¹ØÓÚ1ÔÂ13ÈÕ±¬·¢µÄincaseformat²¡¶¾ÊÂÎñÆÊÎö
2021-01-13
Ò». ÊÂÎñÅä¾°
2021Äê1ÔÂ13ÈÕ£¬AG¹«Ë¾¿Æ¼¼Ó¦¼±ÏìÓ¦ÍŶӽӵ½Ìì϶à¸ö¿Í»§·´ÏìѬȾËùνµÄincaseformat²¡¶¾£¬Éæ¼°Õþ¸®¡¢Ò½ÁÆ¡¢½ÌÓý¡¢ÔËÓªÉ̵ȶà¸öÐÐÒµ£¬ÇÒѬȾÖ÷»ú¶àΪ²ÆÎñÖÎÀíÏà¹ØÓ¦ÓÃϵͳ¡£Ñ¬È¾Ö÷»úÌåÏÖΪËùÓзÇϵͳ·ÖÇøÎļþ¾ù±»É¾³ý£¬ÓÉÓÚ±»É¾³ýÎļþ·ÖÇø¸ùĿ¼Ï¾ù±£´æÃûΪincaseformat.logµÄ¿ÕÎļþ£¬Òò´ËÍøÂçÉϽ«´Ë²¡¶¾ÃüÃûΪincaseformat¡£

Íø´«ÐÅÏ¢½ØÍ¼
¶þ. ²¡¶¾ÆÊÎö
´ÓËÑË÷ÒýÇæÐ§¹ûÀ´¿´£¬¸Ã²¡¶¾×îÔç·ºÆðʱ¼äΪ2009Ä꣬Ö÷Á÷ɱ¶¾Èí¼þ³§É̾ù½«´Ë²¡¶¾ÃüÃûΪWorm.Win32.Autorun£¬´ÓÃû³Æ¿ÉÒÔÅжϸò¡¶¾ÎªWindowsƽ̨ͨ¹ýÒÆ¶¯½éÖÊÈö²¥µÄÈ䳿²¡¶¾¡£
²¡¶¾ÎļþÔËÐкó£¬Ê×Ïȸ´ÖÆ×ÔÉíµ½WindowsĿ¼Ï£¨C:\windows\tsay.exe£©£¬Îļþͼ±êαװΪÎļþ¼Ð¡£

ͬʱÐÞ¸Ä×¢²á±í¼üֵʵÏÖ×ÔÆô¶¯£¬Éæ¼°×¢²á±íÏîΪ£º
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\msfsa

²¡¶¾Îļþ½«ÔÚÖ÷»úÖØÆôºóÔËÐУ¬²¢×îÏȱéÀúËùÓзÇϵͳ·ÖÇøÏÂĿ¼²¢ÉèÖÃΪÒþ²Ø£¬Í¬Ê±½¨ÉèͬÃûµÄ²¡¶¾Îļþ¡£

±ðµÄ»¹»áͨ¹ýÐÞ¸Ä×¢²á±í£¬ÊµÏÖ²»ÏÔʾÒþ²ØÎļþ¼°Òþ²ØÒÑÖªÎļþÀàÐÍÀ©Õ¹Ãû£¬Éæ¼°µÄ×¢²á±íÏî°üÀ¨£º
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\checkedvalue
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt\checkedvalue

