About the use of PyXLL

On January 13, 2021, a well-known domestic security team detected an outbreak of a worm called incaseformat in China.

After the worm is executed, it will self-copy to the Windows directory of the system disk and create a registry to start automatically. Once the user restarts the host, the virus matrix will be executed from the Windows directory. The virus process will traverse all disk files except the system disk for deletion. ,

It has caused irreparable losses to users. At present, users in different industries have been found to have been infected in many regions of the country, and the scope of virus transmission has not been clearly targeted.

该安全团队还为全网用户提供免费查杀工具,可下载如下工具,进行检测查杀:

64位系统下载链接:
http://edr.sangfor.com.cn/tool/SfabAntiBot_X64.7z

32位系统下载链接:
http://edr.sangfor.com.cn/tool/SfabAntiBot_X86.7z

image

Guess you like

Origin blog.csdn.net/weixin_42321517/article/details/112645045