IT猫扑网安全相关

分类分类

ZBot病毒查杀工具(ZBot Trojan Remover)

ZBot病毒查杀工具(ZBot Trojan Remover)

v1.7 绿色版

大小:554.00 KB更新:2017/07/17

类别:病毒防治系统:Winll

立即下载
  • ZBot病毒查杀工具(ZBot Trojan Remover)(1)

ZBot病毒查杀工具(ZBot Trojan Remover)是一款好用的病毒查杀软件,可以检测并查杀ZBot变种木马病毒,这病毒可以从网站上窃取用户的银行信息,信用卡信息和paypal账户的登录凭据。欢迎来IT猫扑网下载!

病毒样本:

Malware Analyzer by HX

Analysis started

MD5: 2BB9A1C4B35719ABD022C605A546D6C4

Executing -> DeviceHarddiskVolume3UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe (PID: 13440)

Command-line: &C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe&

C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe

WriteFile, C:UsersGatewayAppDataRoamingGolaxyeq.exe

C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe

WriteRegistryKey, SoftwareMicrosoft

C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe

WriteRegistryKey, Juat

C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe

DeleteFile, C:UsersGatewayAppDataRoamingGolaxyeq.exe

C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe

WriteFile, C:UsersGatewayAppDataRoamingGolaxyeq.exe

C:UsersGatewayDesktop2BB9A1C4B35719ABD022C605A546D6C4.exe

WriteFile, C:UsersGatewayAppDataRoamingGolaxyeq.exe

Executing -> DeviceHarddiskVolume3SandboxGatewayAnalyzerusercurrentAppDataRoamingGolaxyeq.exe (PID: 16540)

Command-line: &C:UsersGatewayAppDataRoamingGolaxyeq.exe&

C:UsersGatewayAppDataRoamingGolaxyeq.exe

WriteRegistryKey, SoftwareMicrosoftJuat

C:UsersGatewayAppDataRoamingGolaxyeq.exe

WriteRegistryKey, f62bfi

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

accessPROTECTEDProgram, C:WindowsSystem32taskhost.exe (PID: 1992)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:WindowsSystem32dwm.exe (PID: 2976)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:UsersGatewayAppDataLocalMicrosoftSkyDriveSkyDrive.exe (PID: 3484)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:Program Files (x86)GoogleDrivegoogledrivesync.exe (PID: 3496)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:Program FilessandboxieSbieCtrl.exe (PID: 3524)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:Program Files (x86)EvernoteEvernoteEvernoteClipper.exe (PID: 3584)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, K:Program Files (x86)Kaspersky LabKaspersky Endpoint Security 8 for Windowsavp.exe (PID: 3592)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:UsersGatewayDesktopgoagent-goagent-a51d6a2localgoagent.exe (PID: 3600)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:WindowsSystem32conhost.exe (PID: 3608)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:Program FilesBOINCboincmgr.exe (PID: 3696)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:UsersGatewayDesktopgoagent-goagent-a51d6a2localpython27.exe (PID: 3704)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:Program FilesBOINCboinctray.exe (PID: 3776)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, K:SkyDriveProgramsvbSherloggerSherlogger.exe (PID: 3840)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, K:Program Files (x86)BaiduYunbaiduyun.exe (PID: 3868)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:Program Files (x86)GoogleDrivegoogledrivesync.exe (PID: 3952)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:Program FilesBOINCboinc.exe (PID: 3964)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:WindowsSystem32conhost.exe (PID: 3972)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:Program Files (x86)alipaySafeTransactionAlipaySafeTran.exe (PID: 17800)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:ProgramDataBOINCprojectswww.worldcommunitygrid.orgwcgrid_dsfl_vina_6.25_windows_x86_64 (PID: 57092)

C:UsersGatewayAppDataRoamingGolaxyeq.exe (PID: 16540)

AccessPROTECTEDProgram, C:WindowsSystem32conhost.exe (PID: 58156)

Rolling back...

Analysis ended

Reason: Malware detected and rolled back

Anomalies:

- Modifies protected resource. The executable modifies important resources (files, processes, etc.)

精品推荐
同类推荐
未知地区APP
相关下载
  • 最新排行
  • 最热排行
  • 评分最高
安全相关排行榜

点击查看更多

点击查看更多

点击查看更多

说两句网友评论
    我要跟贴
    取消
    实时热词
    比特梵德avast小红伞avg国外杀毒软件u盘病毒U盘杀毒cad病毒专杀工具nsa武器库免疫工具安全软件百度卫士诺顿迈克菲nod32大蜘蛛卡巴斯基卡巴斯基激活防病毒新毒霸瑞星杀毒