搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

详细了解

A new installation of Firefox is redirected to "Internet Explorer Emergency Mode" even after AV8 was removed by PCTools, How can I fix this redirection of home page.

  • 2 个回答
  • 62 人有此问题
  • 2 次查看
  • 最后回复者为 jhackg0d

more options

IBM ThinkPad running XPPro Internet Explorer 8 Installed with "IE8-WindowsXP=86-ENU" Firefox ver 3.6.12 Install ver 4.22.0.0

IBM ThinkPad running XPPro Internet Explorer 8 Installed with "IE8-WindowsXP=86-ENU" Firefox ver 3.6.12 Install ver 4.22.0.0

所有回复 (2)

more options

Do a malware check with some malware scan programs.
You need to scan with all programs because each program detects different malware.
Make sure that you update each program to get the latest version of the database before doing a scan.

See also "Spyware on Windows": http://kb.mozillazine.org/Popups_not_blocked and What to do when searches take you to the wrong search website

If you can't fix it with the above listed scanners then you need to ask advice on one of the forums that specialize in malware removal mentioned in the Popups_not_blocked article.

more options

Check Image File Execution Key...

The following instructions involve removing registry entries, which can severely bork your computer unless you know what you're doing. Please make sure you exercise caution and proceed at your own risk.

Regedit

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]

If you were/are currently infected with AV8... you'll see keys underneath the Image File Execution such as chrome.exe, firefox.exe, opera.exe., iexplore.exe

Do NOT delete DIINXOptions or IEInstal.exe under this branch in the registry.

Delete the full key for any browser name you see there. If you look inside any one of those keys, it will show you that it routes to iesafemode.exe which is a piece of malware in and of itself

IE - Remove Chrome.exe, which specifically references iesafemode.exe

After performing this, you'll probably want to remove the actual piece of malware known as "iesafemode.exe"

32 bit - C:\windows\system32\iesafemode.exe

64 bit - C:\windows\syswow64\iesafemode.exe