昨天开始,开机或者启动IE的时候监控中心就会不停的报警说有东西要修改我的注册表,历史记录如下
进程名称 路径 数值名称 数值数据 操作方式操作结果
C:\WINDOWS\system32\nvsvc32.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN NvCplDaemon RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStart 修改拒绝修改
C:\WINDOWS\Explorer.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN 9z C:\WINDOWS\system32\rundll32.exe 3tjd3.dll Rundll3 修改拒绝修改
C:\WINDOWS\Explorer.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN 9z C:\WINDOWS\system32\rundll32.exe 3tjd3.dll Rundll3 修改拒绝修改
C:\WINDOWS\Explorer.EXE HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN 0qg60qg.exe C:\WINDOWS\system32\0qg60qg.exe C:\WINDOWS\system3 修改拒绝修改
C:\WINDOWS\Explorer.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN 9z C:\WINDOWS\system32\rundll32.exe 3tjd3.dll Rundll3 修改拒绝修改
C:\WINDOWS\Explorer.EXE HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN 0qg60qg.exe C:\WINDOWS\system32\0qg60qg.exe C:\WINDOWS\system3 修改拒绝修改
C:\WINDOWS\Explorer.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN 9z C:\WINDOWS\system32\rundll32.exe 3tjd3.dll Rundll3 修改拒绝修改
C:\WINDOWS\Explorer.EXE HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN 0qg60qg.exe C:\WINDOWS\system32\0qg60qg.exe C:\WINDOWS\system3 修改拒绝修改
C:\WINDOWS\Explorer.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN 9z C:\WINDOWS\system32\rundll32.exe 3tjd3.dll Rundll3 修改拒绝修改
C:\Documents and Settings\lts\桌面\HijackThis.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN KernelFaultCheck 删除同意修改
然后我就用HJ扫描了下,日志显示我被莫名其妙加入了这些HOSTS
O1 - Hosts: 61.141.31.11 www.kzdh.com
O1 - Hosts: 61.141.31.11 www.7255.com
O1 - Hosts: 61.141.31.11 www.7322.com
O1 - Hosts: 61.141.31.11 www.7939.com
O1 - Hosts: 61.141.31.11 www.piaoxue.com
O1 - Hosts: 61.141.31.11 www.feixu.net
O1 - Hosts: 61.141.31.11 www.6781.com
O1 - Hosts: 61.141.31.11 www.7b.com.cn
O1 - Hosts: 61.141.31.11 7b.com.cn
O1 - Hosts: 61.141.31.11 www.918188.com
O1 - Hosts: 61.141.31.11 hao.allxue.com
O1 - Hosts: 61.141.31.11 good.allxue.com
O1 - Hosts: 61.141.31.11 baby.allxue.com
O1 - Hosts: 61.141.31.11 www.allxue.com
O1 - Hosts: 61.141.31.11 about.lank.la
O1 - Hosts: 61.141.31.11 www.x114x.com
O1 - Hosts: 61.141.31.11 www.37ss.com
O1 - Hosts: 61.141.31.11 www.7k.cc
O1 - Hosts: 61.141.31.11 www.73ss.com
O1 - Hosts: 125.91.14.230 www.hao123.com
O1 - Hosts: 61.141.31.11 www.81915.com
O1 - Hosts: 61.141.31.11 222.88.90.22
O1 - Hosts: 61.141.31.11 www.9991.com
O1 - Hosts: 61.141.31.11 www.my123.com
O1 - Hosts: 61.141.31.11 www.haokan123.com
O1 - Hosts: 61.141.31.11 www.5566.net
O1 - Hosts: 61.141.31.11 www.gjj.cc
O1 - Hosts: 61.141.31.11 www.2345.com
O1 - Hosts: 61.141.31.11 dl.hao318.com
O1 - Hosts: 61.141.31.11 www.123wa.com
O1 - Hosts: 61.141.31.11 www.ku886.com
O1 - Hosts: 61.141.31.11 www.5icrack.com
O1 - Hosts: 61.141.31.11 www.jjol.cn
可是麻烦的是不管我是用HJ还是用卡卡,都无法彻底删掉他们,删掉过一会又自动加上去了,用瑞星扫描又没有木马什么的,即使是用GHOST备份还原了过一会又是这样了,我很郁闷,哪位能帮助我解决这个问题