First Aid! What's wrong with the computer automatically popping up web pages, virus?

windows optimizer download the following, can remove rogue software!

IE homepage was changed and malicious code solution IE homepage was changed and malicious code solution

About malicious webpage modification registry:Through the use of ActiveX to modify the registry important items to achieve the purpose of destruction. As for Applet, ActiveX and java and vb scripting languages, please interested friends to understand their own understanding (mainly through the local machine on the WSH parsing and in the local machine to execute the code or activate the application). Luckily, antivirus programs nowadays have added the ability to put malicious code.

To stop malicious code from modifying the registry:

1. Most of the malicious code is only effective on IE5.0 version, so upgrade IE to 6.0 and download and patch it in time! Download and install the latest version of Microsoft WSH, which seems to be version 5.6!

2, install the latest antivirus software, open real-time monitoring to protect the Internet security, because it can block most of such malicious code!

3, vigilance a little better, do not be bad temptation, try not to go on you do not know or unfamiliar with the site! (The recent "web greeting cards" may also be a way to spread the word!)

4, set ie security level, do not recommend, because this is a little choking, ostrich policy feeling!

5, prohibit the editing of the registry, win2000 with the prohibition of remote editing of the registry!

6, download Optimizer, Super Rabbit Magic Settings, Kingsoft Registry Recoverer, "Magic Stone" web page (provided by 3721, "Magic Stone", the suffix for the url, html, htm are hooked off. If there is something like regedit /s *** also remove, its role is to change the registry every time.

2, start - run - (enter) regedit to find the following keys: [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\\Run CurrentVersion\Run] (This is the most critical place)


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce USER\Software\Microsoft\Windows\CurrentVersion\Run]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices Delete the content described in Method 1 after finding it.

16, remove the Tools menu in the Web site

Remove the IE toolbar inside the icon ads, as well as the above Tools drop-down menu ads

Remove: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions The key value under can be deleted.

17, Site ads are added in front of time

Site ads are added in front of time.

Recovery method: change to the system default

[HKEY_CURRENT_USER\Control Panel\International]


18, IE browser link was changed to site advertising


Registry key: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]


19. Ads are being added next to that globe in the lower right corner (above the time) This one is unusual! Hard to come across, but when you do you can't find it!

Find [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] under the "DisplayName"="Change what you like!"

20, prohibit the download

Registry:HKEY_USERS\\\.DEFAULT\\\\\ Software\\\\ Microsoft\\ Windows\\\\ CurrentVersion\\\\Internet Settings\\Zones\\3\\1803

< p>The key value of 3 is to prohibit the download, 0 is to allow the download

21, browse the web page to start the menu has been modified

This is the most "ruthless" one, so that the viewer has a feeling of life and death. After browsing, not only are there symptoms similar to those described above

there will be more tragic encounters:

1) prohibit "shut down the system"

2) prohibit "run"

3) prohibit "Logout"

4)Hide C drive - your C drive can't be found!

5)Disable registry editor regedit

6)Disable DOS programs

7)Make the system unable to enter "real mode"

8)Disable running any programs

Recovering hidden hard disk HKEY_CURRENT_USER\\\bordeaux

Recovering hidden hard disk HKEY_CURRENT_USER\bordeaux

Hidden hard disk CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives key can be deleted

Since the HKEY_CURRENT_USER\Software\ Microsoft\Windows\ CurrentVersion\Policies\Explorer three new "DWORD" values, the name of which are "NoRun" (shield "run"), "NoFind" (shield "find"), "NoClose" (shield "close the system"), and the value of which is "1". Restart the system after the implementation of the "Run" and "close the system" command prompted by the operation is restricted and canceled, at the same time you will find the "Start" menu in the "Find" option is not available, to re-establish its settings, you can remove the corresponding key or key value set to "0" that is.