西西软件园多重安全检测下载网站、值得信赖的软件下载站!
西西首页 电脑软件 安卓软件 电脑游戏 安卓游戏 排行榜 专题合集

ZBot病毒查杀工具(ZBot Trojan Remover)

v1.7 绿色版
  • ZBot病毒查杀工具(ZBot Trojan Remover)v1.7 绿色版
  • 软件大小:552KB
  • 更新时间:2014-04-24 16:24
  • 软件语言:中文
  • 软件厂商:
  • 软件类别:国产软件 / 免费软件 / 专业工具
  • 软件等级:4级
  • 应用平台:WinAll, Win7
  • 官方网站:暂无
  • 应用备案:
好评:50%
坏评:50%

本类精品

软件介绍

ZBot Trojan Remover可以检测并查杀ZBot变种木马病毒,这病毒可以从网站上窃取用户的银行信息,信用卡信息和paypal账户的登录凭据。

病毒样本:

Malware Analyzer by HX
Analysis started

MD5: 2BB9A1C4B35719ABD022C605A546D6C4

Executing -> \Device\HarddiskVolume3\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe (PID: 13440)
Command-line: "C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe"

C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe
        WriteFile, C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe

C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe
        WriteRegistryKey, Software\Microsoft

C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe
        WriteRegistryKey, Juat

C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe
        DeleteFile, C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe

C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe
        WriteFile, C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe

C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe
        WriteFile, C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe

Executing -> \Device\HarddiskVolume3\Sandbox\Gateway\Analyzer\user\current\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
Command-line: "C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe"

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe
        WriteRegistryKey, Software\Microsoft\Juat

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe
        WriteRegistryKey, f62bfi

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Windows\System32\taskhost.exe (PID: 1992)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Windows\System32\dwm.exe (PID: 2976)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Users\Gateway\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (PID: 3484)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Program Files (x86)\Google\Drive\googledrivesync.exe (PID: 3496)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Program Files\Sandboxie\SbieCtrl.exe (PID: 3524)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (PID: 3584)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, K:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\avp.exe (PID: 3592)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Users\Gateway\Desktop\goagent-goagent-a51d6a2\local\goagent.exe (PID: 3600)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Windows\System32\conhost.exe (PID: 3608)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Program Files\BOINC\boincmgr.exe (PID: 3696)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Users\Gateway\Desktop\goagent-goagent-a51d6a2\local\python27.exe (PID: 3704)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Program Files\BOINC\boinctray.exe (PID: 3776)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, K:\SkyDrive\Programs\VB\Sherlogger\Sherlogger.exe (PID: 3840)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, K:\Program Files (x86)\BaiduYun\baiduyun.exe (PID: 3868)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Program Files (x86)\Google\Drive\googledrivesync.exe (PID: 3952)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Program Files\BOINC\boinc.exe (PID: 3964)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Windows\System32\conhost.exe (PID: 3972)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Program Files (x86)\alipay\SafeTransaction\AlipaySafeTran.exe (PID: 17800)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcgrid_dsfl_vina_6.25_windows_x86_64 (PID: 57092)

C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
        AccessPROTECTEDProgram, C:\Windows\System32\conhost.exe (PID: 58156)


Rolling back...
Analysis ended
Reason: Malware detected and rolled back

Anomalies:
        - Modifies protected resource. The executable modifies important resources (files, processes, etc.)

软件标签: 病毒查杀

软件截图

ZBot病毒查杀工具(ZBot Trojan Remover) v1.7 绿色版

其他版本下载

最新评论查看所有(1)条评论 >

第 1 楼 四川铁通 网友 客人 发表于: 2014/4/24 17:31:57
中毒了,用了多款杀毒都没用,还是专业工具好用一下就杀掉了

支持( 0 ) 盖楼(回复)

发表评论

昵称:
表情: 高兴 可 汗 我不要 害羞 好 下下下 送花 屎 亲亲
TOP
软件下载