GitHub ↗ ← 返回

What happens if you click a Fake Captcha.ass

Enderman/What happens if you click a Fake Captcha.assASS共 302 条字幕
样式信息 (3)
Newman-CN-4K
名称Newman-CN-4K字体等距更纱黑体 SC字号125主色&H0055FFFF辅色&H000000FF描边色&H00FF43E4背景色&H00FF2FFF粗体0斜体0下划线0删除线0水平缩放100垂直缩放100间距0角度0边框样式1描边1.5阴影1.2对齐2左边距10右边距10垂直边距20编码1
Newman2-CN-4K
名称Newman2-CN-4K字体HarmonyOS Sans SC字号165主色&H00A0FFF5辅色&H00000000描边色&H96000000背景色&H00000000粗体0斜体0下划线0删除线0水平缩放100垂直缩放95间距0角度0边框样式3描边0.1阴影0对齐2左边距10右边距10垂直边距110编码1
Newman2-EN-4K
名称Newman2-EN-4K字体思源黑体 CN字号75主色&H00E0E0E0辅色&H000000FF描边色&H96000000背景色&HD2000000粗体0斜体0下划线0删除线0水平缩放100垂直缩放95间距0.6角度0边框样式3描边0.1阴影0对齐2左边距10右边距10垂直边距40编码1
#10:00:00.390:00:07.46Newman-CN-4K
{\blur10\fad(200,200)}翻译/压制/字幕制作:HAF半个水果
#20:00:09.080:00:19.08Newman-CN-4K
{\blur10\fad(200,200)\pos(1997.334,728)}使用AI工具翻译,如有不准确的地方请在弹幕或评论区指正,谢谢!\N
!!真的有人看不到这行字!!
#30:00:19.510:00:24.51Newman-CN-4K
{\blur10\fad(200,200)\pos(1933.334,564)}翻译质量权威评价:原来25年就有小拉即用机翻糊弄人了
#40:00:24.960:00:30.96Newman-CN-4K
{\blur10\fad(200,200)\pos(1937.334,548)}♥本视频在Enderman频道会员有效期内翻译♥
#50:00:07.640:00:08.29Newman2-CN-4K
大家好
#60:00:07.640:00:08.29Newman2-EN-4K
Hello
#70:00:08.290:00:10.91Newman2-CN-4K
在本视频中 我想展示另一个虚假验证码
#80:00:08.290:00:10.91Newman2-EN-4K
In this video
#90:00:11.150:00:12.63Newman2-CN-4K
但这次有所不同
#100:00:11.150:00:12.63Newman2-EN-4K
but this time with a twist.
#110:00:13.250:00:14.83Newman2-CN-4K
链接就在这里
#120:00:13.250:00:14.83Newman2-EN-4K
I've got the link here.
#130:00:16.050:00:17.99Newman2-CN-4K
这个域名显然不可信
#140:00:16.050:00:17.99Newman2-EN-4K
The domain is definitely not plausible
#150:00:18.690:00:21.55Newman2-CN-4K
不过你们大概能猜到后续剧情
#160:00:18.690:00:21.55Newman2-EN-4K
but you can probably tell where it is going already.
#170:00:23.270:00:26.39Newman2-CN-4K
让我们验证下猜想
#180:00:23.270:00:26.39Newman2-EN-4K
And let's confirm the suspicions.
#190:00:30.490:00:31.14Newman2-CN-4K
因为首先
#200:00:30.490:00:31.14Newman2-EN-4K
Because first of all
#210:00:31.170:00:33.75Newman2-CN-4K
我们遇到的是Cloudflare的真实验证码
#220:00:31.170:00:33.75Newman2-EN-4K
we get a real CAPTCHA by Cloudflare.
#230:00:34.670:00:37.45Newman2-CN-4K
你可能会以为这就是
#240:00:34.670:00:37.45Newman2-EN-4K
And you would think it's that beautiful
#250:00:37.790:00:40.57Newman2-CN-4K
我一直在寻找的那个完美模仿Cloudflare
#260:00:37.790:00:40.57Newman2-EN-4K
fake Cloudflare CAPTCHA that I was looking for.
