打电话的时候随手点了查毒,结果...
ps,不管有没有事,算不算误报,并不是要针对谁谁,亦不代表在下,请不要人身攻击...
个人建议是无视之。
文件: hard.disk.sentinel.pro-MPT.zip
中文名称: Win32.Malware.Heur_Generic.B
病毒类型: 恶意软件 广告病毒
影响系统: winNT/win2000/winXP/win2003/vista/win7
首次传播: 2011-04-25
危险程度:4级(1-5级,1弱5强,增值0.5)
行为分析:
这是一个广告病毒,该病毒会篡改浏览器,同时会自动安装一款超速浏览器,并且会在桌面上生成很多如:八卦色图、创业投资好项目、网址大全等恶意广告,同时对一些文件进行修改和删除,对注册表进行修改,严重影响系统。
修改注册表:
HKLM\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage
HKLM\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command
HKU\S-1-5-21-1004336348-1383384898-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012008092120080922
增加注册表信息:
HKLM\SOFTWARE\Classes\CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}\shell
HKLM\SOFTWARE\Classes\CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}\shell\Open
HKLM\SOFTWARE\Classes\CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}\shell\Open\Command
HKLM\SOFTWARE \Classes\CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}\shell\创业投资好项目 (&C)
HKLM\SOFTWARE\Classes\CLSID\{1f4de370-d627-11d1-ba4f- 00a0c91eedba}\shell\创业投资好项目(&C)\Command
HKLM\SOFTWARE\Classes \CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}\shell\属性(&R)
HKLM\SOFTWARE \Classes\CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}\shell\属性(&R) \Command
HKLM\SOFTWARE\Classes\CLSID\{1f4de370-d627-11d1-ba4f- 00a0c91eedba}\shell\淘宝网(&T)
HKLM\SOFTWARE\Classes\CLSID \{1f4de370-d627-11d1-ba4f-00a0c91eedba}\shell\淘宝网(&T)\Command
HKLM\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\Loading0
HKLM\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\Loading0\Command
HKLM\SOFTWARE \Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\创业投资好项目 (&C)
HKLM\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA- 08002B30309D}\shell\创业投资好项目(&C)\Command
HKLM\SOFTWARE\Classes \CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\淘宝网(&T)
HKLM\SOFTWARE \Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\淘宝网(&T) \Command
HKLM\SOFTWARE\Classes\CLSID\{e17d4fc0-5564-11d1-83f2-00a0c90dc849}\shell
HKLM\SOFTWARE\Classes\CLSID\{e17d4fc0-5564-11d1-83f2-00a0c90dc849}\shell\Open
HKLM\SOFTWARE\Classes\CLSID\{e17d4fc0-5564-11d1-83f2-00a0c90dc849}\shell\Open\Command
HKLM\SOFTWARE \Classes\CLSID\{e17d4fc0-5564-11d1-83f2-00a0c90dc849}\shell\创业投资好项目 (&C)
HKLM\SOFTWARE\Classes\CLSID \{e17d4fc0-5564-11d1-83f2-00a0c90dc849}\shell\创业投资好项目(&C)\Command
HKLM\SOFTWARE \Classes\CLSID\{e17d4fc0-5564-11d1-83f2-00a0c90dc849}\shell\属性(&R)
HKLM\SOFTWARE \Classes\CLSID\{e17d4fc0-5564-11d1-83f2-00a0c90dc849}\shell\属性(&R) \Command
HKLM\SOFTWARE\Classes\CLSID \{e17d4fc0-5564-11d1-83f2-00a0c90dc849}\shell\淘宝网(&T)
HKLM\SOFTWARE \Classes\CLSID\{e17d4fc0-5564-11d1-83f2-00a0c90dc849}\shell\淘宝网(&T) \Command
HKLM\SOFTWARE\WinRAR
添加广告:
C:\Documents and Settings\All Users\「开始」菜单\程序\Internet Explorer.lnk
C:\Documents and Settings\All Users\「开始」菜单\Internet Explorer.lnk
C:\Documents and Settings\All Users\桌面\超速浏览器.lnk
C:\Documents and Settings\terry\Cookies\terry@219.151.4[2].txt
C:\Documents and Settings\terry\Cookies\terry@linezing[1].txt
C:\Documents and Settings\terry\Cookies\terry@m.weather.com[1].txt
C:\Documents and Settings\terry\Cookies\terry@www.q22[1].txt
C:\Documents and Settings\terry\Favorites\八卦色图.url
C:\Documents and Settings\terry\Favorites\在线电影.url
C:\Documents and Settings\terry\Favorites\网址大全.url
目录增加:
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson
C:\Documents and Settings\terry\Local Settings\History\History.IE5\MSHist012010060120100602
C:\Program Files\Chaosu
C:\Program Files\pqvww
目录删除
C:\Documents and Settings\terry\Local Settings\History\History.IE5\MSHist012008092120080922
个人建议:有人中彩的话,自己手动下好了,反正也不多不难。 |