ZBotTrojanRemover可以检测并查杀ZBot变种木马病毒,这病毒可以从网站上窃取用户的银行信息,信用卡信息和paypal账户的登录凭据。
病毒样本:
MalwareAnalyzerbyHXAnalysisstartedMD5:2BB9A1C4B35719ABD022C605A546D6C4Executing-\Device\HarddiskVolume3\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe(PID:13440)Command-line:"C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe"C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exeWriteFile,C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exeC:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exeWriteRegistryKey,Software\MicrosoftC:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exeWriteRegistryKey,JuatC:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exeDeleteFile,C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exeC:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exeWriteFile,C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exeC:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exeWriteFile,C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exeExecuting-\Device\HarddiskVolume3\Sandbox\Gateway\Analyzer\user\current\AppData\Roaming\Gola\xyeq.exe(PID:16540)Command-line:"C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe"C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exeWriteRegistryKey,Software\Microsoft\JuatC:\Users\Gateway\AppData\Roaming\Gola\xyeq.exeWriteRegistryKey,f62bfiC:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\Windows\System32\taskhost.exe(PID:1992)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\Windows\System32\dwm.exe(PID:2976)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\Users\Gateway\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe(PID:3484)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\ProgramFiles(x86)\Google\Drive\googledrivesync.exe(PID:3496)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\ProgramFiles\Sandboxie\SbieCtrl.exe(PID:3524)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\ProgramFiles(x86)\Evernote\Evernote\EvernoteClipper.exe(PID:3584)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,K:\ProgramFiles(x86)\KasperskyLab\KasperskyEndpointSecurity8forWindows\avp.exe(PID:3592)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\Users\Gateway\Desktop\goagent-goagent-a51d6a2\local\goagent.exe(PID:3600)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\Windows\System32\conhost.exe(PID:3608)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\ProgramFiles\BOINC\boincmgr.exe(PID:3696)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\Users\Gateway\Desktop\goagent-goagent-a51d6a2\local\python27.exe(PID:3704)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\ProgramFiles\BOINC\boinctray.exe(PID:3776)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,K:\SkyDrive\Programs\VB\Sherlogger\Sherlogger.exe(PID:3840)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,K:\ProgramFiles(x86)\BaiduYun\baiduyun.exe(PID:3868)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\ProgramFiles(x86)\Google\Drive\googledrivesync.exe(PID:3952)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\ProgramFiles\BOINC\boinc.exe(PID:3964)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\Windows\System32\conhost.exe(PID:3972)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\ProgramFiles(x86)\alipay\SafeTransaction\AlipaySafeTran.exe(PID:17800)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcgrid_dsfl_vina_6.25_windows_x86_64(PID:57092)C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe(PID:16540)AccessPROTECTEDProgram,C:\Windows\System32\conhost.exe(PID:58156)Rollingback...AnalysisendedReason:MalwaredetectedandrolledbackAnomalies:-Modifiesprotectedresource.Theexecutablemodifiesimportantresources(files,processes,etc.)
Tags:病毒查杀.
小编点评:清华天河PCCAD2021是一款高效.
下载小编点评:糖果音乐播放器是一款集音乐排行榜,
下载小编点评:VoiceReader灵云朗读软件是.
下载小编点评:mysqldll.dll文件是小编找.
下载小编点评:电脑远程桌面服务器管理工具是一个非.
下载小编点评:灰鸽子远程控制软件是一款由潍坊灰鸽子安防工程有限.
下载小编点评:《模拟人偶WhiplashCras.
下载小编点评:暗巷网盘外链转换工具是一款可以将网.
下载小编点评:集任务管理器、磁盘管理、系统设置、定时.
下载小编点评:AngelWriter使用Ange.
下载小编点评:软件介绍Xnview非常棒的图像查.
下载小编点评:软件介绍在对传统定时器进行精简的基.
下载小编点评:软件介绍一款提供2015年中医护理学中级职.
下载techlogic Dialer 2000 V1.0.0下载
股票行情纳牛V2.0.2下载
速拓服装饰品管理系统经典版 v21.0302
EMLOG采集程序下载-EMLOG采集程序 v1.0 免费版
融媒陕西app下载-融媒陕西 v1.0.4 手机版
超级玛丽大乱斗(暂未上线)
使命召唤手游云游戏官方版下载安装-使命召唤云游戏最新版本下载v5.0.1.4019306 安卓2024版本
御剑凌仙果盘版下载-果盘御剑凌仙手游下载v1.0.0 官方安卓版
幸运照片修复助手app下载-幸运照片修复助手官方版下载v1.0 安卓版
手指决斗手机版下载-手指决斗游戏下载v6.0 安卓版
荒野之路游戏下载-荒野之路手游下载v1.1 安卓最新版
爆装超变公益服私服下载-爆装超变变态版下载v2.0.1 安卓满v版
以语慧友手游-以语慧友官方版(暂未上线)v1.0.0 安卓版