×îºó¶Ô·Çϵͳ·ÖÇøÏÂËùÓÐÎļþÖ´ÐÐɾ³ý²Ù×÷£¬²¢½¨Éèincaseformat.logÎļþ¡£

Èý. ѬȾÆÊÎö
¸Ã²¡¶¾ÓÉÓÚ±àдʱ¶Ôijʱ¼äÅжϱäÁ¿¸³Öµ¹ýʧ£¬µ¼ÖÂÔÚ½ñÌ죨2021Äê1ÔÂ13ÈÕ£©²Å´¥·¢²¢Ö´ÐÐÎļþɾ³ýµÄ´úÂëÂß¼£¬ÏÖʵ¸Ã²¡¶¾¿ÉÄÜÒÑÔÚѬȾÖ÷»úÉÏפÁô¶àÄ꣬µ«ÓÉÓÚȱÉÙÖ÷»ú·À²¡¶¾Èí¼þ»ò°×Ãûµ¥ÉèÖùýʧµÈÔµ¹ÊÔÓÉ£¬Ò»Ö±Î´Äܱ»·¢Ã÷¡£
ÓÉÓÚ²¡¶¾×Ô¼ºÖ»ÄÜͨ¹ýUÅ̵ÈÒÆ¶¯½éÖʾÙÐÐÈö²¥£¬²¢ÎÞÏà¹ØÍøÂçÈö²¥ÌØÕ÷£¬´Ë´ÎÔÚº£ÄÚ¶à¸öÐÐÒµ·ºÆð´ó¹æÄ£Ñ¬È¾ÊÂÎñ£¬ÍƲâ¿ÉÄÜÓëÏà¹ØÓ¦ÓÃϵͳµÄ¹©Ó¦Á´»ò³§ÉÌÔËάÓйأ¬È磺Èí¼þ·Ö·¢¡¢¸üÐÂÉý¼¶¡¢Ô¶³ÌÔËάµÈ£¬ÏêϸÈö²¥Í¾¾¶»¹Ðè×ö½øÒ»²½ËÝÔ´ÆÊÎö¡£
ËÄ. ´¦Öóͷ£½¨Òé
1¡¢ Ö÷»úÅŲé
ÅŲéÖ÷»úWindowsĿ¼ÏÂÊÇ·ñ±£´æÍ¼±êΪÎļþ¼ÐµÄtsay.exeÎļþ£¬Èô±£´æ¸ÃÎļþ£¬ÊµÊ±É¾³ý¼´¿É£¬É¾³ýǰÇÐÎð¶ÔÖ÷»úÖ´ÐÐÖØÆô²Ù×÷¡£
2¡¢ Êý¾Ý»Ö¸´
ÇÐÎð¶Ô±»É¾³ýÎļþµÄ·ÖÇøÖ´ÐÐд²Ù×÷£¬ÒÔÃâÁýÕÖÔÓÐÊý¾Ý£¬È»ºóʹÓó£¼ûµÄÊý¾Ý»Ö¸´Èí¼þ£¨È磺Finaldata¡¢recuva¡¢DiskGeniusµÈ£©¼´¿É»Ö¸´±»É¾³ýÊý¾Ý¡£

3¡¢ ²¡¶¾ÕûÀí
ÓÉÓÚ²¡¶¾·ºÆðÄê·Ý½ÏÔ磬Ö÷Á÷ɱ¶¾Èí¼þ¾ù¿É¶Ô¸Ã²¡¶¾¾ÙÐвéɱ£¬Óû§Ò²¿Éͨ¹ýÒÔÏÂÊÖ¹¤·½·¨¾ÙÐÐÕûÀíÐÞ¸´£º
1) ͨ¹ýʹÃüÖÎÀíÆ÷¿¢Ê²¡¶¾Ïà¹ØÀú³Ì£¨ttry.exe£©

2) ɾ³ýWindowsĿ¼ÏÂפÁôÎļþtsay.exeºÍttry.exe¼°×¢²á±íÏà¹ØÆô¶¯ÏRunOnce£©

3) »Ö¸´ÉÏÊö±»²¡¶¾¸Ä¶¯µÄÓÃÓÚÒþ²ØÎļþ¼°À©Õ¹ÃûµÄÏà¹Ø×¢²á±íÏî¡£
Îå. ¸½Â¼
ÒÑÖªÑù±¾MD5£º
4B982FE1558576B420589FAA9D55E81A
1071D6D497A10CEF44DB396C07CCDE65
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







