Ƨ¾²ÒѾõÄIncaseformatÈ䳿²¡¶¾³Áȼ £¬Ó¦¼±´ëÖù滮ͬ²½ÍƳö

°ä²¼¹¦·ò 2021-01-14

²¡¶¾³ÁµãÐÅÏ¢


²¡¶¾Ãû³Æ£ºincaseformat¡¢Worm.Win32.Autorun

´«²¼õè¾¶£ºÒƶ¯½éÖÊ

·çÏÕˮƽ£º·Çϵͳ·ÖÇøÊý¾Ýɾ³ý

´¥·¢Ç°Ìá£ºËæµçÄÔ¿ª»úÆô¶¯

ÍþвԤ²â£º2021Äê1ÔÂ23ÈÕ½«»áÔٴη¢×÷

´ëÖù滮£º¹ý³ÌÒÖÔì¡¢Îļþɾ³ý


Íþв·ÖÎö


¸Ã²¡¶¾×îÔçµÄ³öÏÖ¹¦·òÔ¼ÔÚ2009Äê £¬ÓÉÓÚ²¡¶¾±àÂëÖй¦·ò»»ËãÃýÎó £¬ÑÓºóÁË10ÓàÄê²Å´¥·¢ºóÐøÐÐΪ £¬incaseformat È䳿²¡¶¾ÔËÐкó £¬½«»á½øÐÐÒÔϲÙ×÷£º


1¡¢½øÐÐ×Ô¸´Ô죨C:\windows\tsay.exe¡¢C:\Windows\ttry.exe£©

2¡¢ÉèÖÃ×¢²á±í×ÔÆô¶¯£¨HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\msfsa£©

3¡¢°µ²ØÊܱ£»¤µÄÎļþ

4¡¢´¥·¢Ö´ÐкóÐøµÄÎļþɾ³ý×÷Ϊ


µ±¿àÖÔÏî


1¡¢ÔÝͣʹÓÃUÅ̵ÈÒÆ¶¯´æ´¢¹¤¾ß

2¡¢²»´ò¿ªÎ´ÖªÎļþ¡¢²»µã»÷δ֪Á´½Ó

3¡¢Íþв¶Ï¸ùǰ²»Òª³ÁÆôµçÄÔ

4¡¢È·±£¹²ÏíĿ¼¹Ø¹Ø¡¢Ö÷»ú·À»ðǽ¿ªÆô


´ëÖù滮


¡ñ δװÖÃÌì«‘EDR


1¡¢ÅŲ鲢ɾ³ýC:\Windows\tsay.exe¡¢C:\Windows\ttry.exeÎļþ

2¡¢ÅŲ鲢ɾ³ý×¢²á±í¡°msfsa¡±Ïî

¡°HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce¡±


¡ñ ÒÑ×°ÖÃÌì«‘EDR


1¡¢¿ªÆô¹Ø¼üõè¾¶ÐÅÏ¢¸Ä¹Û²É¼¯²¢Ôö³¤Íþвõè¾¶ÐÅÏ¢ £¬³ÖÐø¼à¿ØÔ¤¾¯

2¡¢¿ªÆô×¢²á±íÐÅÏ¢¸Ä¹Û²É¼¯²¢Ôö³¤Íþвõè¾¶¼à¿ØÐÅÏ¢ £¬³ÖÐø¼à¿ØÔ¤¾¯

3¡¢Ôö³¤¹ý³ÌºÚÃûµ¥ £¬ÒÖÔ첡¶¾ÔËÐÐ

4¡¢ÍÆËÍÏìÓ¦¾ç±¾ £¬È«Íø¶Ï¸ù²¡¶¾Íþв

5¡¢»ØËÝÍþвÈë¿Ú £¬ÎªºóÐø°²È«Õû¸ÄÌṩ֧³Ö


±¦ÔËÀ³¹Ù·½ÍøÕ¾Ìì«‘Öն˸߼¶Íþв¼ì²âÓëÏìӦϵͳ£¨¼ò³ÆÌì«‘EDR£© £¬·¢ÏÖ¡¢·ÖÎö¡¢´ëÖð²È«ÍþвµÄͬʱÌṩÃÀÂúµÄ¿ÉÊÓ»¯»ØËÝÄÜÁ¦ £¬Ð­ÖúÖÎÀíÈËÔ±¶¨Î»ÍþвԴͷ ¡£


ÎÂܰÌáÐÑ


¿Éͨ¹ýÓʼþ»òÆäËû·½Ê½·î¸æËùÓÐÈËÔ±Ö´ÐÐÒ»´Î±¦ÔËÀ³¹Ù·½ÍøÕ¾ÌṩµÄ¡°¹ØÓÚincaseformat¶Ï¸ù¾ç±¾¡±ºóÔٹػú»ò³ÁÆôµçÄÔ ¡£

¶Ï¸ù¾ç±¾»ñÈ¡·½Ê½£º

1¡¢Ö±½ÓÁªÏµ¶Ô½ÓÉÌÎñ¡¢¼¼Êõ

2¡¢²¦´ò±¦ÔËÀ³¹Ù·½ÍøÕ¾ÈÈÏߵ绰£º400-624-3900


±¦ÔËÀ³¹Ù·½ÍøÕ¾½«³ÖÐø¹Ø×¢´Ë²¡¶¾ºóÐø¶¯Ì¬²¢ÊµÊ±Ìṩ½â¾ö¹æ»® ¡£