Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Infosec By G666h05t & AnonGhost Indonesia
- rogue software tampering with ie homepage
- 1) The registry value corresponding to the internet option:
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
- The value of this item is synchronized with the home page in the ie option, you can try it first.
- 2) Bind the operating parameters of the ie main program:
- HKEY_CLASSES_ROOT\Applications\iexplore.exe\shell\open\command
- ie main program operating parameters
- The normal value of this item is "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1. The rogue software appends its own website address as a running parameter, then it will automatically jump to when opening the main program of ie The website, this trick is ruthless.
- 3) Bind the ieframe.dll home page command of the ie form control:
- HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command
- Home page command of ie form control
- The default value of this item is "C:\Program Files\Internet Explorer\iexplore.exe". Similarly, rogue URLs may be appended to block the homepage.
- 4) Bind ie shortcut operation target:
- There is also a method that can't be searched in the registry, but is far away in front of you, is to modify the run target in the ie shortcut properties. Note that it is a shortcut, not the ie icon displayed by default on the desktop. There are four normal ie shortcuts:
- ie shortcut
- It can be seen that the above three ie shortcuts are created by the desktop ie icon, by the ie icon at the top of the start menu, and by the system disk ie main program (Of course, if you hide the extension, the third shortcut will not be available. exe suffix), the fourth is the "Start Internet Explorer" icon on the quick launch bar to the right of the start button. Right-click to view these shortcut properties:
- Ie shortcut created from the start menu ie icon
- Shortcut created by the ie icon in the quick launch bar
- 6) The author has deleted the icon to start IE in the quick launch bar. I put a pen to memorialize, and come from afar, so the window above is slightly foreign. For these two shortcuts, the target default value is "C:\Program Files\Internet Explorer\iexplore.exe". Now the virus is free to drill. As long as you append your own URL to the back, then you can use this icon When you open IE, you will immediately jump to its web site, which is extremely versatile.
- 7)Therefore, I suggest that if the homepage is tampered with and cannot be changed back, please right-click the shortcut opened when you start IE, and see if there is an additional URL after the property "Target", delete it if there is any; if not, go to the registry Check out those possible locations:
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
- HKEY_CLASSES_ROOT\Applications\iexplore.exe\shell\open\command
- HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command
- Find US in telegram : t.me/AnonGhostid
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement