+ -
当前位置:首页 → 问答吧 → 中左INCREDIBAR毒

中左INCREDIBAR毒

时间:2012-08-03

来源:互联网

中左INCREDIBAR毒
救命,每次开chrome新分页 就会出左呢个网页出黎http://mystart.incredibar.com/MB131?a=6OyEpNib6r

用几款防毒,木马都扫唔到有野,点算??

hijackthis 扫瞄报告:http://www.mediafire.com/?e3m5no4eaqy7yd9

作者: hoforchin   发布时间: 1970-01-01

1.执行Hijackthis > Do a system scan only > 勾选下列项目 > 按Fix Checked (fix checked时关闭所有browsers/程式) > 按"是"。
引用:

O1 - Hosts: 123.129.242.212 hub5idx.shub.sandai.net
O1 - Hosts: 58.254.134.204 hub5pr.sandai.net
O2 - BHO: VideoUrlSniffer - {00000ADA-7E0D-47C1-986C-F017D09C4304} - C:\Program Files\Common Files\Thunder Network\KanKan\VideoUrlSniffer.1.1.0.90.(534).dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_1.dll
O2 - BHO: XlBrowserAddinBho.XlBrowserAddinBhoObject - {0EA37B17-6B8B-4085-8257-F3A4AA69C27A} - C:\Program Files\Thunder Network\Thunder\BHO\XlBrowserAddin1.0.8.71.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
O2 - BHO: Web Assistant Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll
O2 - BHO: XunleiBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\BHO\XunleiBHO7.2.9.3634.dll

O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_1.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll

04 - HKCU\..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe
O4 - HKCU\..\Run: [Getchaman] "C:\Program Files\Getchaman 2\Getchaman.exe" -tray
O23 - Service: Web Assistant Updater - Unknown owner - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
2. 下载/执行 OTM做删除。
copy & paste 以下项目於Paste Instructions for Items to be Moved的框格内。
按MoveIt > OK > 重启电脑。
引用:

:files
C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
C:\Program Files\Common Files\Thunder Network\KanKan\VideoUrlSniffer.1.1.0.90.(534).dll
C:\Program Files\Thunder Network\Thunder\BHO\XlBrowserAddin1.0.8.71.dll
C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
C:\Program Files\Web Assistant\Extension32.dll
C:\Program Files\Thunder Network\Thunder\BHO\XunleiBHO7.2.9.3634.dll
C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
3.下载/安装Malwarebytes Anti-Malware 免费版扫毒。更新后做全面扫瞄(唔使选用30天试用),扫完毒按Remove Selected删除感染档案。

请把MBAM扫毒报告及新Hijackthis log贴上。

作者: SILVESTERABEND   发布时间: 1970-01-01

MBAM扫毒报告:  http://www.mediafire.com/?ohvbzu82ylu4oc3
Hijackthis log   :  http://www.mediafire.com/?irfcrilhayqbwxw

作者: hoforchin   发布时间: 1970-01-01

引用:
原帖由 hoforchin 於 2012-8-3 04:47 PM 发表
MBAM扫毒报告:  http://www.mediafire.com/?ohvbzu82ylu4oc3
Hijackthis log   :  http://www.mediafire.com/?irfcrilhayqbwxw
重有冇IncrediBar出现?
1. 楼主要勾选MBAM扫到所有感染档案 > 按Remove Selected删除。
2. 建议去新増/移除程式,移除:
Thunder Netowork
Babylon
Web Assistant

作者: SILVESTERABEND   发布时间: 1970-01-01