#270:00:41.070:00:46.31Newman2-CN-4K
但实际上你会被重定向到虚假YouTube页面
#280:00:41.070:00:46.31Newman2-EN-4K
However
#290:00:47.470:00:50.03Newman2-CN-4K
注意看 在继续访问YouTube前
#300:00:47.470:00:50.03Newman2-EN-4K
And let's see
#310:00:50.990:00:54.89Newman2-CN-4K
需要点击这个看似可信的reCAPTCHA验证
#320:00:50.990:00:54.89Newman2-EN-4K
click on this pretty plausible-looking reCAPTCHA.
#330:00:57.370:00:58.81Newman2-CN-4K
看这里
#340:00:57.370:00:58.81Newman2-EN-4K
So
#350:00:58.850:01:00.19Newman2-CN-4K
“确认您不是机器人”
#360:00:58.850:01:00.19Newman2-EN-4K
Confirm you're not a bot.
#370:01:01.150:01:03.35Newman2-CN-4K
你甚至可以滚动页面
#380:01:01.150:01:03.35Newman2-EN-4K
You can actually scroll and everything.
#390:01:03.490:01:07.69Newman2-CN-4K
在外行人眼里几乎以假乱真
#400:01:03.490:01:07.69Newman2-EN-4K
It looks pretty fine to an untrained eye.
#410:01:09.610:01:11.85Newman2-CN-4K
让我们点击这个复选框试试
#420:01:09.610:01:11.85Newman2-EN-4K
So let's try clicking on that checkbox.
#430:01:14.270:01:16.31Newman2-CN-4K
“完成以下验证步骤”
#440:01:14.270:01:16.31Newman2-EN-4K
Complete these verification steps.
#450:01:16.650:01:18.09Newman2-CN-4K
“为确认您非机器人”
#460:01:16.650:01:18.09Newman2-EN-4K
To confirm you're not a robot
#470:01:18.430:01:19.59Newman2-CN-4K
“请按步骤操作”
#480:01:18.430:01:19.59Newman2-EN-4K
please follow these steps.
#490:01:20.070:01:23.49Newman2-CN-4K
“在验证窗口中按住Windows键加R键”
#500:01:20.070:01:23.49Newman2-EN-4K
Press and hold the Windows key plus R In the verification window
#510:01:23.650:01:26.03Newman2-CN-4K
“按Control加V粘贴复制的数据”
#520:01:23.650:01:26.03Newman2-EN-4K
press Control plus V to paste the copied data.
#530:01:26.550:01:27.99Newman2-CN-4K
“按Enter键完成验证”
#540:01:26.550:01:27.99Newman2-EN-4K
Press Enter to complete the verification.
#550:01:28.930:01:31.99Newman2-CN-4K
没错 这就是经典的虚假验证码
#560:01:28.930:01:31.99Newman2-EN-4K
Well
#570:01:34.110:01:36.29Newman2-CN-4K
这类验证码相当罕见
#580:01:34.110:01:36.29Newman2-EN-4K
These CAPTCHAs are pretty rare
#590:01:36.530:01:39.71Newman2-CN-4K
因为我见过的那些做工都很粗糙
#600:01:36.530:01:39.71Newman2-EN-4K
because the ones I have visited weren't super well made.
#610:01:40.410:01:42.95Newman2-CN-4K
来看看它要我们执行什么操作
#620:01:40.410:01:42.95Newman2-EN-4K
So let's see what it's asking us to execute.
#630:01:44.570:01:47.53Newman2-CN-4K
首先 我们获取到的是PowerShell命令
#640:01:44.570:01:47.53Newman2-EN-4K
First of all
#650:01:47.650:01:48.59Newman2-CN-4K
也就是PowerShell脚本
#660:01:47.650:01:48.59Newman2-EN-4K
the PowerShell script.
#670:01:48.590:01:51.33Newman2-CN-4K
这和我上期视频预期的一致
#680:01:48.590:01:51.33Newman2-EN-4K
And that's what I expected in the last video
#690:01:51.490:01:54.07Newman2-CN-4K
当时实际运行的是MSHTA程序
#700:01:51.490:01:54.07Newman2-EN-4K
when it actually ran MSHTA.
#710:01:54.570:01:56.95Newman2-CN-4K
这条指令的作用是...
#720:01:54.570:01:56.95Newman2-EN-4K
So the command is...
#730:01:56.950:01:58.83Newman2-CN-4K
执行一个HTA文件
#740:01:56.950:01:58.83Newman2-EN-4K
It runs an HTA file.
