--==用户登录==--






 

Hosts反黑辅助:网马防御Kill ActiveX[更新日期:2010-1-19]

转载请注明本文出自:死性不改's Blog~
站点链接:
http://www.clxp.net.cn/
不知道大家是否注意过某些漏洞报道,在文后会加这样一句话。
引用内容 引用内容
官方尚未发布补丁
临时解决方法:
* 为CLSID AE93C5DF-A990-11D1-AEBD-5254ABDD2B69设置kill-bit。

实际上,这就是对漏洞最好的防御方法了。封CLSID的方法早在2004年以前就有了。那时候是为了屏蔽3721自动下载的,所以此方法并不是新方法,但却是很好用的方法!

因为此注册表文件对部分用户会有一些影响,所以未做置顶处理。因为实在是当不起客服的! 希望大家可以多多思考一下。中毒的起因,过程。这样就可以很好的防御病毒了!

网吧可以利用开机通道导入,无需重起即可生效!

显示被隐藏内容 显示被隐藏内容
Windows Registry Editor Version 5.00

#kill-bit MS06-014
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BD96C556-65A3-11D0-983A-00C04FC29E30}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BD96C556-65A3-11D0-983A-00C04FC29E36}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AB9BCEDD-EC7E-47E1-9322-D4A210617116}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0006F033-0000-0000-C000-000000000046}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0006F03A-0000-0000-C000-000000000046}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7F5B7F63-F06F-4331-8A26-339E03C0AE3D}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{06723E09-F4C2-43c8-8358-09FCD1DB0766}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{639F725F-1B2D-4831-A9FD-874847682010}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BA018599-1DB3-44f9-83B4-461454C84BF8}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D0C07D56-7C69-43F1-B4A0-25F5A11FAB19}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E8CCCDDF-CA28-496b-B050-6C07C962476B}]
"Compatibility Flags"=dword:00000400
#kill-bit Yahoo! Messenger 8.1.0.421溢出漏洞
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{24F3EAD6-8B87-4C1A-97DA-71C126BDA08F}]
"Compatibility Flags"=dword:00000400
#kill-bit Apple Quicktime UDTA ATOM整数溢出漏洞
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}]
"Compatibility Flags"=dword:00000400
#kill-bit NCTAudioFile2 ActiveX远程栈溢出漏洞
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{77829F14-D911-40FF-A2F0-D11DB8D6D0BC}]
"Compatibility Flags"=dword:00000400
#kill-bit 百度搜霸ActiveX控件远程代码执行漏洞
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A7F05EE4-0426-454F-8013-C41E3596E9E9}]
"Compatibility Flags"=dword:00000400
#kill-bit PPStream 堆栈溢出漏洞
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}]
"Compatibility Flags"=dword:00000400
#kill-bit 迅雷ActiveX控件DownURL2方式远程缓冲区溢出漏洞
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{EEDD6FF9-13DE-496B-9A1C-D78B3215E266}]
"Compatibility Flags"=dword:00000400
#kill-bit QVOD播放器最新漏洞 2009-2-10注:QVOD3.0版已修复漏洞,故去掉此条
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F3D0D36F-23F8-4682-A195-74C92B03D4AF}]
"Compatibility Flags"=-
#kill-bit 联众
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AE93C5DF-A990-11D1-AEBD-5254ABDD2B69}]
"Compatibility Flags"=dword:00000400
#kill-bit 联众新0day
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{61F5C358-60FB-4A23-A312-D2B556620F20}]
"Compatibility Flags"=dword:00000400
#kill-bit 超星阅读器
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7F5E27CE-4A5C-11D3-9232-0000B48A05B2}]
"Compatibility Flags"=dword:00000400
#kill-bit 迅雷看看
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F3E70CEA-956E-49CC-B444-73AFE593AD7F}]
"Compatibility Flags"=dword:00000400
#kill-bit 未知的CLSID。。。网马里发现的。
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{00EF2092-6AC5-47c0-BD25-CF2D5D657FEB}]
"Compatibility Flags"=dword:00000400
#kill-bit 韩国jetAudio播放器ActiveX控件漏洞2008.1.19发现利用。
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8D1636FD-CA49-4B4E-90E4-0A20E03A15E8}]
"Compatibility Flags"=dword:00000400
#kill-bit MSIE DHTML Edit跨站脚本漏洞
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}]
"Compatibility Flags"=dword:00000400
#kill-bit Microsoft IE navcancl.htm跨站脚本执行漏洞(MS07-033)。
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{EEE78591-FE22-11D0-8BEF-0060081841DE}]
"Compatibility Flags"=dword:00000400
#kill-bit McAfee Security Center集中配置GUI远程溢出漏洞
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9BE8D7B2-329C-442A-A4AC-ABA9D7572602}]
"Compatibility Flags"=dword:00000400
#kill-bit FlashGet 拒绝服务漏洞
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FB5DA724-162B-11D3-8B9B-AA70B4B0B524}]
"Compatibility Flags"=dword:00000400
#kill-bit 瑞星在线扫描远程代码执行漏洞
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153}]
"Compatibility Flags"=dword:00000400
#kill-bit MS07-027
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{d4fe6227-1288-11d0-9097-00aa004254a0}]
"Compatibility Flags"=dword:00000400
#kill-bit Symantec的远程执行漏洞
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{22ACD16F-99EB-11D2-9BB3-00400561D975}]
"Compatibility Flags"=dword:00000400
