Chrome有两种广告一直出来...(ad.yieldmanager)
时间:2013-06-04
来源:互联网
已经被骚扰到快疯掉了
希望有人可以帮忙一下...拜托了
1.使用的Windows版本? Win 7 64bitChrome 一直出现广告,只知道其中一个是ad.yieldmanager
3.出问题前,下载/安装过什么软件?已经有点久了,不是很确定怎么开始的
附档是hijackthis资料,谢谢您
hijackthis.log(17.44 KB)
希望有人可以帮忙一下...拜托了
1.使用的Windows版本? Win 7 64bitChrome 一直出现广告,只知道其中一个是ad.yieldmanager
3.出问题前,下载/安装过什么软件?已经有点久了,不是很确定怎么开始的
附档是hijackthis资料,谢谢您

2013-6-4 02:01 PM, 下载次数: 1
作者: sh000810 发布时间: 2013-06-04
开机按F8,入安全模式做Fix checked & OTM 删除。
1.执行Hijackthis > Do a system scan only > 勾选下列项目 > 按Fix Checked (fix checked时关闭所有browsers/程式) > 按"是"。
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: 砩杬BHO - {876D0712-C780-4347-B56D-C30C520033C5} - C:\Program Files (x86)\ShoppingAssistant\ruyitao\3.2.7.0\ShoppingAssistant.dll
O2 - BHO: Update Timer - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Messenger Plus - {b760d5a4-8d24-4cb6-942e-d6bb540ad88c} - C:\Program Files (x86)\Messenger_Plus\prxtbMess.dll
O2 - BHO: iToolsBHO - {E1499FE7-129D-4B6E-B681-DDF21E14172C} - C:\Users\Ben\Documents\iTools\Plugin\iToolsBHO.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Messenger Plus Toolbar - {b760d5a4-8d24-4cb6-942e-d6bb540ad88c} - C:\Program Files (x86)\Messenger_Plus\prxtbMess.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)
O4 - HKLM\..\Run: [KeyKeyServer] "C:\Program Files\Yahoo!\KeyKey\KeyKeyServer.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Google Update] "C:\Users\Ben\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [aliim] d:\Program Files (x86)\AliWangWang\aliim.exe /run:auto
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_8B4B86C2A5661DC92D9A84E265233F91] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Ben\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: SRS Premium Sound.lnk = ?SystemRoot%\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe
O8 - Extra context menu item: 使用迅雷下载 - C:\Program Files (x86)\Thunder Network\Thunder\Program\geturl.htm
O8 - Extra context menu item: 使用迅雷下载全部连结 - C:\Program Files (x86)\Thunder Network\Thunder\Program\getallurl.htm
O18 - Protocol: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (file missing)
O18 - Protocol: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (file missing)
O18 - Protocol: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (file missing)
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll C:\PROGRA~2\Google\GOOGLE~3\GO36F4~1.DLL
O23 - Service: Afa Card Reader Service (AfaService) - Unknown owner - C:\Windows\system32\afasrv64.exe (file missing)
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
2. 下载/执行 OTM做删除。
copy & paste 以下项目於Paste Instructions for Items to be Moved的框格内。
按MoveIt > OK > 重启电脑。
:files
C:\Users\Ben\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Yahoo!\KeyKey\KeyKeyServer.exe
C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
C:\Program Files (x86)\ShoppingAssistant\ruyitao\3.2.7.0\ShoppingAssistant.dll
C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll
C:\Program Files (x86)\Messenger_Plus\prxtbMess.dll
C:\Users\Ben\Documents\iTools\Plugin\iToolsBHO.dll
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
C:\Program Files (x86)\Messenger_Plus\prxtbMess.dll
C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
C:\PROGRA~2\Google\GOOGLE~3\GO36F4~1.DLL3. 下载/执行Junkware Removal Tool扫毒。执行扫毒前请关闭所有浏览器同程式。
(JRT会自动删除附於浏览器的恶意程式/档案/登录档)
4. 关闭所有防毒软件(包括Windows Defender),下载ComboFix至桌面 ,执行 ComboFix 扫毒。
扫瞄时不要执行其他程式或点击 ComboFix视窗。
(ComboFix扫毒约10 -20分钟,唔使装"修复主控台程式")
完成扫瞄后,ComboFix 报告会自动弹出。
请贴上以下报告:
1. JRT扫毒报告。
2. ComboFix扫毒报告。
3. 新1份Hijackthis扫瞄报告。
1.执行Hijackthis > Do a system scan only > 勾选下列项目 > 按Fix Checked (fix checked时关闭所有browsers/程式) > 按"是"。
引用:
