记分析病毒时遇到的跟IE相关的注册表项

1.病毒破坏IE的右键打开方式。右击打开后跳转到病毒指定网页:

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command

[(默认)]     C:\Program Files\Internet Explorer\IEXPLORE.EXE http://www.sky238.com/?107


2.病毒添加了恶意的IE加载项:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExplorer\Extensions\{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}


3.破坏HTTP启动关联,导致点击后跳到指定网页:

HKEY_CLASSES_ROOT\HTTP\shell\open\command

[(默认)]     C:\Program Files\Internet Explorer\IEXPLORE.EXE http://www.sky238.com/?107

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HTTP\shell\open\command

[(默认)]     C:\Program Files\Internet Explorer\IEXPLORE.EXE http://www.sky238.com/?107


4.隐藏IE桌面图标:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel

[871C5380-42A0-1069-A2EA-08002B30309D]        0x00000001(1)

当windows使用经典主题时,隐藏IE桌面图标:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu

[871C5380-42A0-1069-A2EA-08002B30309D]         0x00000001(1)




你可能感兴趣的:(windows,shell,Microsoft,IE,command,internet)