|
|
发表于 2005-8-4 18:04:09
|
显示全部楼层
[注意]深山红叶启动光盘(WinPE&PE Builder)讨论专帖(违令者必删)
今天受Norton那个INF文件的启发,修改并完善了UnHookExec.inf文件,用于当系统的EXE文件关联被恶意修改后不能执行任何程序时,右击这个文件将注册表还原为非常安全的状态(同时也可修复多种隐蔽的自动加载的木马病毒对注册表的感染)。内容如下,保存为 UnHookExec.inf 文件,设计意图是当任何程序都已经关闭并无法运行时,通过光盘的 Autorun 功能打开工具盘的光盘菜单;再利用菜单的目录调用功能打开该文件所在的目录,然后就可以用鼠标右击、选择安装命令安装了。
但光盘自动运行也被禁用怎么办?一般情况下如果用户对自动运行进行了禁用,则往往也进行了其他类似的安全设置和防护,注册表被修改到任何程序都不能用的可能性比较小。如果真的仍然EXE关联被修改而自动运行无效,则你只有将注册表编辑器改个扩展名(.com)然后手工修改了!因此下个版本考虑同时放一个修改了扩展名的regedit.com文件到PE系统目录,以便紧急时在“运行”对话框中调用(如:f:\pexp\system32\regedit.com)。大家看看对此有没有更好的办法?
UnHookExec.inf 文件内容:
[Version]
Signature="$Chicago$"
Provider=HFUT
[DefaultInstall]
AddReg=UnhookRegKey
[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\cmdfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\txtfile\shell\open\command,,,""notepad.exe" %1"
HKLM, Software\CLASSES\inifile\shell\open\command,,,""%SystemRoot%\System32\NOTEPAD.EXE" %1"
HKLM, Software\CLASSES\Folder\shell\open\command,,,""%SystemRoot%\Explorer.exe /idlist,%I,%L""
HKLM, Software\CLASSES\Folder\shell\explore\command,,,""%SystemRoot%\Explorer.exe /e,/idlist,%I,%L""
HKLM, Software\CLASSES\htmlfile\shell\open\command,,,""C:\PROGRA~1\INTERN~1\iexplore.exe"" %1""
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools,0x00000020,0
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon,Userinit,,"%SystemRoot%\system32\userinit.exe,"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon,UIHost,,"logonui.exe"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon,VmApplet,,"rundll32 shell32,Control_RunDLL ""sysdm.cpl"""
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon,Shell,,"%SystemRoot%\Explorer.exe"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon,Shell,,"%SystemRoot%\Explorer.exe"
HKCU, Software\Microsoft\Windows NT\CurrentVersion\Windows,load,,""
HKCU, Software\Microsoft\Windows NT\CurrentVersion\Windows,run,,""
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks,,,,
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows,AppInit_DLLs,,"UmxSbxExw.dll UmxSbxExw.dll"
HKCU, Software\Microsoft\Command Processor,Autorun,,""
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders,Startup,,"%USERPROFILE%\「开始」菜单\程序\启动"
HKCR, CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32,,,"%SystemRoot%\system32\webcheck.dll"
|
|