病毒修改的注册表项:
项:HKCR\exefile\shell\open\command\
健值:默认
指向数据:病毒原程序当前所在路径 "%1" %*"
项:HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
健值:exloroe
指向数据:%systemroot%\system32\exloroe.com
项:HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\
健值:NoBrowserOptions
指向数据:01
项:HKCU\Software\Policies\Microsoft\Windows\System\
健值:DisableCMD
指向数据:02
项:HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
健值:NoCommon Groups
指向数据:01
项:HKCU\Control Panel\Desktop\
健值:AutoEndTasks
指向数据:01
项:HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\
健值:CheckedValue
指向数据:01
项:HKCU\Software\Microsoft\Windows\Current Version\Policies\Explorer\
健值:NoFolderOptions
指向数据:01
项:HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
健值:DisableTaskMgr
指向数据:01
项:HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
健值:DisableRegistryTools
指向数据:01
项:HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
健值:ShowSuperHidden
指向数据:00
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}
HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}
HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318} |
|