Ransom.Win64.GROUNDE.THGOEBC
Win64:Evo-gen [Trj](AVAST)
Windows
恶意软件类型:
Ransomware
有破坏性?:
没有
加密?:
没有
In the Wild:
是的
概要
它以文件的形式出现在系统中,可能是其他恶意软件投放的,或者是用户在访问恶意网站时无意中下载的。
技术详细信息
???????
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
??
???????:
- {Encrypted Directory}\!!readme!!!.txt
- {Malware File Path}\temp.cmd ? Used to delete itself
???????:
- "%System%\vssadmin.exe" delete shadows /all /quiet
- "%System%\net.exe" stop MSSQLSERVER /f /m
- cmd /c temp.cmd {Malware File Path}/{Malware File Name}.{Malware Extension}
(??: %System% ? Windows ? system ???,???? C:\Windows\System (Windows 98 ? ME)?C:\WINNT\System32 (Windows NT ? 2000) ? C:\WINDOWS\system32 (Windows 2000(32-bit)?XP?Server 2003(32-bit)?Vista?7?8?8.1?2008(64-bit),2012(64bit) ? 10(64-bit))?)
??????
?????????:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\
Microsoft\Windows NT\Terminal Services
MaxDisconnectionTime = 1209600000
解决方案
Step 2
??Windows ME?XP??,????,????????????,??????????
Step 3
注意:在此恶意软件/间谍软件/灰色软件执行期间,并非所有文件、文件夹和注册表键值和项都会安装到您的计算机上。这可能是由于不完整的安装或其他操作系统条件所致。如果您没有找到相同的文件/文件夹/注册表信息,请继续进行下一步操作。
Step 4
???????
????:????Windows???
- In HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services
- MaxDisconnectionTime = 1209600000
- MaxDisconnectionTime = 1209600000
Step 5
????????
- {Encrypted Directory}\!!readme!!!.txt
- {Malware File Path}\temp.cmd
Step 6
?????????????,???????Ransom.Win64.GROUNDE.THGOEBC?? ????????????????????????,????????????????????????????????????????
Step 7
从备份中恢复加密文件。