#750:02:01.450:02:04.61Newman2-CN-4K
它向这个bookvrff.com网站发起网络请求
#760:02:01.450:02:04.61Newman2-EN-4K
It invokes the web request to this website here
#770:02:04.870:02:10.23Newman2-CN-4K
将内容保存为文件后通过MSHTA运行
#780:02:04.870:02:10.23Newman2-EN-4K
bookvrff.com
#790:02:11.550:02:15.21Newman2-CN-4K
之所以用MSHTA执行命令
#800:02:11.550:02:15.21Newman2-EN-4K
and then runs it via MSHTA.
#810:02:15.440:02:22.53Newman2-CN-4K
是因为MSHTA存在大量漏洞
#820:02:15.440:02:22.53Newman2-EN-4K
{\fs95}And the idea why it runs the command via MSHTA is because MSHTA is very vulnerable.
#830:02:19.580:02:27.58Newman-CN-4K注释
{\blur10\pos(2044,1212)\fad(200,200)}MSHTA同样是一种已知的lolbin\N
(活体二进制文件,英文全称:Living-Off-the-Land Binaries\N
直译为:生活在陆地上的二进制,白名单文件利用技术),\N
常被恶意软件用作间接层以模仿可信行为
#840:02:23.390:02:25.57Newman2-CN-4K
可利用多种漏洞
#850:02:23.390:02:25.57Newman2-EN-4K
And there are a lot of holes
#860:02:25.890:02:31.65Newman2-CN-4K
突破HTA沙箱限制
#870:02:25.890:02:31.65Newman2-EN-4K
a lot of exploits you can employ to break out of the HTA box.
#880:02:32.790:02:36.17Newman2-CN-4K
现在来看看这个网站有什么猫腻
#890:02:32.790:02:36.17Newman2-EN-4K
So let's see what that website has to offer.
#900:02:37.110:02:40.37Newman2-CN-4K
复制bookvrff.com网址
#910:02:37.110:02:40.37Newman2-EN-4K
Let's copy the bookvrff.com
#920:02:41.030:02:43.27Newman2-CN-4K
查看网站内容
#930:02:41.030:02:43.27Newman2-EN-4K
see what it has on the website.
#940:02:44.490:02:50.73Newman2-CN-4K
显示该站点已被微软Defender SmartScreen标记为不安全
#950:02:44.490:02:47.33Newman2-EN-4K
Oh
#960:02:47.330:02:50.73Newman2-EN-4K
as unsafe by Microsoft Defender SmartScreen.
#970:02:51.370:02:54.79Newman2-CN-4K
没错 早就被举报滥用
#980:02:51.370:02:54.79Newman2-EN-4K
Yeah
#990:02:55.510:02:58.17Newman2-CN-4K
无视风险,继续访问
#1000:02:55.510:02:58.17Newman2-EN-4K
So let's continue to the unsafe site
#1010:02:58.330:02:59.99Newman2-CN-4K
却显示服务不可用
#1020:02:58.330:02:59.99Newman2-EN-4K
and we get service unavailable.
#1030:03:00.730:03:01.33Newman2-CN-4K
有意思
#1040:03:00.730:03:01.33Newman2-EN-4K
Interesting.
#1050:03:02.010:03:04.45Newman2-CN-4K
但实际执行这条命令会发生什么?
#1060:03:02.010:03:04.45Newman2-EN-4K
But what happens when we actually run this command?
#1070:03:04.930:03:06.01Newman2-CN-4K
我们来试试
#1080:03:04.930:03:06.01Newman2-EN-4K
Let's try that out.
#1090:03:07.970:03:11.67Newman2-CN-4K
为此需要打开命令提示符
#1100:03:07.970:03:11.67Newman2-EN-4K
I'm gonna run the command prompt for that.
#1110:03:12.090:03:12.73Newman2-CN-4K
准备就绪
#1120:03:12.090:03:12.73Newman2-EN-4K
Let's do that.
#1130:03:13.410:03:15.33Newman2-CN-4K
我将以管理员身份运行
#1140:03:13.410:03:15.33Newman2-EN-4K
I'm gonna run this as an admin.
#1150:03:16.110:03:17.19Newman2-CN-4K
然后...
#1160:03:16.110:03:17.19Newman2-EN-4K
And then...
#1170:03:18.610:03:20.59Newman2-CN-4K
啊 剪贴板历史没开启
#1180:03:18.610:03:20.59Newman2-EN-4K
Oh
#1190:03:20.870:03:21.25Newman2-CN-4K
太好了
#1200:03:20.870:03:21.25Newman2-EN-4K
Hell yeah.
