最近我新下了个游戏
游戏安装完后
经常受到QQ5篡改主页的侵扰
最后实在没办法我就删除了该游戏
然后用瑞星和360杀毒
安全模式下也个杀了一次
后来我为了以防万一,怕瑞星也不篡改而杀不出病毒 就将瑞星也重新修复,升级
再杀了一次
安全模式也再杀了一次
可是现在
仍然还是受到QQ5.COM主页篡改的侵扰
虽然现在一直有防火墙顶
没被篡改过
但是
总是这样提示真的很烦人
而且提示本身也说明了恶意行为还存在
木马还存在
现在恳求各位谁能帮帮忘我
以下是防篡改历史记录
操作 时间 进程名称 数值名称 旧值 新值
修改 2009-04-24 02:07:51 C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\
修改 2009-04-24 02:07:48 C:\WINDOWS\REGEDIT.EXE HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\"C:\Program Files\Internet Explorer\iexplore.exe" "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
http://www.qq5.com/?s修改 2009-04-24 02:07:48 C:\WINDOWS\REGEDIT.EXE HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\START PAGE
http://www.hao123.com/ http://www.qq5.com/?s 修改 2009-04-24 02:07:27 C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\
修改 2009-04-23 22:05:40 C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\
修改 2009-04-23 22:05:38 C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\
修改 2009-04-23 22:05:38 C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\
修改 2009-04-23 22:05:37 F:\PROGRAM FILES\MAX PAYNE\GAME.RXPRJ HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\"C:\Program Files\Internet Explorer\iexplore.exe" "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
修改 2009-04-23 21:50:37 C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\
修改 2009-04-23 21:50:36 F:\PROGRAM FILES\MAX PAYNE\GAME.RXPRJ HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\"C:\Program Files\Internet Explorer\iexplore.exe" "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
修改 2009-04-23 01:59:14 C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\
修改 2009-04-23 01:59:13 F:\PROGRAM FILES\MAX PAYNE\GAME.RXPRJ HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\"C:\Program Files\Internet Explorer\iexplore.exe" "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
修改 2009-04-23 01:22:55 C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\
修改 2009-04-23 01:22:47 F:\PROGRAM FILES\MAX PAYNE\GAME.RXPRJ HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\"C:\Program Files\Internet Explorer\iexplore.exe" "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; User-agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; http://bsalsa.com) ; .NET CLR 2.0.50727)| 操作 | 时间 | 进程名称 | 数值名称 | 旧值 | 新值 | | | | | | | |
| 修改 | ######## | C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ |
| 修改 | ######## | C:\WINDOWS\REGEDIT.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ | C:\Program Files\Internet Explorer\iexplore.exe | C:\Program Files\Internet Explorer\IEXPLORE.EXE http://www.qq5.com/?s |
| 修改 | ######## | C:\WINDOWS\REGEDIT.EXE | HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\START PAGE | http://www.hao123.com/ | http://www.qq5.com/?s | | | | | |
| 修改 | ######## | C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ |
| 修改 | ######## | C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ |
| 修改 | ######## | C:\WINDOWS\REGEDIT.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ | C:\Program Files\Internet Explorer\iexplore.exe | C:\Program Files\Internet Explorer\IEXPLORE.EXE http://www.qq5.com/?s |
| 修改 | ######## | C:\WINDOWS\REGEDIT.EXE | HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\START PAGE | http://www.hao123.com/ | http://www.qq5.com/?s | | | | | |
| 修改 | ######## | C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ |
| 修改 | ######## | C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ |
| 修改 | ######## | C:\WINDOWS\REGEDIT.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ | C:\Program Files\Internet Explorer\iexplore.exe | C:\Program Files\Internet Explorer\IEXPLORE.EXE http://www.qq5.com/?s |
| 修改 | ######## | C:\WINDOWS\REGEDIT.EXE | HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\START PAGE | http://www.hao123.com/ | http://www.qq5.com/?s | | | | | |
| 修改 | ######## | C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ |
| 修改 | ######## | C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ |
| 修改 | ######## | C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ |
| 修改 | ######## | C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ |
| 修改 | ######## | F:\PROGRAM FILES\MAX PAYNE\GAME.RXPRJ | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ | C:\Program Files\Internet Explorer\iexplore.exe | C:\Program Files\Internet Explorer\IEXPLORE.EXE
| | |
| 修改 | ######## | C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ |
| 修改 | ######## | F:\PROGRAM FILES\MAX PAYNE\GAME.RXPRJ | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ | C:\Program Files\Internet Explorer\iexplore.exe | C:\Program Files\Internet Explorer\IEXPLORE.EXE
| | |
| 修改 | ######## | C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ |
| 修改 | ######## | F:\PROGRAM FILES\MAX PAYNE\GAME.RXPRJ | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ | C:\Program Files\Internet Explorer\iexplore.exe | C:\Program Files\Internet Explorer\IEXPLORE.EXE
| | |
| 修改 | ######## | C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SETACL.EXE | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ |
| 修改 | ######## | F:\PROGRAM FILES\MAX PAYNE\GAME.RXPRJ | HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND\ | C:\Program Files\Internet Explorer\iexplore.exe | C:\Program Files\Internet Explorer\IEXPLORE.EXE
| | |
| | | | | | | | | | | | | |