App Check- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\kingsoft\office6\mtfont\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\kingsoft\office6\mtfont\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\kingsoft\office6\mtfont\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{4931385B-094D-4DC5-BD6A-5188FE9C51DF}v14.20.27508\packages\vcRuntimeAdditional_amd64\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{4931385B-094D-4DC5-BD6A-5188FE9C51DF}v14.20.27508\packages\vcRuntimeAdditional_amd64\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{4931385B-094D-4DC5-BD6A-5188FE9C51DF}v14.20.27508\packages\vcRuntimeAdditional_amd64\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{7b178cda-9740-4701-a92a-f168d213b343}\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{7b178cda-9740-4701-a92a-f168d213b343}\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{7b178cda-9740-4701-a92a-f168d213b343}\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{8c3f057e-d6a6-4338-ac6a-f1c795a6577b}\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{8c3f057e-d6a6-4338-ac6a-f1c795a6577b}\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{8c3f057e-d6a6-4338-ac6a-f1c795a6577b}\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{B96F6FA1-530F-42F1-9F71-33C583716340}v14.20.27508\packages\vcRuntimeMinimum_x86\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{B96F6FA1-530F-42F1-9F71-33C583716340}v14.20.27508\packages\vcRuntimeMinimum_x86\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{B96F6FA1-530F-42F1-9F71-33C583716340}v14.20.27508\packages\vcRuntimeMinimum_x86\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{C9DE51F8-7846-4621-815D-E8AFD3E3C0FF}v14.20.27508\packages\vcRuntimeAdditional_x86\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{C9DE51F8-7846-4621-815D-E8AFD3E3C0FF}v14.20.27508\packages\vcRuntimeAdditional_x86\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{C9DE51F8-7846-4621-815D-E8AFD3E3C0FF}v14.20.27508\packages\vcRuntimeAdditional_x86\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{F3241984-5A0E-4632-9025-AA16E0780A4B}v14.20.27508\packages\vcRuntimeMinimum_amd64\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{F3241984-5A0E-4632-9025-AA16E0780A4B}v14.20.27508\packages\vcRuntimeMinimum_amd64\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\Package Cache\{F3241984-5A0E-4632-9025-AA16E0780A4B}v14.20.27508\packages\vcRuntimeMinimum_amd64\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\USOShared\Logs\User\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\USOShared\Logs\User\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\USOShared\Logs\User\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\logs\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\logs\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\logs\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\RawdskCompatibility\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\RawdskCompatibility\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\RawdskCompatibility\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\manifest.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\manifest.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\manifest.txt.AKO,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\Adobe{过}{滤}Flashcs3.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\Adobe{过}{滤}Flashcs3.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\Adobe{过}{滤}Flashcs3.txt.AKO,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\adobephotoshopcs3.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\adobephotoshopcs3.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\adobephotoshopcs3.txt.AKO,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\googledesktop.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\googledesktop.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\googledesktop.txt.AKO,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\microsoftoffice.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\microsoftoffice.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\microsoftoffice.txt.AKO,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\vistasidebar.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\vistasidebar.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\vistasidebar.txt.AKO,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\visualstudio2005.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\visualstudio2005.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\visualstudio2005.txt.AKO,,Removed,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\vmwarefilters.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\vmwarefilters.txt,,Restored,RansomGuard
- 04/22/2020 10:58:32 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\vmwarefilters.txt.AKO,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\win7gadgets.txt,,Restored,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\win7gadgets.txt,,Restored,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware Tools\Unity Filters\win7gadgets.txt.AKO,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\de\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\de\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\de\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\en\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\en\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\en\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\es\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\es\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\es\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\fr\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\fr\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\fr\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\it\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\it\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\it\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ja\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ja\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ja\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ko\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ko\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ko\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_CN\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_CN\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_CN\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_TW\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_TW\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_TW\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\ProgramData\VMware\VMware VGAuth\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\Users\Default\AkoReadMe.txt,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\Users\Default\AkoReadMe.html,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\Users\Default\DO_NOT_REMOVE.p44Fa0_ID.key,,Removed,RansomGuard
- 04/22/2020 10:58:31 下午,File Created by Ransomware,File,C:\Users\Public\Desktop\Bandizip.lnk,,Restored,RansomGuard
- 04/22/2020 10:58:31 下午,Ransomware Behavior Detected,File,C:\Users\virus\Downloads\#Ako (2020-04-21).exe,21195dabaebdbf3c584025ac5b9b1b5c,Blocked,RansomGuard
复制代码 |