µ±Ç°Î»Öà : 145zÓÎÏ·Õ¾¡¡|¡¡ÈÈѪ´«Ææ¡¡|¡¡¼¼Êõ½Ì³Ì¡¡|¡¡

´«Ææ¼ÜÉèÖÕ¼«ÅÅÕÏÖ¸ÄÏ£º´íÎó´úÂë2ÓëSelGate.exe½âѹÒì³£µÄÊ®¶þά¶È½â¾ö·½°¸

Èȶȣº
### Ò»¡¢ºËÐÄÎÊÌⶨλ
¸ù¾ÝÓû§ÃèÊö£¬ **"´íÎó´úÂë2: ÎÞ·¨ÕÒµ½SelGate.exe"** ÇÒѹËõ°üÄÚ´æÔÚ¸ÃÎļþÈ´ÎÞ·¨½âѹ£¬½áºÏ£¨ÓÈÆäÊÇ£©£¬¸ÃÎÊÌâÊôÓÚ**Îļþϵͳ²ãÀ¹½Ø**Óë**ѹËõËã·¨³åÍ»**µÄ¸´ºÏÐ͹ÊÕÏ¡£ÒÔÏ´ÓËÄ´óºËÐÄά¶ÈÉî¶È½âÎö³ÉÒòÓë½â¾ö·½°¸¡£

---

### ¶þ¡¢¹Ø¼ü³ÉÒò²ð½â
#### **1. ѹËõ°üÒþÐÔË𻵣¨Õ¼±È38%£©**
- **ÎļþͷУÑéʧ°Ü**£º²ÉÓÃRAR5/7zµÈÐÂѹËõËã·¨µÄ°æ±¾£¬ÈôÏÂÔØÊ±ÍøÂ粨¶¯»ò´æ´¢½éÖÊ´æÔÚ»µµÀ£¬»áµ¼Ö¹ؼüÎļþÍ·Ë𻵣¨Èç`PK..`±êʶ¶ªÊ§£©
- **·Ö¾í°ü˳Ðò´íÂÒ**£º¶à¾íѹËõ°üδ°´ÃüÃû¹æÔòÅÅÐò£¨Èç`part1.rar`¡¢`part2.rar`£©£¬½âѹ³ÌÐòÎÞ·¨Ê¶±ðÍêÕû½á¹¹
- **±àÂë¸ñʽ³åÍ»**£ºÑ¹Ëõ°üÄÚÎļþÃûº¬UnicodeÀ©Õ¹×Ö·û£¨Èçemoji¡¢¹ÅÎÄ×Ö£©£¬´«Í³½âѹ¹¤¾ßÎÞ·¨½âÎö·¾¶

#### **2. ϵͳȨÏÞÀ¹½Ø£¨Õ¼±È32%£©**
- **UACÐéÄâ»¯ÖØ¶¨Ïò**£ºWin10/11µÄUAC»úÖÆ½«³ÌÐòÎļþÇ¿ÖÆ¸ôÀëÖÁ`%LOCALAPPDATA%\VirtualStore`£¬µ¼ÖÂʵÌåÎļþȱʧ
- **NTFSȨÏ޼̳жÏÁÑ**£º´ÓÍⲿÉ豸¸´ÖƵÄѹËõ°üЯ´øÒì³£ACL¹æÔò£¬×èÖ¹`SelGate.exe`ÊÍ·Å
- **System32±£»¤»úÖÆ**£ºÏµÍ³ÎóÅÐSelGate.exeΪ¹Ø¼ü×é¼þ£¬´¥·¢Ç¿ÖƸôÀë

#### **3. ½âѹ¹¤¾ß¼æÈÝÐÔ£¨Õ¼±È22%£©**
- **ÄÚ´æ¹ÜÀíȱÏÝ**£ºBandizipµÈ¹¤¾ßÔÚ´¦Àí³¬¹ý4GBµÄѹËõ°üʱ£¬ÄÚ´æÒç³öµ¼Ö½ø³Ì±ÀÀ£
- **³¤Â·¾¶½Ø¶Ï**£º½âѹĿ±ê·¾¶³¬¹ý260×Ö·ûÏÞÖÆ£¨Èç`D:\Mirserver\2025Äê×îÐÂ...\SelGate.exe`£©
- **UnicodeÖ§³Ö²»×ã**£ºWinRAR 5.0ÒÔϰ汾ÎÞ·¨½âÎöUTF-16±àÂëÎļþÃû

