ZBot病毒查杀工具(ZBot Trojan Remover)v1.7 绿色版

ZBot病毒查杀工具(ZBot Trojan Remover)是一款好用的病毒查杀软件,可以检测并查杀ZBot变种木马病毒,这病毒可以从网站上窃取用户的银行信息,信用卡信息和paypal账户的登录凭据。欢迎来IT猫扑网下载!

病毒样本:

Malware Analyzer by HX

Analysis started

MD5: 2BB9A1C4B35719ABD022C605A546D6C4

Executing -> \Device\HarddiskVolume3\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe (PID: 13440)

Command-line: "C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe"

C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe

WriteFile, C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe

C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe

WriteRegistryKey, Software\Microsoft

C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe

WriteRegistryKey, Juat

C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe

DeleteFile, C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe

C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe

WriteFile, C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe

C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe

WriteFile, C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe

Executing -> \Device\HarddiskVolume3\Sandbox\Gateway\Analyzer\user\current\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

Command-line: "C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe"

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe

WriteRegistryKey, Software\Microsoft\Juat

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe

WriteRegistryKey, f62bfi

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

accessPROTECTEDProgram, C:\Windows\System32\taskhost.exe (PID: 1992)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Windows\System32\dwm.exe (PID: 2976)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Users\Gateway\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (PID: 3484)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Program Files (x86)\Google\Drive\googledrivesync.exe (PID: 3496)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Program Files\sandboxie\SbieCtrl.exe (PID: 3524)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (PID: 3584)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, K:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\avp.exe (PID: 3592)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Users\Gateway\Desktop\goagent-goagent-a51d6a2\local\goagent.exe (PID: 3600)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Windows\System32\conhost.exe (PID: 3608)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Program Files\BOINC\boincmgr.exe (PID: 3696)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Users\Gateway\Desktop\goagent-goagent-a51d6a2\local\python27.exe (PID: 3704)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Program Files\BOINC\boinctray.exe (PID: 3776)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, K:\SkyDrive\Programs\vb\Sherlogger\Sherlogger.exe (PID: 3840)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, K:\Program Files (x86)\BaiduYun\baiduyun.exe (PID: 3868)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Program Files (x86)\Google\Drive\googledrivesync.exe (PID: 3952)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Program Files\BOINC\boinc.exe (PID: 3964)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Windows\System32\conhost.exe (PID: 3972)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Program Files (x86)\alipay\SafeTransaction\AlipaySafeTran.exe (PID: 17800)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcgrid_dsfl_vina_6.25_windows_x86_64 (PID: 57092)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:\Windows\System32\conhost.exe (PID: 58156)

Rolling back…

Analysis ended

Reason: Malware detected and rolled back

Anomalies:

– Modifies protected resource. The executable modifies important resources (files, processes, etc.)

下载权限
查看
  • 免费下载
    评论并刷新后下载
    登录后下载
  • {{attr.name}}:
您当前的等级为
登录后免费下载登录 小黑屋反思中,不准下载! 评论后刷新页面下载评论 支付以后下载 请先登录 您今天的下载次数(次)用完了,请明天再来 支付积分以后下载立即支付 支付以后下载立即支付 您当前的用户组不允许下载升级会员
您已获得下载权限 您可以每天下载资源次,今日剩余
声明:本站所有文章,如无特殊说明或标注,均转摘自网络。如若本站内容侵犯了原著者的合法权益,请邮件联系66553826(@)qq.com进行处理。
电脑软件

Wirelurker for mac(病毒查杀)v1.0 苹果电脑版

2024-9-24 20:32:20

电脑软件

360杀毒极速版官方版v7.0.0.1011 最新版

2024-9-24 20:38:26

搜索