IE is hijacked by www.537.com and www. coxdx. info ~

Source: Internet
Author: User

In a colleague's computer, ie has been using the 265 web site navigation as the homepage. On this day, it suddenly becomes hxxp: // www. coxdx. info /? Z012 is expired. The modification cannot be returned. Please help me with the repair.

Turn on the Internet option and manually change the homepage to http://www.265.com/, but it cannot be effective. Disable the real-time monitoring of the anti-virus software on the computer, download and install the Jinshan guard for repair, and check for any problems.

Pe_xscan is used to scan logs and analyze the logs. The following suspicious items are found:

 

Pe_xscan 11-03-17 by Purple endurer
2011-6-30 11:35:23
Windows XP Service Pack 3 (5.1.2600)
MSIE: 6.0.2900.5512
Administrator user group
Normal Mode
O2-ieaddon (PPLIVE lite class)
-{EF0D1A14-1033-41A2-A589-240C01EDC078}
= C: \ Program Files \ Internet Explorer \ pplite \ plugin \ pplugin2.dll
| 11:14:36
| Pplugin module | 1, 1, 0, 24
| Pplugin module | Copyright 2008
| 1, 1, 0, 24 |
| Pplugin
| Pplugin. dll

O4-HKLM \ .. \ Run: [duoduobox]
C: \ Program Files \ duoduobox \ duoduotray.exe
O9-IE Toolbar extension button HKLM:
-{8ef13cf9-5b58-4125-bb67-f6c9c3de1e72}-c: \ Program Files \ Baidu \ banlv \ inside. dll
O9-ie tool menu extension item HKLM: Baidu browser companion settings
-{8ef13cf9-5b58-4125-bb67-f6c9c3de1e72 }-
C: \ Program Files \ Baidu \ banlv \ inside. dll

O29-hkcu-start page
= Hxxp: // www. coxdx. info /? Z012
O29-HKLM-start page
= Http://www.265.com/
O29-hkus-start page
= Hxxp: // www.537.com

 

C: \ Documents ents and Settings \ Administrator \ Application Data \ Microsoft \ Internet Explorer \ Quick Launch
Intornot exploror. lnk->
C: \ Program Files \ jishu_145412 \ jishu_1420..exe

 

Open the Registry Editor and change the start page value in HKEY_CURRENT_USER \ Software \ Microsoft \ Internet Explorer \ main
Http://www.265.com /.

 

Kingsoft Guard immediately prompts that the IE homepage has been modified and requires you to confirm whether it is allowed. Of course. Use Kingsoft guard to lock the homepage at http://www.265.com /.

 

For more information about duoduotray.exe, see:
Http://xml.ssdsandbox.net/view/f843b8dbb804349a40a7721482a574da

 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.