#1210:03:23.010:03:25.63Newman2-CN-4K
马上粘贴看看效果
#1220:03:23.010:03:25.63Newman2-EN-4K
Let's paste that real quick and see what happens.
#1230:03:32.930:03:33.97Newman2-CN-4K
应用程序工具
#1240:03:32.930:03:33.97Newman2-EN-4K
Application tool.
#1250:03:35.970:03:38.77Newman2-CN-4K
然后它会执行另外几个PowerShell脚本
#1260:03:35.970:03:38.77Newman2-EN-4K
Then it executes a couple other PowerShell scripts
#1270:03:38.990:03:40.41Newman2-CN-4K
看起来是这样
#1280:03:38.990:03:40.41Newman2-EN-4K
it seems like.
#1290:03:41.830:03:43.13Newman2-CN-4K
我来检查任务管理器
#1300:03:41.830:03:43.13Newman2-EN-4K
Let's check the task manager.
#1310:03:43.590:03:44.39Newman2-CN-4K
正在写入网络请求
#1320:03:43.590:03:44.39Newman2-EN-4K
Writing web requests.
#1330:03:44.390:03:45.69Newman2-CN-4K
它一直在下载东西
#1340:03:44.390:03:45.69Newman2-EN-4K
It keeps downloading stuff.
#1350:03:47.030:03:49.23Newman2-CN-4K
这里可能经过了几层间接跳转
#1360:03:47.030:03:49.23Newman2-EN-4K
There might be a couple indirections here.
#1370:03:50.150:03:56.29Newman2-CN-4K
所以当你看到PowerShell脚本在某个应用程序工具窗口弹出时
#1380:03:50.150:03:56.29Newman2-EN-4K
So once you see PowerShell scripts popping up in some application tool window
#1390:03:56.890:03:58.39Newman2-CN-4K
这是个危险信号
#1400:03:56.890:03:58.39Newman2-EN-4K
it is a bad sign.
#1410:04:00.090:04:01.33Newman2-CN-4K
最搞笑的是
#1420:04:00.090:04:01.33Newman2-EN-4K
And the funniest part
#1430:04:01.450:04:04.31Newman2-CN-4K
我觉得 它实际上受到Cloudflare的保护
#1440:04:01.450:04:04.31Newman2-EN-4K
I think
#1450:04:04.350:04:06.85Newman2-CN-4K
而且开头还设置了真正的验证码
#1460:04:04.350:04:06.85Newman2-EN-4K
and they have the real CAPTCHA at the beginning.
#1470:04:07.750:04:09.37Newman2-CN-4K
等等 现在好像失效了
#1480:04:07.750:04:09.37Newman2-EN-4K
Oh
#1490:04:09.450:04:09.89Newman2-CN-4K
对吧?
#1500:04:09.450:04:09.89Newman2-EN-4K
does it?
#1510:04:12.930:04:14.77Newman2-CN-4K
是的 突然就不工作了
#1520:04:12.930:04:14.77Newman2-EN-4K
Yeah
#1530:04:14.770:04:17.41Newman2-CN-4K
这是...什么原因?
#1540:04:14.770:04:17.41Newman2-EN-4K
Is that... why is that?
#1550:04:17.550:04:17.99Newman2-CN-4K
有意思
#1560:04:17.550:04:17.99Newman2-EN-4K
Interesting.
#1570:04:18.990:04:22.71Newman2-CN-4K
好 我们来看看AppData里的HTA文件
#1580:04:18.990:04:22.71Newman2-EN-4K
Okay
#1590:04:23.030:04:27.15Newman2-CN-4K
就是从bookvrff.com下载的那个
#1600:04:23.030:04:27.15Newman2-EN-4K
the file it has downloaded from bookvrff.com.
#1610:04:28.090:04:29.67Newman2-CN-4K
需要打开AppData目录
#1620:04:28.090:04:29.67Newman2-EN-4K
So we have to open AppData.
#1630:04:29.850:04:32.37Newman2-CN-4K
它把自己存进了 r 文件夹
#1640:04:29.850:04:32.37Newman2-EN-4K
It saved itself into the R folder.
#1650:04:33.550:04:36.91Newman2-CN-4K
{\move(1920,2018,1916,1606,1550,1850)}这里有个名为z.hta的文件
#1660:04:33.550:04:36.91Newman2-EN-4K
{\move(1920,2110,1916,1702,1550,1850)}And there is a file called z.hta.
