ZBot Trojan Remover是一款可以检测并查杀ZBot变种木马病毒的查杀工具,ZBot变种木马会在电脑中潜伏,并且专门针对用户的各种银行账号,是一种威胁非常大的病毒,大家一定要小心防范。
病毒样本:
Malware Analyzer by HX
Analysis started
MD5: 2BB9A1C4B35719ABD022C605A546D6C4
Executing -> \Device\HarddiskVolume3\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe (PID: 13440)
Command-line: "C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe"
C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteFile, C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe
C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteRegistryKey, Software\Microsoft
C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteRegistryKey, Juat
C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe
DeleteFile, C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe
C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteFile, C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe
C:\Users\Gateway\Desktop\2BB9A1C4B35719ABD022C605A546D6C4.exe
WriteFile, C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe
Executing -> \Device\HarddiskVolume3\Sandbox\Gateway\Analyzer\user\current\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
Command-line: "C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe"
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe
WriteRegistryKey, Software\Microsoft\Juat
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe
WriteRegistryKey, f62bfi
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Windows\System32\taskhost.exe (PID: 1992)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Windows\System32\dwm.exe (PID: 2976)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Users\Gateway\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (PID: 3484)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Program Files (x86)\Google\Drive\googledrivesync.exe (PID: 3496)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Program Files\Sandboxie\SbieCtrl.exe (PID: 3524)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (PID: 3584)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, K:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\avp.exe (PID: 3592)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Users\Gateway\Desktop\goagent-goagent-a51d6a2\local\goagent.exe (PID: 3600)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Windows\System32\conhost.exe (PID: 3608)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Program Files\BOINC\boincmgr.exe (PID: 3696)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Users\Gateway\Desktop\goagent-goagent-a51d6a2\local\python27.exe (PID: 3704)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Program Files\BOINC\boinctray.exe (PID: 3776)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, K:\SkyDrive\Programs\VB\Sherlogger\Sherlogger.exe (PID: 3840)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, K:\Program Files (x86)\BaiduYun\baiduyun.exe (PID: 3868)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Program Files (x86)\Google\Drive\googledrivesync.exe (PID: 3952)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Program Files\BOINC\boinc.exe (PID: 3964)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Windows\System32\conhost.exe (PID: 3972)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Program Files (x86)\alipay\SafeTransaction\AlipaySafeTran.exe (PID: 17800)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcgrid_dsfl_vina_6.25_windows_x86_64 (PID: 57092)
C:\Users\Gateway\AppData\Roaming\Gola\xyeq.exe (PID: 16540)
AccessPROTECTEDProgram, C:\Windows\System32\conhost.exe (PID: 58156)
Rolling back...
Analysis ended
Reason: Malware detected and rolled back
Anomalies:
- Modifies protected resource. The executable modifies important resources (files, processes, etc.)
- PC官方版
- 安卓官方手机版
- IOS官方手机版











360安全卫士极速版V15.0.2.1036 电脑版
马保国杀毒卫士1.0绿色版
AutoCAD Virus Cleaner(CAD杀毒软件)1.62 绿色版
Avast Pro Antivirus18.5.2342 简体中文高级版
瑞星之剑勒索病毒防御软件1.0.0.68 绿色版
Xshell后门查杀工具1.0 免费版
Allcry解密工具1.0.0.1 免费版
Meltdown&Spectre检测工具1.0.0.1 免费版
小红伞Avira Antivirus Pro 201815.0.36.200 中文授权版(附证书地址)
ESET工作站防护高级版6.6.2078.5中文正式版
3DMax病毒查杀脚本1.0 绿色免费版
Max杀毒卫士1.81 官方版
3dmax病毒清理大师1.0 官方版
电脑管家Globelmposter勒索病毒拦截查杀工具12.12 官方版
360 Skygofree恶意软件查杀工具最新免费版
360杀毒离线升级包171026安装版最新版
ESET NOD32防病毒软件简体中文版v11.0.144.0正式版【附激活密钥】
BadRabbit勒索病毒查杀工具360最新版
Bad Rabbit勒索病毒360防护版安全版
坏兔子Bad Rabbit勒索病毒查杀修复工具正式版
坏兔子(Bad Rabbit)病毒查杀软件最新免费版
火绒互联网安全软件6.0.5.3 官方版
瑞星杀毒软件V17官方版25.0.9.80 免费版
金山毒霸电脑版15.2023.2.4.061900.1335 官方版
江民速智版杀毒软件V19免费版
2020卡巴斯基反病毒软件20.0.14.1085免费版
金山毒霸木马专杀工具11.4.6 最新官方版
360安全卫士U盘病毒专杀工具2.1 免费版
德国小红伞杀毒软件(Avira AntiVir Personal)2020免费中文版
360杀毒正式版5.0.0.8160 官方版64位
U盘杀毒专家(USBKiller)3.22 官方单机版
大蜘蛛杀毒软件(Dr.Web)12.0 官方最新版


飞塔免费杀毒软件(FortiClient )5.4.0.0780
暴风一号病毒专杀工具V1.0 绿色中文免费版
计算机安全与故障攻略 1.0
瑞星永恒之蓝免疫工具+病毒专杀最新官方版
McAfee Desktop Firewall v8.0 简体中文版
ESET VC52 WebID(ESET ID获取工具)2.2.2.4
pchunter64专业版1.52 绿色版
Ashampoo FireWall Pro v1.12 汉化免费版
Ramnit.b专杀工具