ZBotTrojanRemover是一款可以检测并查杀ZBot变种木马病毒的查杀工具,ZBot变种木马会在电脑中潜伏,并且专门针对用户的各种银行账号,是一种威胁非常大的病毒,大家一定要小心防范。愤怒的小鸟赚钱版
病毒样本:
MalwareAnalyzerbyHX
Analysisstarted
MD5:2BB9A1C4B35719ABD022C605A546D6C4
Executing->DeviceHarddiskVolume3UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe(PID:13440)
Command-line:"C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe"
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteFile,C:UsersGatewayAppDataRoamingGolaxyeq.exe
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteRegistryKey,SoftwareMicrosoft
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteRegistryKey,Juat
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
DeleteFile,C:UsersGatewayAppDataRoamingGolaxyeq.exe
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteFile,C:UsersGatewayAppDataRoamingGolaxyeq.exe
C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteFile,C:UsersGatewayAppDataRoamingGolaxyeq.exe
Executing->DeviceHarddiskVolume3SandboxGatewayAnalyzerusercurrentAppDataRoamingGolaxyeq.exe(PID:16540)
Command-line:"C:UsersGatewayAppDataRoamingGolaxyeq.exe"
C:UsersGatewayAppDataRoamingGolaxyeq.exe
WriteRegistryKey,SoftwareMicrosoftJuat
C:UsersGatewayAppDataRoamingGolaxyeq.exe
WriteRegistryKey,f62bfi
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32 askhost.exe(PID:1992)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32dwm.exe(PID:2976)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:UsersGatewayAppDataLocalMicrosoftSkyDriveSkyDrive.exe(PID:3484)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFiles(x86)GoogleDrivegoogledrivesync.exe(PID:3496)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFilesSandboxieSbieCtrl.exe(PID:3524)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFiles(x86)EvernoteEvernoteEvernoteClipper.exe(PID:3584)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,K:ProgramFiles(x86)KasperskyLabKasperskyEndpointSecurity8forWindowsavp.exe(PID:3592)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:UsersGatewayDesktopgoagent-goagent-a51d6a2localgoagent.exe(PID:3600)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32conhost.exe(PID:3608)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFilesBOINCoincmgr.exe(PID:3696)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:UsersGatewayDesktopgoagent-goagent-a51d6a2localpython27.exe(PID:3704)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFilesBOINCoinctray.exe(PID:3776)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,K:SkyDriveProgramsVBSherloggerSherlogger.exe(PID:3840)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,K:ProgramFiles(x86)BaiduYunaiduyun.exe(PID:3868)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFiles(x86)GoogleDrivegoogledrivesync.exe(PID:3952)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFilesBOINCoinc.exe(PID:3964)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32conhost.exe(PID:3972)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramFiles(x86)alipaySafeTransactionAlipaySafeTran.exe(PID:17800)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:ProgramDataBOINCprojectswww.worldcommunitygrid.orgwcgrid_dsfl_vina_6.25_windows_x86_64(PID:57092)
C:UsersGatewayAppDataRoamingGolaxyeq.exe(PID:16540)
AccessPROTECTEDProgram,C:WindowsSystem32conhost.exe(PID:58156)
Rollingback...
Analysisended
Reason:Malwaredetectedandrolledback
Anomalies:
-Modifiesprotectedresource.Theexecutablemodifiesimportantresources(files,processes,etc.)
展开

网络赚钱偏门模式
棋牌游戏空中接龙
来钱赚app
网络赚钱兼职2016
怎么样赚钱方法
手机k歌赚钱软件排行榜
支付宝红包领了没到账
迷你世界迷你币怎么赚
直播服务佣金协议书
在郑州什么职业挣钱
有没有捕鱼手机可以赚钱的
那个手机网游能赚钱吗
网赚打算团队
怎样在家也能赚钱吗
开元棋牌app赌博
太原妹子兼职
手机搬砖赚钱方法
炸鲜奶怎么做才能赚钱
做tiktok运营赚钱吗
挂机赚佣金的软件