#1670:04:35.410:04:38.41Newman-CN-4K注释
{\blur10\pos(2180,1824)}* 在 X 上关注!
#1680:04:38.070:04:41.19Newman2-CN-4K
{\move(1952,1594,1948,2002,430,730)}用记事本打开看看内容
#1690:04:38.070:04:41.19Newman2-EN-4K
{\move(1952,1690,1952,2098,430,730)}Let's open it with Notepad and see what this is.
#1700:04:41.190:04:44.23Newman2-CN-4K
本质上这是个内嵌的VBScript
#1710:04:41.190:04:44.23Newman2-EN-4K
So basically
#1720:04:45.130:04:48.45Newman2-CN-4K
其实就是个在本地运行的VBS文件
#1730:04:45.130:04:48.45Newman2-EN-4K
And it's basically a VBS file running on your computer.
#1740:04:49.630:04:51.69Newman2-CN-4K
它的功能是...
#1750:04:49.630:04:51.69Newman2-EN-4K
So what it does...
#1760:04:51.690:04:53.25Newman2-CN-4K
看这个远程链接
#1770:04:51.690:04:53.25Newman2-EN-4K
Okay
#1780:04:53.850:04:56.31Newman2-CN-4K
你们应该已经猜到后续发展了
#1790:04:53.850:04:56.31Newman2-EN-4K
you can already see where this is going.
#1800:04:56.550:04:58.57Newman2-CN-4K
它在下载exe可执行文件
#1810:04:56.550:04:58.57Newman2-EN-4K
It's downloading an exe file.
#1820:05:00.830:05:01.43Newman2-CN-4K
没错
#1830:05:00.830:05:01.43Newman2-EN-4K
Yes.
#1840:05:02.990:05:05.37Newman2-CN-4K
系统已将其拦截为不安全文件
#1850:05:02.990:05:05.37Newman2-EN-4K
It was blocked as unsafe
#1860:05:05.490:05:06.21Newman2-CN-4K
但先保留它
#1870:05:05.490:05:06.21Newman2-EN-4K
but let's keep it.
#1880:05:06.490:05:08.05Newman2-CN-4K
来看看这个文件是什么
#1890:05:06.490:05:08.05Newman2-EN-4K
Let's see what this file is.
#1900:05:08.790:05:10.15Newman2-CN-4K
能让我保留它吗?
#1910:05:08.790:05:10.15Newman2-EN-4K
Can I please keep it?
#1920:05:12.530:05:13.57Newman2-CN-4K
检测到病毒
#1930:05:12.530:05:13.57Newman2-EN-4K
Virus detected.
#1940:05:14.390:05:14.71Newman2-CN-4K
好的
#1950:05:14.390:05:14.71Newman2-EN-4K
Cool.
#1960:05:17.230:05:17.79Newman2-CN-4K
X蠕虫病毒
#1970:05:17.230:05:17.79Newman2-EN-4K
XWorm.
#1980:05:18.910:05:19.89Newman2-CN-4K
我想看看这个文件
#1990:05:18.910:05:19.89Newman2-EN-4K
I want to see this file.
#2000:05:20.030:05:20.55Newman2-CN-4K
拜托 老兄
#2010:05:20.030:05:20.55Newman2-EN-4K
Come on
#2020:05:25.050:05:26.47Newman2-CN-4K
这是个随机生成的名字
#2030:05:25.050:05:26.47Newman2-EN-4K
That's a randomly generated name
#2040:05:26.590:05:27.75Newman2-CN-4K
要是有的话
#2050:05:26.590:05:27.75Newman2-EN-4K
if I've ever seen one.
#2060:05:28.830:05:29.89Newman2-CN-4K
查看属性
#2070:05:28.830:05:29.89Newman2-EN-4K
Check out the properties.
#2080:05:33.110:05:35.57Newman2-CN-4K
Stub.exe 才是原始文件名
#2090:05:33.110:05:35.57Newman2-EN-4K
Stub.exe is the original file name.
#2100:05:38.250:05:39.49Newman2-CN-4K
我们来看看它还有什么功能
#2110:05:38.250:05:39.49Newman2-EN-4K
Let's see what else it does.
#2120:05:45.870:05:47.73Newman2-CN-4K
它把自己放进了启动文件夹
#2130:05:45.870:05:47.73Newman2-EN-4K
It puts itself into the startup folder.