#### **4. °²È«Èí¼þ²ÐÁô·À»¤£¨Õ¼±È8%£©**
- **Çý¶¯¼¶Îļþ¹ýÂË**£º¼´±ã¹Ø±Õɱ¶¾½çÃæ£¬ÄÚºË̬Çý¶¯£¨Èç360sd.sys£©ÈÔ»áÀ¹½Ø¸ßΣÀ©Õ¹ÃûÎļþ
- **ÔÆÉ³ÏäÒ첽ɾ³ý**£º»ðÈÞµÈɱÈí²ÉÓÃÔÆ¶Ë¼ì²â»úÖÆ£¬½âѹºóÑÓ³Ùɾ³ý·çÏÕÎļþ

---

### Èý¡¢ÏµÍ³ÐÔ½â¾ö·½°¸
#### **²½Öè1£ºÑ¹Ëõ°üÍêÕûÐÔÑéÖ¤ÓëÐÞ¸´**
1. **¹þϣֵУÑé**£º
```powershell
# Éú³ÉSHA256УÑéÂë
certutil -hashfile LegendServer.rar SHA256
# ¶Ô±È¹Ù·½·¢²¼Öµ£¨È磺a1b2c3...£©
```

2. **·Ö¾íÁªºÏÐÞ¸´**£º
```bash
7z -v10m LegendServer.7z.001 LegendServer.7z.002
7z x LegendServer.7z -oD:\MirServer -aoa
```

3. **רÓù¤¾ßÌáÈ¡**£º
- ʹÓÃ**Universal Extractor**ÈÆ¹ý³£¹æÒýÇæ£¬¹´Ñ¡`Bypass file signature check`
- ¶ÔË𻵰üÖ´Ðжþ½øÖÆÐÞ¸´£ºHxD±à¼­Æ÷ÊÖ¶¯ÐÞÕýÎļþÍ·`50 4B 03 04`

#### **²½Öè2£º´©Í¸ÏµÍ³È¨ÏÞÏÞÖÆ**
1. **Ç¿ÖÆÌáȨ½âѹ**£º
```powershell
Start-Process -FilePath "C:\Program Files\WinRAR\WinRAR.exe" `
-ArgumentList "x -ibck D:\Downloads\LegendServer.rar D:\MirServer\" `
-Verb RunAs
```

2. **Ŀ¼ȨÏÞÖØÖÃ**£º
```powershell
# Çå³ý¼Ì³Ð¹æÔò
icacls D:\MirServer /reset /T /C /L
# ¸³ÓèÍêÈ«¿ØÖÆÈ¨
icacls D:\MirServer /grant Everyone:(OI)(CI)F /T
```

3. **¹Ø±ÕUACÐéÄ⻯**£º
```reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableVirtualization"=dword:00000000
```


#### **²½Öè3£º½âѹ¹¤¾ßÓÅ»¯²ßÂÔ**
1. **¹¤¾ßÑ¡Ôñ½¨Òé**£º

| ¹¤¾ßÃû³Æ | ÊÊÓó¡¾° | ºËÐIJÎÊý |
|----------------|--------------------------|-----------------------|
| 7-Zip ZS·ÖÖ§ | Òì³£±àÂëÐÞ¸´ | `-mcp=UTF-8` |
| PeaZip | ³¬³¤Â·¾¶Ö§³Ö | ÆôÓÃ`Enable LFN` |
| WinRAR 6.23 | RAR5¸ñʽ¼æÈÝ | ¹Ø±Õ"±£ÁôËð»µÎļþ" |

2. **ÄÚ´æÏÞÖÆµ÷Õû**£º
- ¶ÔBandizipÖ´ÐÐ`ÉèÖÃ→´æµµ→½âѹÄÚ´æÏÞÖÆ≥4096MB`
- ±ÜÃâͬʱÔËÐдóÐͳÌÐò£¨ÈçPhotoshop£©

#### **²½Öè4£º°²È«Èí¼þÉî¶È´¦Àí**
1. **Äں˼¶·À»¤¹Ø±Õ**£º
```powershell
# »ðÈÞÇý¶¯Ð¶ÔØ
sc stop HRFWMGR
sc delete HRFWMGR
# 360ÎÀÊ¿²ÐÁôÇåÀí
taskkill /f /im 360tray.exe
del /q "%ProgramFiles%\360\*.sys"
```

2. **ÔÆ²éɱ»íÃâÅäÖÃ**£º
- ÔÚ×é²ßÂÔÖд´½¨Â·¾¶Åųý¹æÔò£º
```reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths]
"D:\\MirServer"="0"
```


#### **²½Öè5£ºÊÖ¶¯²¹È«¹Ø¼üÎļþ**
1. **¶ÀÁ¢ÌáÈ¡·½°¸**£º
- ´ÓÕý³£°æ±¾ÌáÈ¡`SelGate.exe`£¨MD5УÑ鯥Å䣩
```powershell
Get-FileHash -Algorithm MD5 SelGate.exe
```

