病毒样本:
MalwareAnalyzerbyHX让球胜平负
Analysisstarted
MD5:2BB9A1C4B35719ABD022C605A546D6C4
Executing->DeviceHarddiskVolume3UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe(PID:13440)
Command-line:"C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe"
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteFile,C:UsersGatewayAppDataRoamingGolaxyeq.exe
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteRegistryKey,SoftwareMicrosoft
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteRegistryKey,Juat
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
DeleteFile,C:UsersGatewayAppDataRoamingGolaxyeq.exe
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteFile,C:UsersGatewayAppDataRoamingGolaxyeq.exe
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteFile,C:UsersGatewayAppDataRoamingGolaxyeq.exe
Executing->DeviceHarddiskVolume3SandboxGatewayAnalyzerusercurrentAppDataRoamingGolaxyeq.exe(PID:16540)
Command-line:"C:UsersGatewayAppDataRoamingGolaxyeq.exe"
C:UsersGatewayAppDataRoamingGolaxyeq.exe
WriteRegistryKey,SoftwareMicrosoftJuat
C:UsersGatewayAppDataRoamingGolaxyeq.exe
WriteRegistryKey,f62bfi
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32 askhost.exe(PID:1992)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32dwm.exe(PID:2976)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:UsersGatewayAppDataLocalMicrosoftSkyDriveSkyDrive.exe(PID:3484)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFiles(x86)GoogleDrivegoogledrivesync.exe(PID:3496)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFilesSandboxieSbieCtrl.exe(PID:3524)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFiles(x86)EvernoteEvernoteEvernoteClipper.exe(PID:3584)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,K:ProgramFiles(x86)KasperskyLabKasperskyEndpointSecurity8forWindowsavp.exe(PID:3592)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:UsersGatewayDesktopgoagent-goagent-a51d6a2localgoagent.exe(PID:3600)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32conhost.exe(PID:3608)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFilesBOINCoincmgr.exe(PID:3696)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:UsersGatewayDesktopgoagent-goagent-a51d6a2localpython27.exe(PID:3704)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFilesBOINCoinctray.exe(PID:3776)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,K:SkyDriveProgramsVBSherloggerSherlogger.exe(PID:3840)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,K:ProgramFiles(x86)BaiduYunaiduyun.exe(PID:3868)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFiles(x86)GoogleDrivegoogledrivesync.exe(PID:3952)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFilesBOINCoinc.exe(PID:3964)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32conhost.exe(PID:3972)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFiles(x86)alipaySafeTransactionAlipaySafeTran.exe(PID:17800)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramDataBOINCprojectswww.worldcommunitygrid.orgwcgrid_dsfl_vina_6.25_windows_x86_64(PID:57092)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32conhost.exe(PID:58156)
Rollingback...
Analysisended
Reason:Malwaredetectedandrolledback
Anomalies:
-Modifiesprotectedresource.Theexecutablemodifiesimportantresources(files,processes,etc.)
ZBotTrojanRemover是一款可以检测并查杀ZBot变种木马病毒的查杀工具,ZBot变种木马会在电脑中潜伏,并且专门针对用户的各种银行账号,是一种威胁非常大的病毒,大家一定要小心防范。
3d 试走势图 手机上哪能买球 体彩排列三讲座 g双色球 一号站平台娱乐展开

嘉石榴线上理财管家-嘉石榴app2.0.1 安卓最新版
魔幻厨房oppo客户端下载-oppo魔幻厨房游戏1.21渠道服
仙剑柔情安卓版下载-仙剑柔情手游1.0 官方版
久草视频官方下载-久草视频app1.0.6 安卓版
娱丸软件下载-娱丸社交app3.4.0 安卓版
斯拉少女下载-斯拉少女官方版版3.40内测版
依时利三旺TCP模块设置工具1.3.5免费版
美食之家app下载-美食之家软件1.6.1 安卓手机版
创作猫去水印app下载-创作猫去水印app4.2.3 免费版
星路旅游App下载-星路旅游2.2.6 最新版
易软餐饮管理系统门店版2.7 最新免费版
人人桌面5.0.0.1正式版
开局一只鲲下载-开局一只鲲游戏2.15 最新版
上鹿学车官网下载-上鹿学车1.8.0605 官方无广告版
表格编辑手机版下载-表格编辑手机版1.7.7 免费版
安徽医疗便民app下载-安徽医疗便民服务平台居民版3.12.0安卓版
生鲜鸽app1.1.7 最新安卓版
奇怪玩具屋安卓下载-奇怪玩具屋鲤鱼解说1.3 安卓版
梦幻遮天送2021充值版下载-梦幻遮天boss送充值版1.0.1福利版
打金合击版传奇手游下载-打金合击服1.0 高爆版