#kill-bit Yahoo! Music Jukebox的ActiveX控件缓冲区溢出漏洞,远程攻击者可能利用此漏洞控制用户系统。
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{5F810AFC-BB5F-4416-BE63-E01DD117BD6C}]
"Compatibility Flags"=dword:00000400
#kill-bit MS07-004
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{10072CEC-8CC1-11D1-986E-00A0C955B42E}]
"Compatibility Flags"=dword:00000400
#8:44 2008-3-6 IE被劫持
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4D2EAF15-81D0-42DA-8C39-19EDD39E0FB3}]
"Compatibility Flags"=dword:00000400
#MS06-057(2008-04-10更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{844F4806-E8A8-11d2-9652-00C04FC30871}]
"Compatibility Flags"=dword:00000400
#联众世界GLIEDown.dll组件存在漏洞(2008-05-06更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F917534D-535B-416B-8E8F-0C04756C31A8}]
"Compatibility Flags"=dword:00000400
#雅虎助手3721远程代码执行漏洞(2008-05-09更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2283BB66-A15D-4AC8-BA72-9C8C9F5A1691}]
"Compatibility Flags"=dword:00000400
#PPStream 堆栈溢出(2008-05-10更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{20C2C286-BDE8-441B-B73D-AFA22D914DA5}]
"Compatibility Flags"=dword:00000400
#Windows组件导致的0day漏洞(2008-05-18更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{00E1DB59-6EFD-4CE7-8C0A-2DA3BCAAD9C6}]
"Compatibility Flags"=dword:00000400
#Yahoo! Messenger 8.1.0.249缓冲区溢出漏洞(2008-05-21更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DCE2F8B1-A520-11D4-8FD0-00D0B7730277}]
"Compatibility Flags"=dword:00000400
#uusee2008测试版0day(2008-06-17更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2CACD7BB-1C59-4BBB-8E81-6E83F82C813B}]
"Compatibility Flags"=dword:00000400
#迅雷、迅雷看看ActiveX控件远程代码执行漏洞(2008-06-18更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8}]
"Compatibility Flags"=dword:00000400
#MS Office Snapshot Viewer ActiveX Exploit 漏洞(2008-07-16更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F0E42D50-368C-11D0-AD81-00A0C90DC8D9}]
"Compatibility Flags"=dword:00000400
#MS Office Snapshot Viewer ActiveX Exploit 漏洞(2008-07-16更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F0E42D60-368C-11D0-AD81-00A0C90DC8D9}]
"Compatibility Flags"=dword:00000400
#MS Office Snapshot Viewer ActiveX Exploit 漏洞(2008-07-16更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F2175210-368C-11D0-AD81-00A0C90DC8D9}]
"Compatibility Flags"=dword:00000400
#新浪DLoader Class ActiveX控件任意文件下载漏洞(2008-07-20更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{78ABDC59-D8E7-44D3-9A76-9A0918C52B4A}]
"Compatibility Flags"=dword:00000400
#MS08-053(2008-09-17更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A8D3AD02-7508-4004-B2E9-AD33F087F43C}]
"Compatibility Flags"=dword:00000400
#MS08-052(2008-09-17更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FA91DF8D-53AB-455D-AB20-F2F023E498D3}]
"Compatibility Flags"=dword:00000400
#EDraw Office Viewer Component 5.2 ActiveX Remote BoF PoC(2008-09-28更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6BA21C22-53A5-463F-BBE8-5CF7FFA0132B}]
"Compatibility Flags"=dword:00000400
#GdPicture Pro ActiveX (gdpicture4s.ocx) Remote File Overwrite(2008-10-2更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E8512363-3581-42EF-A43D-990E7935C8BE}]
"Compatibility Flags"=dword:00000400
#Real漏洞(2008/11/2更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0FDF6D6B-D672-463B-846E-C6FF49109662}]
"Compatibility Flags"=dword:00000400
#Real漏洞(2008/11/2更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{224E833B-2CC6-42D9-AE39-90B6A38A4FA2}]
"Compatibility Flags"=dword:00000400
#Real漏洞(2008/11/2更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93}]
"Compatibility Flags"=dword:00000400
#Real漏洞(2008/11/2更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3B46067C-FD87-49B6-8DDD-12F0D687035F}]
"Compatibility Flags"=dword:00000400
#Real漏洞(2008/11/2更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3B5E0503-DE28-4BE8-919C-76E0E894A3C2}]
"Compatibility Flags"=dword:00000400
#Real漏洞(2008/11/2更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{44CCBCEB-BA7E-4C99-A078-9F683832D493}]
"Compatibility Flags"=dword:00000400
#Real漏洞(2008/11/2更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A1A41E11-91DB-4461-95CD-0C02327FD934}]
"Compatibility Flags"=dword:00000400
#Real漏洞(2008/11/5更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{405DE7C0-E7DD-11D2-92C5-00C0F01F77C1}]
"Compatibility Flags"=dword:00000400
#0812IE漏洞(2008/12/16更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2048EEE6-7FA2-11D0-9E6A-00A0C9138C29}]
"Compatibility Flags"=dword:00000400
#某网马利用过的(2009/4/2更新)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{19EFFC12-25FB-479A-A0F2-1569AE1B3365}]
"Compatibility Flags"=dword:00000400