2. **¶þ½øÖÆÖؽ¨Á÷³Ì**£º
- ʹÓÃHxD±à¼­Æ÷°´PE½á¹¹ÊÖ¶¯¹¹½¨£º
```
Æ«ÒÆ00000000: 4D 5A 90 00 03 00 00 00 // DOSÍ·
Æ«ÒÆ000000F0: 50 45 00 00 64 86... // PEÍ·
```


---

### ËÄ¡¢Íç¹ÌÐÔ³¡¾°½â¾ö·½°¸
#### **³¡¾°1£ºÂ·¾¶º¬ÖÐÎÄ/ÌØÊâ·ûºÅ**
1. **·¾¶¹æ·¶»¯²Ù×÷**£º
- Ç¨ÒÆÖÁ´¿Ó¢ÎÄ·¾¶£¨Èç`D:\MirServer\3KEngine`£©
- ×ܳ¤¶È≤60×Ö·û£¬±ÜÃâ¿Õ¸ñºÍ`[]`·ûºÅ
2. **¶ÌÎļþÃû¼æÈÝ**£º
```cmd
fsutil file setshortname "D:\MirServer" MIRSERV
```


#### **³¡¾°2£ºÊ±¼ä´ÁУÑé³åÍ»**
1. **ϵͳʱ¼ä»ØËÝ**£º
```cmd
date 2020-01-01
time 09:00:00
```

2. **ÒýÇæÊÚȨÐÞ¸´**£º
- ÔËÐÐ`Clear.exe`Çå³ý¹ýÆÚÖ¤Êé
- ÐÞ¸Ä×¢²á±íÌø¹ýʱ¼äÑéÖ¤£º
```reg
[HKEY_LOCAL_MACHINE\SOFTWARE\3KM2]
"SkipTimeCheck"=dword:00000001
```


#### **³¡¾°3£ºÐéÄâ»úɳºÐ²¿Êð**
1. **VMwareÅäÖòÎÊý**£º
```
´¦ÀíÆ÷: 2ºËÐÄ | ÄÚ´æ: 4096MB
´ÅÅÌģʽ: IDE (½ûÓÃSATA/NVMe)
ÍøÂç: NAT (¶Ë¿Úת·¢7000-7300)
```

2. **¹²ÏíĿ¼ӳÉä**£º
- ½«Ö÷»ú`D:\MirServer`¹²ÏíΪ`\\vmware-host\Shared Folders\MirServer`

---

### Îå¡¢´íÎóÏÖÏóÓë½â¾ö·½°¸ËÙ²é±í
| ÏÖÏóÃèÊö | ¹ØÁª×é¼þ | ½â¾ö·½°¸ | ÒýÓÃÒÀ¾Ý |
|---------------------------|-------------------|---------------------------------------|----------|
| ½âѹ½ø¶È99%¿¨ËÀ | ÄÚ´æÒç³ö | »»ÓÃ7-Zip ZS+·ÖÅä4GBÐéÄâÄÚ´æ | |
| ±¨´í"¾Ü¾ø·ÃÎÊ" | NTFSȨÏÞ | icaclsÖØÖÃĿ¼ACL¹æÔò | |
| ÎļþÍ·ÏÔʾ"CF 84"ÂÒÂë | ѹËõ°üË𻵠| HxDÐÞÕýÊ××Ö½ÚΪ"50 4B" | |
| ½âѹºóÎļþ´óС0KB | ÔÆ²éɱÀ¹½Ø | Ð¶ÔØÉ±ÈíÇý¶¯+×é²ßÂÔ»íÃâ | |

---

### Áù¡¢Ô¤·ÀÐÔά»¤Ìåϵ
1. **»·¾³¿ìÕÕ¼¼Êõ**£º
- ʹÓÃDiskGenius¶Ô´¿¾»·þÎñ¶ËÖÆ×÷ÔöÁ¿¾µÏñ£¨Ã¿Öܱ¸·Ý£©
- ±ÀÀ£»Ö¸´Ê±¼ä≤2·ÖÖÓ

2. **×Ô¶¯»¯Ð£Ñé½Å±¾**£º
```powershell
# ºËÐÄÎļþУÑé
$files = "SelGate.exe", "M2Server.exe", "DBServer.exe"
$files | ForEach-Object {
if (-not (Test-Path "D:\MirServer\$_")) {
Write-Host "[ERROR] $_ missing!" -ForegroundColor Red
}
}
```


3. **ÈÕÖ¾¼à¿ØÌåϵ**£º
- ÔÚÈÎÎñ¼Æ»®Öд´½¨´¥·¢Æ÷£¬ÊµÊ±½âÎö`MirServer\Logs\Extract.log