+ -
当前位置:首页 → 问答吧 → CHROME 成日弹不知明广告

CHROME 成日弹不知明广告

时间:2014-03-07

来源:互联网

成日上上下网一TICK LINK就系弹呢个网D广告


http://pp.developunit.info/


仲有MOUSE成日无禁都有好多自己KICK既声
求解决

[ 本帖最后由 颖小柚 於 2014-2-19 05:40 PM 编辑 ]
hijackthis.log (14.56 KB)

2014-2-19 05:39 PM, 下载次数: 6

作者: 颖小柚   发布时间: 2014-03-07

引用:原帖由 颖小柚 於 2014-2-19 05:39 PM 发表
成日上上下网一TICK LINK就系弹呢个网D广告


http://pp.developunit.info/


仲有MOUSE成日无禁都有好多自己KICK既声
求解决
楼主有冇印象在安装乜野软件后出现mouse click声?

作者: SILVESTERABEND   发布时间: 2014-03-07

开机按F8,入安全模式做Fix checked & OTM 删除。
1. 执行Hijackthis > Do a system scan only > 勾选下列项目 > 按Fix Checked (fix checked时关闭所有browsers/程式) > 按"是"。
引用:
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [YouCam Mirage] "c:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "c:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [RemoteControl10] "c:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Users\meiyum\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = meiyum\AppData\Roaming\Dropbox\bin\Dropbox.exe

O8 - Extra context menu item: 添加为广告过滤图片 - C:\Program Files (x86)\Super Rabbit\IeProt\AddBlock.htm
O20 - AppInit_DLLs: c:\windows\syswow64\nvinit.dll c:\progra~3\webplat\webplat.dll c:\progra~3\prowebi\prowebi.dll c:\progra~3\winsys~1\winsys~1.dll
O23 - Service: Ad-Aware Service 11 (LavasoftAdAwareService11) - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Service KMSELDI - Unknown owner - C:\Program Files\KMSpico\Service_KMS.exe
2. 下载/执行 OTM做删除。
copy & paste 以下项目於Paste Instructions for Items to be Moved的框格内。
按MoveIt > OK > 重启电脑。
引用:
:files
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Users\meiyum\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
c:\progra~3\webplat\webplat.dll
c:\progra~3\prowebi\prowebi.dll
c:\progra~3\winsys~1\winsys~1.dll
3. 下载/执行Junkware Removal Tool扫毒。执行扫毒前请关闭所有浏览器同程式。
(JRT会自动删除附於浏览器的恶意程式/档案/登录档)

4. 关闭所有防毒软件(包括Windows Defender),下载ComboFix至桌面 ,执行 ComboFix 扫毒。
扫瞄时不要执行其他程式或点击 ComboFix视窗。
完成扫瞄后,ComboFix 报告会自动弹出。

请贴上以下报告:
a. JRT扫毒报告。
b. ComboFix扫毒报告。
c. 新1份Hijackthis扫瞄报告。


PS:建议去程式集移除Ad-Aware Antivirus。

作者: SILVESTERABEND   发布时间: 2014-03-07

无咩印象 净系时不时就有 都好耐下X_X

作者: 颖小柚   发布时间: 2014-03-07

done!

[ 本帖最后由 颖小柚 於 2014-2-19 08:57 PM 编辑 ]
ComboFix.txt (31.51 KB)

2014-2-19 08:55 PM, 下载次数: 2

JRT.txt (13.84 KB)

2014-2-19 08:55 PM, 下载次数: 2

hijackthis(NEW).log (11.78 KB)

2014-2-19 08:57 PM, 下载次数: 3

作者: 颖小柚   发布时间: 2014-03-07

引用:原帖由 颖小柚 於 2014-2-19 08:55 PM 发表
done!
1. 下载/安装Malwarebytes Anti-Malware Free 扫毒。更新后做全面扫瞄,扫到毒按Select all > 再按Remove Selected做删除。

2. 下载 OTL.exe於桌面。双按OTL.exe > 按Run Scan > 完成后请将OTL扫瞄报告(OTL.txt)贴上。
(OTL扫瞄需时较长,请耐心等候)



请贴上以下报告:
a. MBAM扫毒报告。
b. OTL.txt扫瞄报告。

作者: SILVESTERABEND   发布时间: 2014-03-07

DONE ! THX板主
mbam-log-2014-02-20 (22-54-06).txt (6.81 KB)

2014-2-21 01:20 AM, 下载次数: 5

Extras.Txt (92.76 KB)

2014-2-21 01:20 AM, 下载次数: 2

OTL.Txt (117.51 KB)