#暴风影音2009(mps.dll)ActiveX远程栈溢出漏洞2009/5/5更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB}]
"Compatibility Flags"=dword:00000400
#暴风影音2009(Config.dll)ActiveX远程栈溢出漏洞2009/5/5更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BD103B2B-30FB-4F1E-8C17-D8F6AADBCC05}]
"Compatibility Flags"=dword:00000400
#中国游戏中心游戏大厅ActiveX远程栈溢出漏洞2009/5/5更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{75108B29-202F-493C-86C5-1C182A485C4C}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/5更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0955AC62-BF2E-4CBA-A2B9-A63F772D46CF}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{011B3619-FE63-4814-8A84-15A194CE9CE3}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0149EEDF-D08F-4142-8D73-D23903D21E90}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0369B4E5-45B6-11D3-B650-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0369B4E6-45B6-11D3-B650-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{055CB2D7-2969-45CD-914B-76890722F112}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{15D6504A-5494-499C-886C-973C9E53B9F1}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1BE49F30-0E1B-11D3-9D8E-00C04F72D980}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1C15D484-911D-11D2-B632-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1DF7D126-4050-47F0-A7CF-4C4CA9241333}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2C63E4EB-4CEA-41B8-919C-E947EA19A77C}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{334125C0-77E5-11D3-B653-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{37B0353C-A4C8-11D2-B634-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{37B03543-A4C8-11D2-B634-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{37B03544-A4C8-11D2-B634-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4A5869CF-929D-4040-AE03-FCAFC5B9CD42}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{577FAA18-4518-445E-8F70-1473F8CF4BA4}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{59DC47A8-116C-11D3-9D8E-00C04F72D980}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7F9CB14D-48E4-43B6-9346-1AEBC39C64D3}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{823535A0-0318-11D3-9D8E-00C04F72D980}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8872FF1B-98FA-4D7A-8D93-C9F1055F85BB}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8A674B4C-1F63-11D3-B64C-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8A674B4D-1F63-11D3-B64C-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9CD64701-BDF3-4D14-8E03-F12983D86664}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9E77AAC4-35E5-42A1-BDC2-8F3FF399847C}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A1A2B1C4-0E3A-11D3-9D8E-00C04F72D980}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2E30750-6C3D-11D3-B653-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A8DCF3D5-0780-4EF4-8A83-2CFFAACB8ACE}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AD8E510D-217F-409B-8076-29C5E73B98E8}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B0EDF163-910A-11D2-B632-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8A674B4C-1F63-11D3-B64C-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B64016F3-C9A2-4066-96F0-BD9563314726}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BB530C63-D9DF-4B49-9439-63453962E598}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C531D9FD-9685-4028-8B68-6E1232079F1E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCC-9B79-11D3-B654-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCD-9B79-11D3-B654-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCE-9B79-11D3-B654-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCF-9B79-11D3-B654-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CD0-9B79-11D3-B654-00C04F79498E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C6B14B32-76AA-4A86-A7AC-5C79AAF58DA7}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{CAAFDD83-CEFC-4E3D-BA03-175F17A24F91}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D02AAC50-027E-11D3-9D8E-00C04F72D980}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F9769A06-7ACA-4E39-9CFB-97BB35F0E77E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C531D9FD-9685-4028-8B68-6E1232079F1E}]
"Compatibility Flags"=dword:00000400
#BDATuner.MPEG2TuneRequest Stack Overflow Exploit 2009/7/11更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FA7C375B-66A7-4280-879D-FD459C84BB02}]
"Compatibility Flags"=dword:00000400
#Office Spreadsheet ActiveX 0day漏洞2009/12/6更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E551-0000-0000-C000-000000000046}]
"Compatibility Flags"=dword:00000400

