Ƨ¾²ÒѾõÄIncaseformatÈ䳿²¡¶¾³Áȼ£¬Ó¦¼±´ëÖù滮ͬ²½ÍƳö

°ä²¼¹¦·ò 2021-01-14

²¡¶¾³ÁµãÐÅÏ¢


²¡¶¾Ãû³Æ£ºincaseformat¡¢Worm.Win32.Autorun

´«²¼õè¾¶£ºÒƶ¯½éÖÊ

·çÏÕˮƽ£º·Çϵͳ·ÖÇøÊý¾Ýɾ³ý

´¥·¢Ç°Ìá£ºËæµçÄÔ¿ª»úÆô¶¯

ÍþвԤ²â£º2021Äê1ÔÂ23ÈÕ½«»áÔٴη¢×÷

´ëÖù滮£º¹ý³ÌÒÖÔì¡¢Îļþɾ³ý


Íþв·ÖÎö


¸Ã²¡¶¾×îÔçµÄ³öÏÖ¹¦·òÔ¼ÔÚ2009Ä꣬ÓÉÓÚ²¡¶¾±àÂëÖй¦·ò»»ËãÃýÎó£¬ÑÓºóÁË10ÓàÄê²Å´¥·¢ºóÐøÐÐΪ£¬incaseformat È䳿²¡¶¾ÔËÐк󣬽«»á½øÐÐÒÔϲÙ×÷£º


1¡¢½øÐÐ×Ô¸´Ô죨C:\windows\tsay.exe¡¢C:\Windows\ttry.exe£©

2¡¢ÉèÖÃ×¢²á±í×ÔÆô¶¯£¨HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\msfsa£©

3¡¢°µ²ØÊܱ£»¤µÄÎļþ

4¡¢´¥·¢Ö´ÐкóÐøµÄÎļþɾ³ý×÷Ϊ


µ±¿àÖÔÏî


1¡¢ÔÝͣʹÓÃUÅ̵ÈÒÆ¶¯´æ´¢¹¤¾ß

2¡¢²»´ò¿ªÎ´ÖªÎļþ¡¢²»µã»÷δ֪Á´½Ó

3¡¢Íþв¶Ï¸ùǰ²»Òª³ÁÆôµçÄÔ

4¡¢È·±£¹²ÏíĿ¼¹Ø¹Ø¡¢Ö÷»ú·À»ðǽ¿ªÆô


´ëÖù滮


¡ñ δװÖÃÌì«‘EDR


1¡¢ÅŲ鲢ɾ³ýC:\Windows\tsay.exe¡¢C:\Windows\ttry.exeÎļþ

2¡¢ÅŲ鲢ɾ³ý×¢²á±í¡°msfsa¡±Ïî

¡°HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce¡±


¡ñ ÒÑ×°ÖÃÌì«‘EDR


1¡¢¿ªÆô¹Ø¼üõè¾¶ÐÅÏ¢¸Ä¹Û²É¼¯²¢Ôö³¤Íþвõè¾¶ÐÅÏ¢£¬³ÖÐø¼à¿ØÔ¤¾¯

2¡¢¿ªÆô×¢²á±íÐÅÏ¢¸Ä¹Û²É¼¯²¢Ôö³¤Íþвõè¾¶¼à¿ØÐÅÏ¢£¬³ÖÐø¼à¿ØÔ¤¾¯

3¡¢Ôö³¤¹ý³ÌºÚÃûµ¥£¬ÒÖÔ첡¶¾ÔËÐÐ

4¡¢ÍÆËÍÏìÓ¦¾ç±¾£¬È«Íø¶Ï¸ù²¡¶¾Íþв

5¡¢»ØËÝÍþвÈë¿Ú£¬ÎªºóÐø°²È«Õû¸ÄÌṩ֧³Ö


GA»Æ½ð¼×Ìì«‘Öն˸߼¶Íþв¼ì²âÓëÏìӦϵͳ£¨¼ò³ÆÌì«‘EDR£©£¬·¢ÏÖ¡¢·ÖÎö¡¢´ëÖð²È«ÍþвµÄͬʱÌṩÃÀÂúµÄ¿ÉÊÓ»¯»ØËÝÄÜÁ¦£¬Ð­ÖúÖÎÀíÈËÔ±¶¨Î»ÍþвԴͷ¡£


ÎÂܰÌáÐÑ


¿Éͨ¹ýÓʼþ»òÆäËû·½Ê½·î¸æËùÓÐÈËÔ±Ö´ÐÐÒ»´ÎGA»Æ½ð¼×ÌṩµÄ¡°¹ØÓÚincaseformat¶Ï¸ù¾ç±¾¡±ºóÔٹػú»ò³ÁÆôµçÄÔ¡£

¶Ï¸ù¾ç±¾»ñÈ¡·½Ê½£º

1¡¢Ö±½ÓÁªÏµ¶Ô½ÓÉÌÎñ¡¢¼¼Êõ

2¡¢²¦´òGA»Æ½ð¼×ÈÈÏߵ绰£º400-624-3900


GA»Æ½ð¼×½«³ÖÐø¹Ø×¢´Ë²¡¶¾ºóÐø¶¯Ì¬²¢ÊµÊ±Ìṩ½â¾ö¹æ»®¡£