電腦安全 - 首頁被Qvo6.com綁架了 - 電腦

前往內容


首頁被Qvo6.com綁架了

AdwCleaner 程式跑完後 要記得原本訂選在桌面的ie chrome 捷徑移除 從program 裡再重新拉捷徑到桌面 應該就沒問題了
朋友的電腦剛告訴我被Qvo6.com綁架一直無法連yahoo
結果就找到這裡。謝謝樓主提供這麼好的工具程式3q
剛剛也被Qvo6綁架了. 幸虧網上找到了AdwCleaner這個神器, 才把這個可惡的麻煩除掉. 看了一下AdwCleaner留下來的清潔單, 真的被Qvo6嚇到了. 它在系統上改的地方實在太多了. 沒了AdwCleaner, 恐怕只剩下重灌這招了.

AdwCeaner 清潔單 (Qvo6 連接全換掉了):

# AdwCleaner v2.304 - Logfile created 07/08/2013 at 17:17:40
# Updated 03/07/2013 by Xplode
# Operating system : Windows 8.1 Pro Preview with Media Center (64 bits)
# User : XXXX - XXXX
# Boot Mode : Normal
# Running from : D:\Downloads\hxxp\Programs\adwcleaner.exe
# Option [Delete]


***** [Services] *****

***** [Files / Folders] *****

File Deleted : C:\Users\Cantor\AppData\Local\Temp\Uninstall.exe
File Deleted : D:\Data\Users\Cantor\Desktop\TornTV.lnk
File Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
File Disinfected : C:\Users\Cantor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
File Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk
Folder Deleted : C:\Program Files (x86)\Desk 365
Folder Deleted : C:\Program Files (x86)\TornTV.XXX
Folder Deleted : C:\ProgramData\eSafe
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Users\Cantor\AppData\Roaming\eIntaller
Folder Deleted : C:\Users\Cantor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.XXX
Folder Deleted : C:\Users\Cantor\AppData\Roaming\SogouExplorer

***** [Registry] *****

Data Deleted : HKLM\...\StartMenuInternet\Google Chrome [(Default)] = "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://www.qvo6.XXX/?utm_source=b&utm_medium=ild&from=ild&uid=ST1000DM003-1CH162_Z1D4YQHDXXXXZ1D4YQHD&ts=1373273913
Data Deleted : HKLM\...\StartMenuInternet\IEXPLORE.EXE [(Default)] = C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.qvo6.XXX/?utm_source=b&utm_medium=ild&from=ild&uid=ST1000DM003-1CH162_Z1D4YQHDXXXXZ1D4YQHD&ts=1373273913
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13D095-45C3-4271-9475-F3B48227DD9F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5911488E-9D1E-40EC-8CBB-06B231CC153F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13D095-45C3-4271-9475-F3B48227DD9F}
Key Deleted : HKCU\Software\Zugo
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\Software\Desksvc
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\qvo6Software
Key Deleted : HKLM\Software\V9
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IM
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Tarma Installer

***** [Internet Browsers] *****

-\\ Internet Explorer v11.0.9431.0

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.qvo6.XXX/?utm_source=b&utm_medium=ild&from=ild&uid=ST1000DM003-1CH162_Z1D4YQHDXXXXZ1D4YQHD&ts=1373273913 --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://www.qvo6.XXX/?utm_source=b&utm_medium=ild&from=ild&uid=ST1000DM003-1CH162_Z1D4YQHDXXXXZ1D4YQHD&ts=1373273913 --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://www.qvo6.XXX/?utm_source=b&utm_medium=ild&from=ild&uid=ST1000DM003-1CH162_Z1D4YQHDXXXXZ1D4YQHD&ts=1373273913 --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.qvo6.XXX/?utm_source=b&utm_medium=ild&from=ild&uid=ST1000DM003-1CH162_Z1D4YQHDXXXXZ1D4YQHD&ts=1373273913 --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://www.qvo6.XXX/?utm_source=b&utm_medium=ild&from=ild&uid=ST1000DM003-1CH162_Z1D4YQHDXXXXZ1D4YQHD&ts=1373273913 --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.qvo6.XXX/?utm_source=b&utm_medium=ild&from=ild&uid=ST1000DM003-1CH162_Z1D4YQHDXXXXZ1D4YQHD&ts=1373273913 --> hxxp://www.google.com

-\\ Google Chrome v27.0.1453.116

File : C:\Users\Cantor\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.3784] : urls_to_restore_on_startup = [ "hxxp://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid[...]

*************************

AdwCleaner[R1].txt - [5353 octets] - [08/07/2013 17:17:04]
AdwCleaner[S1].txt - [5008 octets] - [08/07/2013 17:17:40]

########## EOF - C:\AdwCleaner[S1].txt - [5068 octets] ##########
藤木 wrote:
真的很討厭被綁架的感覺

大陸這類型網站很多, ^^
超雞巴的!

judy30017 wrote:
我用GOOGLE查「...(恕刪)



八樓大大,已試過您教的方法了。
但還是行不通耶...
討人厭的Qvo6還是存在!!!!!!

真的只剩重灌的方法了嗎?

huli1233 wrote:
八樓大大,已試過您教...(恕刪)


可以試試看Windows的系統還原,或許有機會喔!
要時常存著善念,並用感恩、懺悔、包容的心來面對一切......

judy30017 wrote:
我用GOOGLE查「qvo6 網頁被綁」很久都找不到解決辦法
後來想說用「qvo6 remove」試試看
看了搜尋第二個像是奇摩知識家的網站裡分享一個實用網站

http://www.bleepingcomputer.com/download/adwcleaner/

裡面都是英文
用網頁翻譯照著說明做就可以了
一開始我也很擔心但是一直跳出qvo6實在太煩了
所以決心一試

連結網址裡也有說明圖
下載後按Search後會跳出一個列出你電腦所有惡意廣告程式的記事本
再按下Delete之後會重新開機
開機後一樣會跳出個記事本

結果
!!!!!!!!!!!!!!GOOGLE和火狐和IE三個瀏覽器都得救了!!!!!!!!!!!!!!!

整個頁面變好清爽啊!!!!!!!!!!!!!!!!!!!!開心的不得了~~~~~~~~


這很有效喔~連其它惡意程式都一起掃掉了!

月無心 wrote:
我找到方法囉。我的是...(恕刪)


最近這二、三天也是被這網站給綁架
試了一下這個方法之後真的很有效
只是試了之後只有被釘在工作列裡的IE有被綁架,桌面上的IE則是正常(也就是一開啟便是雅虎
於是就只有刪了工作列上的IE

我也中了這網頁兩次綁架,

其實我覺得二樓的方式蠻好用的。

首先先看看有沒有被安裝了附加元件,有的話請先刪除。

接著到各個IE上點右鍵> 內容

此時可以看見 " 目標" 項目被修改了。在啟動的位置後面多加了Qvo6的網址。

只要將其刪除即可。

以chrome為例:

http://imageshack.us/photo/my-images/593/s0d2.jpg/

judy30017 wrote:
我用GOOGLE查「...(恕刪)


太感謝大大了!!
下載完後搜尋之後刪除真的就好了....
IE 和 GOOGLE CHROME 一起得救!!
再次感謝提供解決的辦法<(_"_)>

4頁 (共6頁) » 分享到

前往



廣告