#Office Spreadsheet ActiveX 0day漏洞2009/12/6更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E541-0000-0000-C000-000000000046}]
"Compatibility Flags"=dword:00000400

#Office Spreadsheet ActiveX 0day漏洞2009/12/6更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E559-0000-0000-C000-000000000046}]
"Compatibility Flags"=dword:00000400

#QvodPlayer ColorFilter Codec ActiveX Remote Exec 0day POC漏洞2010/1/19更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{432F118C-DB79-4561-9799-CC95EA78208B}]
"Compatibility Flags"=dword:00000400

#Xunlei ActiveX Remote Exec 0day POC漏洞2010/1/19更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A9322148-C691-4B9D-91FC-B9C461DBE9DD}]
"Compatibility Flags"=dword:00000400

#Windows Live Messenger 2009(MSN) ActiveX 拒绝服务攻击(DOS)2010/1/19更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B69003B3-C55E-4B48-836C-BC5946FC3B28}]
"Compatibility Flags"=dword:00000400

#Flashget 3.x IEHelper 远程溢出漏洞 0day PoC2010/1/19更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C6262DCE-6E64-45D2-B080-801F1E298AC2}]
"Compatibility Flags"=dword:00000400

#Windows Media Player 11 ActiveX 漏洞2010/1/19更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
"Compatibility Flags"=dword:00000400

隐藏内容 隐藏内容
该内容已经被作者隐藏,只有会员才允许查阅 登录 | 注册
此文的可行性评估分数:9分/总分10分。
文章来自: 死性不改's Blog~
引用通告: 查看所有引用 | 我要引用此文章
Tags: 网马 安全 HOSTS
相关日志:
评论: 66 | 引用: 0 | 查看次数: 19459
回复回复askystar[2010-06-09 00:26 AM | IP:60.191.235.18 | 浙江省金华市 永康市东城东方网吧 del]
这个可以屏蔽净网5.0的BHO吗
回复回复wjsandy[2010-05-19 08:55 PM | IP:115.238.48.35 | 浙江省杭州市 电信 del]
汗,导这些clsid现在导致百度音乐都无法播放
回复回复飛雪[2010-03-04 09:12 AM | IP:122.116.200.141 | 台湾省 中华电信 del]
請問老楚老大:

可以用在win7上面嗎? 會不會有副作用啊?

