#最近我用来实验各种奇奇怪怪的工具的Win7虚拟机总是伴随启动一个 "Chrome.exe" process, but the machine has never been installed in Google browser
First navigate to the file:
#症状:
1. Path: C:\user\***\appdata\romaing\chrome.exe, the boring is that if the end of the process will be directly to the blue screen, it is too arrogant.
2. "Netstat-ano" View the process port open and connected, did not find a link to the process (perhaps an older version of the Hack tool, now no one to manage).
3. View the startup item found there are many places that the exe file was added.
#进入安全模式, the registry searches for "Chrome" and there are a lot of related table entries
and register the firewall policy
In particular, the relevant string "d367e43651a1cef4a18fb38335c8460c" is found in the boot entry area
And
The other EXE file and the startup file are found accordingly
There's also an entry that looks like a record keyboard.
#简要分析一下可能是 "Chrome.exe" to register the startup item, follow the system startup release the file "D367e43651a1cef4a18fb38335c8460c.exe" and register the firewall and so on
#手工清除方法也很简单
#安全模式下
1. Delete all "chrome" and "d367e43651a1cef4a18fb38335c8460c" related table entries in the registry
2. Delete the file "C:\user\***\appdata\romaing\chrome.exe"
, "C:\user\***\appdata\romaing\microsoft\windows\startmenu\programs\startup\ D367e43651a1cef4a18fb38335c8460c.exe "
and "C:\Windows\pss\d367e43651a1cef4a18fb38335c8460c.exe.Startup"
3. Restart
#完后可以发现进程 "Chrome.exe" and startup items are clean.
#样本 "Chrome.exe" (Always feel a hack tool to get the back door ...)
Link: http://pan.baidu.com/s/1slvZPud Password: 80al
| Md5:f5d95b4f622af3e58bfb5230b85b00c1 |
| sha1:f0429298ee5c13f2d0b0909d69751130200b351d |
#大量杀软报毒请谨慎下载!!!
A strange "chrome.exe" process