 Web 浏览器带来的其他影响,请尝试以下步骤: 2 - 安装防御性软件,如上述“防止浏览器劫持”部分中提到的各种软件。 您可以通过下载、安装并运行这些程序来识别和删除许多浏览器劫持程序。 3 - 运行 恶意软件删除工具。此工具可捕获某些(但并非所有)类型的劫持软件。 4 - 手动还原您的设置。 如果您正在使用 Internet Explorer 且主页已被更改,则通常可以自己将其重置。 1.在“工具”菜单上,单击“Internet 选项”,然后单击“常规”选项卡。 2.在“主页”框中,将所需网址键入到“地址”栏中,或单击“使用默认页”按钮恢复原来的出厂设置。 3.单击“确定”。 5 - 通过“添加/删除”功能删除有害程序 如果您准备尝试某些高级删除方法,Microsoft 帮助和支持文章欺骗性软件可能会使计算机出现莫名其妙的问题提供了您可以执行的附加步骤,包括如何使用“添加/删除”功能、内置程序删除工具以及 Windows Explorer 中的程序查找工具。 6 - 完成这些步骤后,请清空回收站,特别是在删除了有害的程序时。 然后重新启动系统。
评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值