新装的Windows 11, 不想买淘宝的激活码, 自己下载了一个
HEU KMS Activator v24.5.0
这个软件教程叫我关闭Defender,防火墙,杀软等,打开一键式傻瓜式激活, 我本来想的是也不用安装软件,一键式激活也挺好, 我就信了。
的确激活了, 但是我用了一会电脑发现Windows更新不能用了, 原因不知道。
然后就是注册表编辑器, 一打开就关闭,这个原因也不知道。
于是我抱着试试看的态度,用病毒扫描软件简单扫了一下,结果吓一跳。
RKill.exe
Host文件被改成这样了。阻止我访问所有的杀软域名,也就是说我的杀软在线更新都崩了。
但是注册表为什么打开就立刻关闭还是没找到原因,我怀疑是进程劫持,它以另外一个用户运行了注册表,并且修改了权限,导致我没法运行。
这是扫描结果:
Rkill 2.9.1 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2022 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 06/11/2022 09:56:50 PM in x64 mode.
Windows Version: Windows 10 Enterprise
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Windows\System32\kms-renewal.exe (PID: 3756) [WD-HEUR]
1 proccess terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* Windows Automatic Updates Disabled
[HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAutoUpdate" = dword:00000001
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
0.0.0.0 avast.com
0.0.0.0 www.avast.com
0.0.0.0 totalav.com
0.0.0.0 www.totalav.com
0.0.0.0 scanguard.com
0.0.0.0 www.scanguard.com
0.0.0.0 totaladblock.com
0.0.0.0 www.totaladblock.com
0.0.0.0 pcprotect.com
0.0.0.0 www.pcprotect.com
0.0.0.0 mcafee.com
0.0.0.0 www.mcafee.com
0.0.0.0 bitdefender.com
0.0.0.0 www.bitdefender.com
0.0.0.0 us.norton.com
0.0.0.0 www.us.norton.com
0.0.0.0 avg.com
0.0.0.0 www.avg.com
0.0.0.0 malwarebytes.com
0.0.0.0 www.malwarebytes.com
20 out of 97 HOSTS entries shown.
Please review HOSTS file for further entries.