当前时间: 2026-05-21 14:00:58
分类:办公文件
评论(0)
记一次电脑中病毒(银狐木马)事件原本是想从Github上下载一个工具研究下,因为电脑使用多年了,运行虚拟机有点卡,直接去沙箱里跑下吧,结果发现可疑进程protocal.exe,好家伙这是什么东东?占用内存和CPU基本忽略不计。丢进威胁情报里看看,为了避免广告嫌疑,此处不提哪家的。只有卡巴斯基检测出有中木马,这是银狐木马(SilverFox,也被称为“游蛇/谷堕大盗”)的变种,HEUR:Trojan.Win32.Silverfox.gen就是它的特征码识别结果。姜还是老的辣,此处不得不提卡巴斯基还是牛逼(此处非广告、绝非广告),大学时自己的破电脑花钱也要安装卡巴。马上将其样本喂给数字公司、某某绒,好了,它们也有查杀能力了。多数银狐木马国产杀软还是可以查杀的,现在提供下下载方法:1. 火绒银狐木马专杀工具(推荐)
- 功能:专杀银狐木马及变种,清除 IP-guard 远控、修复注册表与服务项。
- 下载:https://down5.huorong.cn/tools/Hrkill-SilverFox.exe
- 运行:管理员权限运行,点 “开始查杀”,完成后重启。

2. 腾讯电脑管家银狐专杀
- 功能:强力扫描 + 专杀双引擎,清除进程、驱动与自启动项。
- 下载:管家内 “工具箱→银狐专杀” 或独立工具。

3. 安恒银狐专杀(企业级)
- 下载:https://edr.dbappsecurity.com.cn/dd/das_scanner.zip(Win7+)
4. 启明星辰银狐专杀
- 下载:https://venuscloud.cn/download/zip/EDR_SILVER_FOX_TOOL/%E9%93%B6%E7%8B%90%E4%B8%93%E6%9D%80%E5%B7%A5%E5%85%B7.zip
基本
文件
流程
错误
SQL
调试
- 请求信息 : 2026-05-22 14:44:35 HTTP/1.1 GET : https://www.yeyulingfeng.com/a/650904.html
- 运行时间 : 0.085244s [ 吞吐率:11.73req/s ] 内存消耗:4,755.19kb 文件加载:145
- 缓存信息 : 0 reads,0 writes
- 会话信息 : SESSION_ID=33590e043a4801cdd17f5e963fd330b2
- CONNECT:[ UseTime:0.000517s ] mysql:host=127.0.0.1;port=3306;dbname=wenku;charset=utf8mb4
- SHOW FULL COLUMNS FROM `fenlei` [ RunTime:0.000805s ]
- SELECT * FROM `fenlei` WHERE `fid` = 0 [ RunTime:0.000348s ]
- SELECT * FROM `fenlei` WHERE `fid` = 63 [ RunTime:0.000342s ]
- SHOW FULL COLUMNS FROM `set` [ RunTime:0.000476s ]
- SELECT * FROM `set` [ RunTime:0.000210s ]
- SHOW FULL COLUMNS FROM `article` [ RunTime:0.000523s ]
- SELECT * FROM `article` WHERE `id` = 650904 LIMIT 1 [ RunTime:0.000343s ]
- UPDATE `article` SET `lasttime` = 1779432275 WHERE `id` = 650904 [ RunTime:0.001094s ]
- SELECT * FROM `fenlei` WHERE `id` = 64 LIMIT 1 [ RunTime:0.000237s ]
- SELECT * FROM `article` WHERE `id` < 650904 ORDER BY `id` DESC LIMIT 1 [ RunTime:0.000426s ]
- SELECT * FROM `article` WHERE `id` > 650904 ORDER BY `id` ASC LIMIT 1 [ RunTime:0.000543s ]
- SELECT * FROM `article` WHERE `id` < 650904 ORDER BY `id` DESC LIMIT 10 [ RunTime:0.000853s ]
- SELECT * FROM `article` WHERE `id` < 650904 ORDER BY `id` DESC LIMIT 10,10 [ RunTime:0.000757s ]
- SELECT * FROM `article` WHERE `id` < 650904 ORDER BY `id` DESC LIMIT 20,10 [ RunTime:0.001267s ]
0.087867s