本帖最后由 病毒探索者 于 2020-4-22 22:50 编辑
App Check- 04/22/2020 10:47:25 下午,File Created by Ransomware,File,C:\Users\virus\Downloads\#Ransomware (2020-04-22)\s.bat,,Removed,RansomGuard
- 04/22/2020 10:47:25 下午,File Created by Ransomware,File,C:\PerfLogs\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:25 下午,File Created by Ransomware,File,C:\Program Files\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:25 下午,File Created by Ransomware,File,C:\Program Files\Bandizip\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:25 下午,File Created by Ransomware,File,C:\Program Files\Bandizip\data\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:25 下午,File Created by Ransomware,File,C:\Program Files\Bandizip\icons\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:25 下午,File Created by Ransomware,File,C:\Program Files\Bandizip\icons\default\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:25 下午,File Created by Ransomware,File,C:\Program Files\Bandizip\langs\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:25 下午,File Created by Ransomware,File,C:\Program Files\Bandizip\shellicons\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:25 下午,File Created by Ransomware,File,C:\Program Files\CheckMAL\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:25 下午,File Created by Ransomware,File,C:\Program Files\Common Files\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\ar-SA\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\bg-BG\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\cs-CZ\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\da-DK\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\de-DE\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\el-GR\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\en-GB\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\en-US\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\es-ES\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\es-MX\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\et-EE\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fi-FI\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fr-CA\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fr-FR\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskclearui\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskmenu\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\osknav\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\osknumpad\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskpred\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\symbols\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\he-IL\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\hr-HR\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\hu-HU\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\HWRCustomization\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\it-IT\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\ja-JP\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\ko-KR\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\LanguageModel\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\lt-LT\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\lv-LV\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\nb-NO\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\nl-NL\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\pl-PL\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\pt-BR\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\pt-PT\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\ro-RO\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\ru-RU\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\sk-SK\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:24 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\sl-SI\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\sr-Latn-RS\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\sv-SE\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\th-TH\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\tr-TR\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\uk-UA\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\ink\zh-TW\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\MSInfo\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\MSInfo\en-US\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\MSInfo\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\Stationery\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\TextConv\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\TextConv\en-US\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\Triedit\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\Triedit\en-US\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\microsoft shared\VGX\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\Services\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\System\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\System\ado\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\System\ado\en-US\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\System\ado\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\System\en-US\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\System\msadc\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\System\msadc\en-US\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\System\msadc\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\System\Ole DB\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\System\Ole DB\en-US\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\System\Ole DB\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\System\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\efifw\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\efifw\Win8\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\hgfs\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\hgfs\Win8\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\memctl\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\memctl\Win8\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\mouse\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\mouse\Win8\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\pvscsi\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\pvscsi\Win8\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\rawdsk\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\rawdsk\Win8\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\video_wddm\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\video_wddm\Vista\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\vmci\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\vmci\device\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\vmci\device\Win8\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\vmci\sockets\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\vmci\sockets\include\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\vmci\sockets\Win8\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\vmxnet3\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\vmxnet3\Win8\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\Drivers\vss\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Common Files\VMware\InstallerCache\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Internet Explorer\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Internet Explorer\en-US\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Internet Explorer\images\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Internet Explorer\SIGNUP\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Internet Explorer\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\MSBuild\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\MSBuild\Microsoft\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Reference Assemblies\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Reference Assemblies\Microsoft\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Reference Assemblies\Microsoft\Framework\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\zh-CHS\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\zh-CHS\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Uninstall Information\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\messages\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\messages\de\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\messages\es\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\messages\fr\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\messages\it\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\messages\ja\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\messages\ko\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\messages\zh_CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\messages\zh_TW\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\plugins\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\plugins\common\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\plugins\vmsvc\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\plugins\vmusr\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\VMware VGAuth\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\VMware VGAuth\schemas\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\win32\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\VMware\VMware Tools\win64\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Defender\Offline\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Defender\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Defender Advanced Threat Protection\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Defender Advanced Threat Protection\Classification\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Defender Advanced Threat Protection\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Mail\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Media Player\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Media Player\Media Renderer\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Media Player\Network Sharing\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Media Player\Skins\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Media Player\Visualizations\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Media Player\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Multimedia Platform\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows NT\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows NT\Accessories\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows NT\Accessories\en-US\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows NT\Accessories\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows NT\TableTextService\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows NT\TableTextService\en-US\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows NT\TableTextService\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Photo Viewer\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Photo Viewer\zh-CN\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Portable Devices\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Security\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Security\BrowserCore\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Security\BrowserCore\en-US\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Sidebar\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Sidebar\Gadgets\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\Windows Sidebar\Shared Gadgets\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\WindowsPowerShell\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\WindowsPowerShell\Configuration\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\WindowsPowerShell\Configuration\Registration\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\WindowsPowerShell\Configuration\Schema\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\WindowsPowerShell\Modules\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\1.0.1\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\1.0.1\Diagnostics\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\1.0.1\Diagnostics\Comprehensive\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\1.0.1\Diagnostics\Simple\readMe!.txt,,Removed,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files (x86)\Internet Download Manager\Toolbar\3d_largeHot_3.bmp,,Restored,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files (x86)\Internet Download Manager\Toolbar\3d_largeHot_3_hdpi15.bmp,,Restored,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files (x86)\Internet Download Manager\Toolbar\3d_large_3.bmp,,Restored,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files (x86)\Internet Download Manager\Toolbar\3d_large_3_hdpi15.bmp,,Restored,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files (x86)\Internet Download Manager\Toolbar\3d_smallHot_3.bmp,,Restored,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files (x86)\Internet Download Manager\Toolbar\3d_small_3.bmp,,Restored,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files (x86)\Internet Download Manager\Toolbar\black-Over.bmp,,Restored,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files (x86)\Internet Download Manager\Toolbar\black.bmp,,Restored,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files (x86)\Internet Download Manager\Toolbar\Blue_Arrow_Disable.bmp,,Restored,RansomGuard
- 04/22/2020 10:47:23 下午,File Created by Ransomware,File,C:\Program Files (x86)\Internet Download Manager\Toolbar\Blue_Arrow_Hot.bmp,,Restored,RansomGuard
- 04/22/2020 10:47:23 下午,Ransomware Behavior Detected,File,C:\Users\virus\Downloads\#Ransomware (2020-04-22)\пункты назначения и грузы.xlsx.exe,f6a6a95be78d0c7ee9f68cc71a265d27,Blocked,RansomGuard
复制代码 |