查看: 4166|回复: 13
收起左侧

[可疑文件] 注册表项,360报了 大伙看看

[复制链接]
梦幻舞步
发表于 2014-7-19 10:52:40 | 显示全部楼层 |阅读模式
全盘扫描时发现的 可是之前实时防护一直没报 是一个不会发作的可疑文件?还是木马残留?

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
卡巴专家
发表于 2014-7-19 10:55:44 | 显示全部楼层
KIS KILL

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
z2009
发表于 2014-7-19 11:23:55 | 显示全部楼层
本帖最后由 z2009 于 2014-7-19 11:28 编辑

avast和火绒扫描均安全

ps:一个文件不需要加密,多此一举了
cn86li
发表于 2014-7-19 12:13:33 | 显示全部楼层
360IS倒是不报
360 Internet Security Scan log

Virus Database version: 2014-07-19 08:17
Date & time: 2014-07-19 12:12:55
Time elapsed: 00:00:00
Type: Manual Scan
Files scanned: 1
Threats: 0
Threats cleared: 0

Current scan settings
----------------------
Scanned all files: Yes
Scanned Zip files: Yes
Resolution: User to decide on resolution
Scanned disk Boot Sector: Yes
Scanned for Rootkit: Yes
Used Cloud Engine: Yes
QVM Engine: Yes
Automatically repair: No
AV Engine settings: BitDefender

Scan content
----------------------
C:\Users\lenovo\Desktop\密码123


Whitelist
----------------------


Scan results
======================
No threats detected
烟花雨
头像被屏蔽
发表于 2014-7-19 13:05:31 | 显示全部楼层
本帖最后由 烟花雨 于 2014-7-19 13:06 编辑

  1. Scan Log
  2. Version of virus signature database: 10120 (20140718)
  3. Date: 7/19/2014 Sat  Time: 1:04:48 PM
  4. Scanned disks, folders and files: C:\Users\Microsoft\Desktop\quick7.reg
  5. Number of scanned objects: 1
  6. Number of threats found: 0
  7. Time of completion: 1:04:49 PM  Total scanning time: 1 sec (00:00:01)
复制代码
fuzhk
发表于 2014-7-19 13:08:24 | 显示全部楼层
本帖最后由 fuzhk 于 2014-7-19 13:29 编辑

貌似是优化win7用的,可能  不一定是病毒吧。
这个都改了些什么啊,一个字都看不懂
Windows Registry Editor Version 5.00

; 侧边栏设置

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Sidebar\Settings]
"AllowElevatedProcess"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Sidebar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Sidebar\Compatibility]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Sidebar\Settings]
;
; 资源管理器设置

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Start_SearchFiles"=dword:00000002
"ServerAdminUI"=dword:00000000
"ShowCompColor"=dword:00000001
"DontPrettyPath"=dword:00000000
"ShowInfoTip"=dword:00000001
"HideIcons"=dword:00000000
"MapNetDrvBtn"=dword:00000000
"WebView"=dword:00000001
"Filter"=dword:00000000
"SeparateProcess"=dword:00000000
"AutoCheckSelect"=dword:00000000
"IconsOnly"=dword:00000000
"ShowTypeOverlay"=dword:00000001
"ListviewAlphaSelect"=dword:00000001
"ListviewShadow"=dword:00000001
"TaskbarAnimations"=dword:00000001
"StartMenuInit"=dword:00000004
"Start_ShowRun"=dword:00000001
"Start_LargeMFUIcons"=dword:00000000
"Start_MinMFU"=dword:0000000a
"Start_JumpListItems"=dword:0000000a
"Start_AdminToolsRoot"=dword:00000000
"StartMenuAdminTools"=dword:00000000
"TaskbarSizeMove"=dword:00000000
"DisablePreviewDesktop"=dword:00000000
"TaskbarSmallIcons"=dword:00000000
"TaskbarGlomLevel"=dword:00000000
"Start_PowerButtonAction"=dword:00000002
"Hidden"=dword:00000001
"HideFileExt"=dword:00000000
"SuperHidden"=dword:00000000
;
; 策略

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000005
"ConsentPromptBehaviorUser"=dword:00000003
"EnableInstallerDetection"=dword:00000000
"EnableLUA"=dword:00000000
"EnableSecureUIAPaths"=dword:00000000
"EnableUIADesktopToggle"=dword:00000000
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000000
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoLowDiskSpaceChecks"=dword:00000001
"NoInternetOpenWith"=dword:00000001
;
; Dont mark new applications

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Start_ShowRecentDocs"=dword:00000000
"Start_TrackDocs"=dword:00000000
;
; Microsoft升级设置

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]
"ConfigVer"=dword:00000001
"AUOptions"=dword:00000002
"IncludeRecommendedUpdates"=dword:00000001
"ScheduledInstallDay"=dword:00000000
"ScheduledInstallTime"=dword:00000012
;
; 当BSOD(蓝屏)时关闭自动重启