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: 砩杬BHO - {876D0712-C780-4347-B56D-C30C520033C5} - C:\Program Files (x86)\ShoppingAssistant\ruyitao\3.2.7.0\ShoppingAssistant.dll
O2 - BHO: Update Timer - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Messenger Plus - {b760d5a4-8d24-4cb6-942e-d6bb540ad88c} - C:\Program Files (x86)\Messenger_Plus\prxtbMess.dll
O2 - BHO: iToolsBHO - {E1499FE7-129D-4B6E-B681-DDF21E14172C} - C:\Users\Ben\Documents\iTools\Plugin\iToolsBHO.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Messenger Plus Toolbar - {b760d5a4-8d24-4cb6-942e-d6bb540ad88c} - C:\Program Files (x86)\Messenger_Plus\prxtbMess.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)
O4 - HKLM\..\Run: [KeyKeyServer] "C:\Program Files\Yahoo!\KeyKey\KeyKeyServer.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Google Update] "C:\Users\Ben\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [aliim] d:\Program Files (x86)\AliWangWang\aliim.exe /run:auto
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_8B4B86C2A5661DC92D9A84E265233F91] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Ben\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: SRS Premium Sound.lnk = ?SystemRoot%\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe
O8 - Extra context menu item: 使用迅雷下载 - C:\Program Files (x86)\Thunder Network\Thunder\Program\geturl.htm
O8 - Extra context menu item: 使用迅雷下载全部连结 - C:\Program Files (x86)\Thunder Network\Thunder\Program\getallurl.htm
O18 - Protocol: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (file missing)
O18 - Protocol: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (file missing)
O18 - Protocol: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (file missing)
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll C:\PROGRA~2\Google\GOOGLE~3\GO36F4~1.DLL
O23 - Service: Afa Card Reader Service (AfaService) - Unknown owner - C:\Windows\system32\afasrv64.exe (file missing)
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
copy & paste 以下项目於Paste Instructions for Items to be Moved的框格内。
按MoveIt > OK > 重启电脑。
引用:
:files
C:\Users\Ben\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Yahoo!\KeyKey\KeyKeyServer.exe
C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
C:\Program Files (x86)\ShoppingAssistant\ruyitao\3.2.7.0\ShoppingAssistant.dll
C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll
C:\Program Files (x86)\Messenger_Plus\prxtbMess.dll
C:\Users\Ben\Documents\iTools\Plugin\iToolsBHO.dll
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
C:\Program Files (x86)\Messenger_Plus\prxtbMess.dll
C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
C:\PROGRA~2\Google\GOOGLE~3\GO36F4~1.DLL
(JRT会自动删除附於浏览器的恶意程式/档案/登录档)
4. 关闭所有防毒软件(包括Windows Defender),下载ComboFix至桌面 ,执行 ComboFix 扫毒。
扫瞄时不要执行其他程式或点击 ComboFix视窗。
(ComboFix扫毒约10 -20分钟,唔使装"修复主控台程式")
完成扫瞄后,ComboFix 报告会自动弹出。
请贴上以下报告:
1. JRT扫毒报告。
2. ComboFix扫毒报告。
3. 新1份Hijackthis扫瞄报告。
作者: SILVESTERABEND 发布时间: 2013-06-04
Thank u very much for helping,
Please find the log file in the attachment : )
(Sorry, I can't type Chinese after the virus scan...so I had to type in English)
log.txt(171.08 KB)
JRT.txt(28.55 KB)
hijackthis.log(12.35 KB)
Please find the log file in the attachment : )
(Sorry, I can't type Chinese after the virus scan...so I had to type in English)

2013-6-4 06:28 PM, 下载次数: 1

2013-6-4 06:28 PM, 下载次数: 1

2013-6-4 06:28 PM, 下载次数: 1
作者: sh000810 发布时间: 2013-06-04
相关阅读 更多
热门阅读
-
office 2019专业增强版最新2021版激活秘钥/序列号/激活码推荐 附激活工具
阅读:74
-
如何安装mysql8.0
阅读:31
-
Word快速设置标题样式步骤详解
阅读:28
-
20+道必知必会的Vue面试题(附答案解析)
阅读:37
-
HTML如何制作表单
阅读:22
-
百词斩可以改天数吗?当然可以,4个步骤轻松修改天数!
阅读:31
-
ET文件格式和XLS格式文件之间如何转化?
阅读:24
-
react和vue的区别及优缺点是什么
阅读:121
-
支付宝人脸识别如何关闭?
阅读:21
-
腾讯微云怎么修改照片或视频备份路径?
阅读:28