TROJAN STARTPAGE

Trojan/StartPage
病毒類型:木馬
危害等級:*
影響平台:Win9X/2000/XP/NT/Me
Trojan/StartPage修改IE默認頁和搜尋頁,是個dll控制項,該控制項程式中沒有卸載代碼,導致註冊後無法卸載。該控制項插入ie進程,每次打開則顯示自己資源中的html廣告程式。
傳播過程及特徵:
1.創建檔案:
%SystemDir%\config\software,6115328位元組
2.修改註冊表:
病毒通過修改下列註冊表鍵值,改變IE默認主頁等信息:
/HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExplorer\Main
"SearchPage"=res://%43%3a%5c%6c%69%6f%6d%2e%64%6c%6c/%73%70%2e%68%74%6d%6c
/HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExplorer\Main
"StartPage"=about:blank
/HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExplorer\Main
"HOMEOldSP"=about:blank
/HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExplorer\Main
"SearchBar"=res://%43%3a%5c%6c%69%6f%6d%2e%64%6c%6c/%73%70%2e%68%74%6d%6c
/HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExplorer\Main
"UseSearchAsst"=no
/HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExplorer\Main
"UseCustomSearchURL"=
/HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExplorer\Search
"SearchAssistant"=res://%43%3a%5c%6c%69%6f%6d%2e%64%6c%6c/%73%70%2e%68%74%6d%6c
/HKEY_CURRENT_USER\SOFTWARE\Microsoft\InternetExplorer\Extensions\CmdMapping
"NextId"=
/HKEY_CURRENT_USER\SOFTWARE\Microsoft\InternetExplorer\Extensions\CmdMapping
""=
/HKEY_CURRENT_USER\SOFTWARE\Microsoft\InternetExplorer\Main
"StartPage"=about:blank
/HKEY_CURRENT_USER\SOFTWARE\Microsoft\InternetExplorer\Main
"SearchPage"=res://%43%3a%5c%6c%69%6f%6d%2e%64%6c%6c/%73%70%2e%68%74%6d%6c
/HKEY_CURRENT_USER\SOFTWARE\Microsoft\InternetExplorer\Main
"HOMEOldSP"=about:blank
/HKEY_CURRENT_USER\SOFTWARE\Microsoft\InternetExplorer\Main
"SearchBar"=res://%43%3a%5c%6c%69%6f%6d%2e%64%6c%6c/%73%70%2e%68%74%6d%6c
/HKEY_CURRENT_USER\SOFTWARE\Microsoft\InternetExplorer\Main
"UseSearchAsst"=no
/HKEY_CURRENT_USER\SOFTWARE\Microsoft\InternetExplorer\Main
"UseCustomSearchURL"=
/HKEY_CURRENT_USER\SOFTWARE\Microsoft\InternetExplorer\Search
"SearchAssistant"=res://%43%3a%5c%6c%69%6f%6d%2e%64%6c%6c/%73%70%2e%68%74%6d%6c
註:%Windir%為變數,一般為C:\Windows或C:\Winnt;
%System%為變數,一般為C:\Windows\System(Windows95/98/Me),
C:\Winnt\System32(WindowsNT/2000),
或C:\Windows\System32(WindowsXP)。

相關詞條

相關搜尋

熱門詞條

聯絡我們