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl]
"AutoReboot"=dword:00000000
;
; MSN设置

[HKEY_CURRENT_USER\Software\Microsoft\MSNMessenger]
"AppSettings"=hex(3):62,04,01,00
"ShowEmoticons"=hex(3):01,00,00,00
"ShowCustomEmoticons"=hex(3):01,00,00,00
"PlayWinks"=hex(3):01,00,00,00
;
; 关闭休眠

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power]
"HibernateEnable"=dword:00000000
;
; 鼠标设置(获取时间(以毫秒为单位),鼠标指针必须在悬停矩形中停留这么长时间以生成鼠标悬停事件。)

[HKEY_CURRENT_USER\Control Panel\Mouse]
"MouseHoverTime"="50"
;
; 关闭UAC通知(会降低安全性)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UacDisableNotify"=dword:00000001
;
; 显示窗口经典文件夹 (文件 |编辑 | 视图 | 工具 | 帮助)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"AlwaysShowMenus"=dword:00000001
;
; 关闭系统托盘图标组

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"TaskbarGlomming"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer]
"EnableAutoTray"=dword:00000000

; 在设备管理器中显示详细设备设置

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment]
"DEVMGR_SHOW_DETAILS"="1"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]
"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=dword:00000000
;
; 在设备管理器中显示全部隐藏设备

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment]
"DEVMGR_SHOW_NONPRESENT_DEVICES"=1
;
; 删除" - 快捷方式" 后缀

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer]
"link"=hex:00,00,00,00
;
; Cleartype

[HKEY_CURRENT_USER\Control Panel\Desktop]
"FontSmoothing"="2"
"FontSmoothingType"=dword:00000002
;
; 设置经典小图标的控制面板

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel]
"AllItemsIconView"=dword:00000001
"StartupPage"=dword:00000001

; 资源管理器窗口最小化时显示完整路径

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState]
"FullPath"=dword:00000001
;
; 在命令窗口中的文本为白色

[HKEY_CURRENT_USER\Software\Microsoft\Command Processor]
"DefaultColor"=dword:0000000F
;
; 禁用网络服务-绕过“浏览网页”文件关联,打开未知扩展。“打开方式...”就变成默认

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"NoInternetOpenWith"=dword:00000001

; 禁用追踪损坏的快捷链接

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoResolveTrack"=dword:00000001
;
; 用Microsoft不需要的制作Windows注册

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion]
"RegDone"="1"
;
; 远程注册表

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry]
"Start"=dword:00000004
;
; 在开始菜单关闭'使用大图标'

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Start_LargeMFUIcons"=dword:00000000
;
; 关闭NTFS最后访问的时戳
; (speeds up viewing folders in ntfs)
; (00000000 = disabled, 00000001 = enabled)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem]
"NtfsDisableLastAccessUpdate"=dword:00000000
;
; 记事本保存窗口位置

[HKEY_CURRENT_USER\Software\Microsoft\Notepad]
"fSaveWindowPositions"=dword:00000001

; 关闭 'Windows Defender'启动

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=-

; 开启记事本状态栏

[HKEY_CURRENT_USER\Software\Microsoft\Notepad]
"StatusBar"=dword:00000001

;关闭驱动程序验证
[HKEY_CURRENT_USER\Software\Microsoft\Driver Signing]
"Policy"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Driver Signing]
"Policy"=hex:01

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows NT\Driver Signing]
"BehaviorOnFailedVerify"=dword:00000001

;管理员取得所有权
[HKEY_CLASSES_ROOT\*\shell\runas]

@="管理员取得所有权"

"NoWorkingDirectory"=""  

[HKEY_CLASSES_ROOT\*\shell\runas\command]

@="cmd.exe /c takeown /f \"%1\" && icacls \"%1\" /grant administrators:F"

"IsolatedCommand"="cmd.exe /c takeown /f \"%1\" && icacls \"%1\" /grant administrators:F"  

[HKEY_CLASSES_ROOT\exefile\shell\runas2]

@="管理员取得所有权"

"NoWorkingDirectory"=""  

[HKEY_CLASSES_ROOT\exefile\shell\runas2\command]

@="cmd.exe /c takeown /f \"%1\" && icacls \"%1\" /grant administrators:F"

"IsolatedCommand"="cmd.exe /c takeown /f \"%1\" && icacls \"%1\" /grant administrators:F"  

[HKEY_CLASSES_ROOT\Directory\shell\runas]

@="管理员取得所有权"

"NoWorkingDirectory"=""  

[HKEY_CLASSES_ROOT\Directory\shell\runas\command]

@="cmd.exe /c takeown /f \"%1\" /r /d y && icacls \"%1\" /grant administrators:F /t"

"IsolatedCommand"="cmd.exe /c takeown /f \"%1\" /r /d y && icacls \"%1\" /grant administrators:F /t"