2014-2-21 01:20 AM, 下载次数: 5

作者: 颖小柚   发布时间: 2014-03-07

双按OTL.exe > 将下列档案copy & paste 到Custom Scans/Fixes框架内 > 按左上角[Run Fix];执行fix前要关闭浏览器。
成功fixed (删除)会有通知(Fix complete! Click OK to open the fix log.) >按OK > 重启电脑。

请将OTL fix log贴上。
引用:
:OTL
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
FF - HKLM\Software\MozillaPlugins\@funshion.com/npFunshion: C:\Users\meiyum\funshion\funshiontools\npFunshion.dll File not found
FF - HKLM\Software\MozillaPlugins\@xunlei.com/npxluser: File not found
FF - HKCU\Software\MozillaPlugins\@xunlei.com/npxluser: File not found
CHR - homepage: http://start.icq.com/
CHR - Extension: Vivienne Westwood = C:\Users\meiyum\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahhehaklopgggapefjdijagkgbgeapkb\2_0\
CHR - Extension: Google \u6587\u4EF6 = C:\Users\meiyum\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_1\
CHR - Extension: Google \u96F2\u7AEF\u786C\u789F = C:\Users\meiyum\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_1\
CHR - Extension: Google \u641C\u5C0B = C:\Users\meiyum\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1\
CHR - Extension: TeuebeItoAAdBBLocckkAap = C:\Users\meiyum\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbedebmkdkndjikakliejjefljfpkjfi\2.6_0\
CHR - Extension: Google \u96FB\u5B50\u9322\u5305 = C:\Users\meiyum\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {41564952-412D-5637-00A7-7A786E7484D7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {481EE3EC-C026-4F9A-BA22-FD07654ADFC0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8:64bit: - Extra context menu item: &妏蚚&捃泞狟婥 - File not found
O8:64bit: - Extra context menu item: &妏蚚&捃泞狟婥窒蝈诿 - File not found
O8:64bit: - Extra context menu item: &妏蚚&捃泞烛盄狟婥 - File not found
O8:64bit: - Extra context menu item: 氝楼峈嫘豢戴诤芞 - Reg Error: Value error. File not found
O8 - Extra context menu item: &妏蚚&捃泞狟婥 - File not found
O8 - Extra context menu item: &妏蚚&捃泞狟婥窒蝈诿 - File not found
O8 - Extra context menu item: &妏蚚&捃泞烛盄狟婥 - File not found
O8 - Extra context menu item: 氝楼峈嫘豢戴诤芞 - Reg Error: Value error. File not found
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1C439983-8D32-4675-96AF-1D1AF9174E02}: DhcpNameServer = 172.20.10.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\osf - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - File not found
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - File not found

:Files
C:\Users\meiyum\AppData\Roaming\Funshion
C:\Program Files (x86)\YoTuberAdosoRemov
C:\Program Files (x86)\YYTubeAdsRRemover
C:\Program Files (x86)\TeuebeItoAAdBBLocckkAap
C:\Users\meiyum\AppData\Roaming\LavasoftStatistics
C:\Program Files\Common Files\Lavasof
C:\ProgramData\Lavasoft
C:\ProgramData\YYTubeAdsRRemover
C:\ProgramData\TeuebeItoAAdBBLocckkAap
C:\ProgramData\YoTuberAdosoRemov
C:\ProgramData\jbedebmkdkndjikakliejjefljfpkjfi
C:\ProgramData\hegfehinljebdjjimjbcckdneffmcaak
C:\ProgramData\afjkcmadebhcgojbpenaickajdmckadc
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4081711590-3367479463-3935261450-1001UA.job
C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4081711590-3367479463-3935261450-1001Core.job
C:\Users\meiyum\FunShion.ini

ipconfig /flushdns /c

:Commands
[PURITY]
[EMPTYTEMP]
[reboot]

作者: SILVESTERABEND   发布时间: 2014-03-07

DONE
02212014OTL.txt (86.01 KB)

2014-2-21 11:25 PM, 下载次数: 3

作者: 颖小柚   发布时间: 2014-03-07

Chrome重有冇弹广告?

作者: SILVESTERABEND   发布时间: 2014-03-07

暂时未有 因为我用左adblock
试下关左一排先
Thx板主

作者: 颖小柚   发布时间: 2014-03-07

引用:原帖由 颖小柚 於 2014-2-23 12:17 AM 发表
暂时未有 因为我用左adblock
试下关左一排先
Thx板主



观察多1两天睇重有冇弹广告网页同出现mouse click声。

作者: SILVESTERABEND   发布时间: 2014-03-07

热门下载

更多