#2140:05:52.170:05:53.59Newman2-CN-4K
等等 我在干什么?
#2150:05:52.170:05:53.59Newman2-EN-4K
Wait
#2160:05:53.710:05:55.53Newman2-CN-4K
我记得有个Shell命令可以做到
#2170:05:53.710:05:55.53Newman2-EN-4K
I think there is a shell command for that.
#2180:05:55.610:05:56.19Newman2-CN-4K
试试这个
#2190:05:55.610:05:56.19Newman2-EN-4K
Let's try this.
#2200:05:58.890:05:59.27Newman2-CN-4K
完美
#2210:05:58.890:05:59.27Newman2-EN-4K
Excellent.
#2220:06:00.050:06:02.33Newman2-CN-4K
这就是我们找到的东西
#2230:06:00.050:06:02.33Newman2-EN-4K
So here's what we've got here.
#2240:06:03.390:06:05.37Newman2-CN-4K
这就是它创建快捷方式的位置
#2250:06:03.390:06:05.37Newman2-EN-4K
That's where it dropped the link.
#2260:06:05.610:06:06.83Newman2-CN-4K
看看这个快捷方式的作用
#2270:06:05.610:06:06.83Newman2-EN-4K
Let's see what this link does.
#2280:06:10.690:06:11.33Newman2-CN-4K
属性
#2290:06:10.690:06:11.33Newman2-EN-4K
Properties.
#2300:06:12.310:06:12.87Newman2-CN-4K
等一下
#2310:06:12.310:06:12.87Newman2-EN-4K
Hold up.
#2320:06:14.570:06:15.15Newman2-CN-4K
属性
#2330:06:14.570:06:15.15Newman2-EN-4K
Properties.
#2340:06:22.030:06:27.23Newman2-CN-4K
电脑上还有另一个exe文件
#2350:06:22.030:06:27.23Newman2-EN-4K
There's another exe file we have on our computer.
#2360:06:27.950:06:30.33Newman2-CN-4K
而这仅仅是通过运行MSHTA产生的
#2370:06:27.950:06:30.33Newman2-EN-4K
And that's just from running MSHTA
#2380:06:30.330:06:32.35Newman2-CN-4K
这真是太可怕了
#2390:06:30.330:06:32.35Newman2-EN-4K
That's really horrible.
#2400:06:34.630:06:38.33Newman2-CN-4K
那就来看看Roaming\DataBox吧
#2410:06:34.630:06:38.33Newman2-EN-4K
So let's check out Roaming\DataBox.
#2420:06:38.530:06:40.61Newman2-CN-4K
好的 没错 这个launs.exe
#2430:06:38.530:06:40.61Newman2-EN-4K
Okay
#2440:06:40.650:06:41.37Newman2-CN-4K
它就出现在这里
#2450:06:40.650:06:41.37Newman2-EN-4K
you have it here.
#2460:06:42.990:06:44.67Newman2-CN-4K
基本上是同个东西
#2470:06:42.990:06:44.67Newman2-EN-4K
Oh
#2480:06:45.350:06:48.25Newman2-CN-4K
它只是把自己下载为launs
#2490:06:45.350:06:48.25Newman2-EN-4K
It just downloaded itself as launs.
#2500:06:53.200:06:55.32Newman2-CN-4K
他们在关闭Windows Defender
#2510:06:53.200:06:55.32Newman2-EN-4K
They're turning off Windows Defender
#2520:06:56.140:06:57.72Newman2-CN-4K
添加排除路径
#2530:06:56.140:06:57.72Newman2-EN-4K
adding exclusion paths
#2540:06:58.240:07:01.90Newman2-CN-4K
用尽手段阻止反恶意软件运行
#2550:06:58.240:07:01.90Newman2-EN-4K
and doing everything to stop the anti-malware from working.
#2560:07:03.160:07:04.26Newman2-CN-4K
而且我觉得它成功了
#2570:07:03.160:07:04.26Newman2-EN-4K
And I think it worked
#2580:07:04.340:07:06.60Newman2-CN-4K
因为我没看到任何东西破坏这个Defender
#2590:07:04.340:07:06.60Newman2-EN-4K
because I haven't seen anything ruin this Defender.
#2600:07:09.000:07:10.04Newman2-CN-4K
初始化完成
#2610:07:09.000:07:10.04Newman2-EN-4K
Initialization complete.