;
;网络加速
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Tcpip\Parameters]
"GlobalmaxTcp WindowSize"=dword:0003ebc0

;桌面显示快捷图标
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]
"{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=dword:00000000
"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=dword:00000000
"{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=dword:00000000

;桌面显示IE图标
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{00000000-0000-0000-0000-100000000001}]
@="Internet Explorer"

[HKEY_CLASSES_ROOT\CLSID\{00000000-0000-0000-0000-100000000001}]
@="Internet Explorer"

[HKEY_CLASSES_ROOT\CLSID\{00000000-0000-0000-0000-100000000001}\DefaultIcon]
@="C:\\Windows\\System32\\ieframe.dll,-190"

[HKEY_CLASSES_ROOT\CLSID\{00000000-0000-0000-0000-100000000001}\shell]
@=""

[HKEY_CLASSES_ROOT\CLSID\{00000000-0000-0000-0000-100000000001}\shell\NoAddOns]
@="无加载项(&N)"

[HKEY_CLASSES_ROOT\CLSID\{00000000-0000-0000-0000-100000000001}\shell\NoAddOns\Command]
@="\"C:\\Program Files\\Internet Explorer\\iexplore.exe\" -extoff"

[HKEY_CLASSES_ROOT\CLSID\{00000000-0000-0000-0000-100000000001}\shell\Open]
@="打开主页(&H)"

[HKEY_CLASSES_ROOT\CLSID\{00000000-0000-0000-0000-100000000001}\shell\Open\Command]
@="\"C:\\Program Files\\Internet Explorer\\iexplore.exe\""

[HKEY_CLASSES_ROOT\CLSID\{00000000-0000-0000-0000-100000000001}\shell\Set]
@="属性(&R)"

[HKEY_CLASSES_ROOT\CLSID\{00000000-0000-0000-0000-100000000001}\shell\Set\Command]
@="\"C:\\Windows\\System32\\rundll32.exe\" C:\\Windows\\System32\\shell32.dll,Control_RunDLL C:\\Windows\\System32\\inetcpl.cpl"
;
;去除新建快捷方式前面的"新建快捷方式 "字串
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer]
"Link"=hex:00,00,00,00

;加快Windows 7任务栏预览缩略图的弹出速度
[HKEY_CURRENT_USER\Control Panel\Mouse]
"MouseHoverTime"="10"

;保持网络连接
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"KeepRasConnections"="1"

;优化IRQ
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\PriorityControl]
"IRQ8Priority"=dword:00000001

;开启TCP/IP半开连接数限制
[HKEY_LOCAL_MACHINESYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
"EnableConnectionRateLimiting"=dword:00000000

;打造单进程版IE 8
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"TabProcGrowth"=dword:00000001

;IE8 - 开启图像自动缩放
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Enable AutoImageResize"="yes"
;
;开启记事本的自动换行
[HKEY_CURRENT_USER\Software\Microsoft\Notepad]
"fWrap"=dword:00000001

;用记事本打开NFO文件
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nfo]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nfo\OpenWithList]
"a"="NOTEPAD.EXE"
"MRUList"="a"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nfo\OpenWithProgids]
"MSInfoFile"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nfo\UserChoice]
"Progid"="Applications\\notepad.exe"

;加快Windows 7 系统开机速度
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters]
"EnablePrefetcher"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Memory Management\PrefetchParameters]
"EnablePrefetcher"=dword:00000000

;加快Windows 7 系统关机速度
[HKEY_CURRENT_USER\Control Panel\Desktop]
"AutoEndTasks"="1"
"HungAppTimeout"="500"
"WaitToKillAppTimeout"="2000"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control]
"WaitToKillServiceTimeout"="2000"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control]
"WaitToKillServiceTimeout"="2000"

;添加百度和搜索代码(修改默认搜索引擎)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{CDB051F2-166F-408A-B5AD-852FBEB67EB5}"
"Version"=dword:00000001

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CDB051F2-166F-408A-B5AD-852FBEB67EB5}]
"DisplayName"="百度"
"URL"="http://www.baidu.com/s?wd={searchTerms}&tn=97cool_pg&cl=3&ie=utf-8"
"Codepage"=dword:0000fde9
King、暮光
发表于 2014-7-19 13:19:36 | 显示全部楼层
红伞MISS 毒霸MISS
XywCloud
发表于 2014-7-19 13:39:38 | 显示全部楼层
这个注册表应该没啥问题
把内容从头到尾都看了一遍
herobobo21
发表于 2014-7-19 13:54:49 | 显示全部楼层
应该是误报,应该是优化行为,对注册表有行为,有些杀毒软件就报了!!
梦幻舞步
 楼主| 发表于 2014-7-19 14:28:34 | 显示全部楼层
z2009 发表于 2014-7-19 11:23
avast和火绒扫描均安全

ps:一个文件不需要加密,多此一举了

好的,多谢提醒
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-6-12 20:10 , Processed in 0.185258 second(s), 22 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表