XP是完全OK的,就不知WIN7行不?
回复来自 楚林 的评论 楚林 于 2010-03-04 03:06 PM 回复11
这个win7上没测试过。你可以测试下是否有用
回复回复xf2004[2010-02-10 04:07 PM | IP:218.65.253.236 | 广西桂林市 电信 del]
微软与2/10/2010发布料官方的Kill ActiveX如果能配合反黑Kill ActiveX一起用相信就完美了,相关网站support.microsoft.com/kb/978262
回复来自 楚林 的评论 楚林 于 2010-03-04 03:07 PM 回复11
微软的这个实现方式和我的不一样的,windows是微软出的东西,因此他们的解决方案更加优秀,只是不一定适合中国而已。
回复回复dj82[2010-02-02 02:25 PM | IP:58.55.5.251 | 湖北省孝感市 电信 del]
老楚可以,整理一下,把常用插件的注释,方便别人查找去除!
回复来自 楚林 的评论 楚林 于 2010-03-04 03:07 PM 回复11
这到是个不错的想法,可以考虑下。
回复回复刘十九[2010-01-26 00:00 AM | IP:61.153.63.21 | 浙江省丽水市 电信 del]
Windows Media Player 11 ActiveX 漏洞2010/1/19更新
添加此漏洞之后。1ting网站不能听歌.现在如何去除好了呢?找找BLOG内容看看
回复来自 楚林 的评论 楚林 于 2010-03-04 03:07 PM 回复11
可以把相关内容删除掉。
回复回复lqleelq[2010-01-23 05:45 PM | IP:218.15.190.90 | 广东省梅州市兴宁市 电信ADSL del]
#Windows Media Player 11 ActiveX 漏洞2010/1/19更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
"Compatibility Flags"=dword:00000400


导致百度歌曲不能播放,一直音频连接中,不会缓冲播放。。。。。
回复来自 楚林 的评论 楚林 于 2010-01-23 08:59 PM 回复11
这个注册表会干掉wmp的mp3播放功能,可以修改文件关联到realplayer。修改好用regshot提取下注册表,然后开机导入即可。
回复回复qq308928271[2010-01-23 04:50 PM | IP:219.136.52.218 | 广东省广州市 电信ADSL del]
支持老大
回复来自 楚林 的评论 楚林 于 2010-01-23 08:58 PM 回复11
谢谢。
回复回复lgm0603[2010-01-20 01:03 PM | IP:60.164.207.71 | 甘肃省陇南市 电信 del]
#Windows Media Player 11 ActiveX 漏洞2010/1/19更新
导致51.com中的音乐不能播放,提示插件不安装?如何解决?
回复来自 楚林 的评论 楚林 于 2010-01-23 08:19 PM 回复11
把相应注册表删除掉,建议更换其他播放器,即可避免被漏洞攻击,又不存在文件播放问题。
回复回复飛雪[2010-01-20 07:04 AM | IP:122.116.200.141 | 台湾省 中华电信 del]
請問是只要保存成.reg導入就ok了嗎?
回复来自 楚林 的评论 楚林 于 2010-01-23 08:19 PM 回复11
是的
回复回复洪荒老道[2009-10-24 01:14 PM | IP:122.229.237.124 | 浙江省杭州市 电信 del]
支持
回复回复yesh1989[2009-05-13 01:54 PM | IP:121.13.242.106 | 广东省东莞市 横沥镇网游天下网吧 del]
电脑有时网页打不开,QQ掉线,游戏却没掉,重启下又正常,不知是不是打了这个注册表问题.你们打了这个注册表,有这情况么???
回复来自 楚林 的评论 楚林 于 2010-01-23 08:19 PM 回复11
你的问题与这个注册表无关。
回复回复sgoon[2009-01-09 02:06 AM | IP:61.182.48.106 | 河北省石家庄市 联通 del]
呵呵

能否解说一下注册表的键值?

为什么要设置成0000400,还有其他的值吗?

如果自己想封某个CLSID,怎么查找对应的注册表值?
回复来自 楚林 的评论 楚林 于 2009-01-09 02:23 AM 回复11
这个是王八的屁股,规定。
回复回复xuepeng258[2008-12-10 01:17 PM | IP:125.70.241.18 | 四川省成都市 电信 del]
支持老大
回复回复a110180956[2008-08-02 01:54 AM | IP:202.104.125.109 | 广东省深圳市南山区 全速后海网吧(华明路后海居委会统建楼商业裙楼二层) del]
我也下搞来用用,大哥辛苦了! 及时关注及时更新
发表评论
你没有权限发表评论!
上一张
快捷键"←"
下一张
快捷键"→"
图片来自 http://www.clxp.net.cn 请勿盗链! 关闭 移动