#2620:07:10.180:07:10.38Newman2-CN-4K
很好
#2630:07:10.180:07:10.38Newman2-EN-4K
Cool.
#2640:07:10.920:07:11.84Newman2-CN-4K
再运行一次
#2650:07:10.920:07:11.84Newman2-EN-4K
Let's run it again.
#2660:07:12.240:07:13.00Newman2-CN-4K
等等 DeleteApp
#2670:07:12.240:07:13.00Newman2-EN-4K
Oh
#2680:07:13.020:07:13.48Newman2-CN-4K
那是什么
#2690:07:13.020:07:13.48Newman2-EN-4K
what's that?
#2700:07:17.390:07:21.27Newman2-CN-4K
临时文件夹tybd7.exe
#2710:07:17.390:07:21.27Newman2-EN-4K
Temporary folder tybd7.exe.
#2720:07:26.120:07:27.46Newman2-CN-4K
现在已经不存在了
#2730:07:26.120:07:27.46Newman2-EN-4K
It doesn't exist anymore.
#2740:07:27.460:07:30.00Newman2-CN-4K
被那个脚本删除了
#2750:07:27.460:07:30.00Newman2-EN-4K
It was deleted by that script.
#2760:07:31.080:07:35.50Newman2-CN-4K
我有个每次开机都会运行的exe文件
#2770:07:31.080:07:35.50Newman2-EN-4K
I have an exe file that runs on every computer startup
#2780:07:36.060:07:38.20Newman2-CN-4K
肯定没安好心
#2790:07:36.060:07:38.20Newman2-EN-4K
and it surely does nothing good.
#2800:07:39.300:07:44.66Newman2-CN-4K
这就是运行一个来自假YouTube页面的不明命令的下场
#2810:07:39.300:07:42.21Newman2-EN-4K
So this is what happens when you run an executable served
#2820:07:42.210:07:44.66Newman2-EN-4K
to you by a fake YouTube capture.
#2830:07:45.420:07:47.50Newman2-CN-4K
别成为这种骗局的受害者
#2840:07:45.420:07:47.50Newman2-EN-4K
Don't fall victim to such a scam
#2850:07:47.720:07:49.02Newman2-CN-4K
感谢观看
#2860:07:47.720:07:49.02Newman2-EN-4K
and thank you for watching.
#2870:07:49.460:07:50.08Newman2-CN-4K
保重
#2880:07:49.460:07:50.08Newman2-EN-4K
Take care.
#2890:07:54.000:07:55.70Newman2-CN-4K
它正在后台运行
#2900:07:54.000:07:55.70Newman2-EN-4K
It's running in the background
#2910:07:59.520:08:01.56Newman2-CN-4K
Launs.exe看 正在运行
#2920:07:59.520:08:01.56Newman2-EN-4K
Launs.exe
#2930:08:01.880:08:04.40Newman2-CN-4K
得先结束进程才能删除
#2940:08:01.880:08:04.40Newman2-EN-4K
I have to end it first before deleting it.
#2950:08:05.960:08:08.30Newman2-CN-4K
好的 感谢观看
#2960:08:05.960:08:08.30Newman2-EN-4K
Yep
#2970:08:08.420:08:08.88Newman2-CN-4K
保重
#2980:08:08.420:08:08.88Newman2-EN-4K
and take care.
#2990:08:09.990:08:29.53Newman-CN-4K
{\blur90\fad(200,200)\fscx185\fscy188\pos(1885.333,840)}在 Youtube 上关注
#3000:08:00.510:08:05.51Newman-CN-4K
{\blur10\fad(200,200)\pos(1953.333,496)}原标题:What happens if you click a Fake Captcha 原作者:Enderman\N
原视频上传日期:2025年8月6日
#3010:08:10.430:08:16.43Newman-CN-4K
{\blur10\fad(200,200)\pos(1909.333,1220)}翻译/压制/字幕制作:HAF半个水果\N
翻译质量权威评价:原来25年就有小拉即用机翻糊弄人了
#3020:08:16.710:08:21.71Newman-CN-4K
{\blur10\fad(200,200)\pos(1889.334,1336)}♥本视频在Enderman频道会员有效期内翻译♥\N
如果你喜欢这个视频,请多多支持和评论哒~ o((>ω< ))o\N
字幕制作不易,喜欢的话支持一下我吧!