简体   繁体   English

使用\\ ApprovedExtensionsMigration \\启用Auto-BHO是否安全?

[英]Safety of using \ApprovedExtensionsMigration\ for Auto-BHO enabling?

I'm in the process of looking into auto-enabling an IE9 toolbar so the user does not need to click the enable button, and I noticed another company used the following method. 我正在研究自动启用IE9工具栏的过程,因此用户不需要单击“启用”按钮,并且我注意到另一家公司使用了以下方法。

  1. Delete the registry key HKCU\\Software\\Microsoft\\Internet Explorer\\ApprovedExtensionsMigration\\ 删除注册表项HKCU \\ Software \\ Microsoft \\ Internet Explorer \\ ApprovedExtensionsMigration \\
  2. Create a new key under HKCU\\Software\\Microsoft\\Internet Explorer\\ApprovedExtensionsMigration\\ 在HKCU \\ Software \\ Microsoft \\ Internet Explorer \\ ApprovedExtensionsMigration \\下创建一个新密钥
  3. Add my toolbar's CLSID string value HKCU\\Software\\Microsoft\\Internet Explorer\\ApprovedExtensionsMigration{XXXXXXX....-XXXX} 添加我的工具栏的CLSID字符串值HKCU \\ Software \\ Microsoft \\ Internet Explorer \\ ApprovedExtensionsMigration {XXXXXXX ....- XXXX}

x. X。 Internet Explorer 9 automatically enables my toolbar and proceeds as if the user had clicked enable. Internet Explorer 9自动启用我的工具栏,并继续进行操作,就像用户单击了启用一样。

I have not found any documentation for this method, but I believe the way this works is Internet Explorer 9 believes the toolbar is going from IE8->IE9, and enables the toolbar. 我没有找到有关此方法的任何文档,但我相信此方法的工作方式是Internet Explorer 9认为该工具栏是从IE8-> IE9开始的,并启用了该工具栏。 Should this method be considered unsafe for use (too hacky and will instantly get flagged by anti-virus), or is this considered a valid way of auto-enabling a toolbar? 该方法是否应该被认为不安全使用(太容易受到攻击,并且会立即被反病毒标记),还是被认为是自动启用工具栏的有效方法?

Also, does anyone know if this method works in Internet Explorer 10? 另外,有人知道这种方法是否可以在Internet Explorer 10中使用吗?

Can't find any resources about this method. 找不到有关此方法的任何资源。 Viruses will use this method for sure (see http://www.threatexpert.com/report.aspx?md5=bde1312b225ad987b57b1dbef0885817 which is an identified virus that do exactly that), but since this registry is deleted (or at least the Time Stamp value is changed) in legitimate scenarios, it is possible that anti-viruses will not freak out, as they don't want to create false positives. 病毒肯定会使用此方法(请参见http://www.threatexpert.com/report.aspx?md5=bde1312b225ad987b57b1dbef0885817 ,它是确定能够做到这一点的病毒),但是由于删除了此注册表(至少是时间戳)值已更改),在合法情况下,反病毒可能不会吓跑,因为它们不想造成误报。

Regardless, what you are trying to do feels bad. 无论如何,您尝试做的事情感觉很糟糕。

Also you should consider other users on the machine (not currently logged in). 另外,您还应考虑计算机上的其他用户(当前未登录)。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM