病毒样本:
MalwareAnalyzerbyHX战锤40k修改器-战锤40k:战争黎明2八项属性修改器8v1.0 绿色版
Analysisstarted
MD5:2BB9A1C4B35719ABD022C605A546D6C4
Executing->DeviceHarddiskVolume3UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe(PID:13440)
Command-line:"C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe"
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteFile,C:UsersGatewayAppDataRoamingGolaxyeq.exe
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteRegistryKey,SoftwareMicrosoft
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteRegistryKey,Juat
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
DeleteFile,C:UsersGatewayAppDataRoamingGolaxyeq.exe
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteFile,C:UsersGatewayAppDataRoamingGolaxyeq.exe
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteFile,C:UsersGatewayAppDataRoamingGolaxyeq.exe
Executing->DeviceHarddiskVolume3SandboxGatewayAnalyzerusercurrentAppDataRoamingGolaxyeq.exe(PID:16540)
Command-line:"C:UsersGatewayAppDataRoamingGolaxyeq.exe"
C:UsersGatewayAppDataRoamingGolaxyeq.exe
WriteRegistryKey,SoftwareMicrosoftJuat
C:UsersGatewayAppDataRoamingGolaxyeq.exe
WriteRegistryKey,f62bfi
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32 askhost.exe(PID:1992)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32dwm.exe(PID:2976)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:UsersGatewayAppDataLocalMicrosoftSkyDriveSkyDrive.exe(PID:3484)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFiles(x86)GoogleDrivegoogledrivesync.exe(PID:3496)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFilesSandboxieSbieCtrl.exe(PID:3524)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFiles(x86)EvernoteEvernoteEvernoteClipper.exe(PID:3584)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,K:ProgramFiles(x86)KasperskyLabKasperskyEndpointSecurity8forWindowsavp.exe(PID:3592)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:UsersGatewayDesktopgoagent-goagent-a51d6a2localgoagent.exe(PID:3600)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32conhost.exe(PID:3608)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFilesBOINCoincmgr.exe(PID:3696)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:UsersGatewayDesktopgoagent-goagent-a51d6a2localpython27.exe(PID:3704)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFilesBOINCoinctray.exe(PID:3776)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,K:SkyDriveProgramsVBSherloggerSherlogger.exe(PID:3840)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,K:ProgramFiles(x86)BaiduYunaiduyun.exe(PID:3868)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFiles(x86)GoogleDrivegoogledrivesync.exe(PID:3952)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFilesBOINCoinc.exe(PID:3964)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32conhost.exe(PID:3972)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFiles(x86)alipaySafeTransactionAlipaySafeTran.exe(PID:17800)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramDataBOINCprojectswww.worldcommunitygrid.orgwcgrid_dsfl_vina_6.25_windows_x86_64(PID:57092)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32conhost.exe(PID:58156)
Rollingback...
Analysisended
Reason:Malwaredetectedandrolledback
Anomalies:
-Modifiesprotectedresource.Theexecutablemodifiesimportantresources(files,processes,etc.)
ZBotTrojanRemover是一款可以检测并查杀ZBot变种木马病毒的查杀工具,ZBot变种木马会在电脑中潜伏,并且专门针对用户的各种银行账号,是一种威胁非常大的病毒,大家一定要小心防范。
万博全球站地址 nfl体育直播 嘉博娱乐城 极速飞艇博彩 y博官网展开

萌宠大联盟0.05折下载-萌宠大联盟0.05折代金尊享版1.0 安卓版
爆破三国私服下载-爆破三国满v版1.6.2 安卓版
河北医药平台app1.0 安卓正式版
少年三国志电脑模拟器版4.9.15 pc最新版
极限飞车模拟器2下载最新-极限飞车模拟器25.09.123 最新版
王者魔神送充版下载-王者魔神送千元充值版1.0.8 安卓送1000元版
时光树免费版下载-时光树安卓版1.0.85 官方免费版
都市圣传最新版-都市圣传官方版1.0.0最新版
好分数辅导app下载-好分数辅导app安卓版5.6.2 最新版
3ds Max 2014注册机下载-Autodesk 3ds Max 2014注册机32/64位绿色版
卫生值班表-办公室卫生值班表word格式打印版
俱乐部小助手下载-俱乐部小助手1.3.3 最新版
图片去灰底与增强的软件-原本(永久免费的专业级图片漂白软件)2.1 免费版
逆天仙魔录1.2正式版免费下载
文件加密工具(Quick Crypt)1.1 绿色免费版
医院怪谈游戏下载-医院怪谈游戏1.0 安卓版
嘀嗒出行顺风车app下载-嘀嗒出行苹果版9.7.0 iOS最新版
邮件伪造工具(伪造邮件发件人)1.2 绿色最新版
九天封神破晓1.0 最新版
小笨猫游戏下载-小笨猫Clumsy Cat1.4.4 最新版