AVG:
扫描:miss;
双击:实机双击(不入沙),样本成功注入meisxec.exe,后调用cmd.exe时被IDP击杀。
"";"IDP.ARES.Generic, C:\Users\Killer\Desktop\新建文件夹\e2c857f506eea6f01c40239992480c90f92d7d4c69ae594141cfc8a8a4577b15.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/3, 21:56:48"
"";", C:\Users\Killer\Desktop\新建文件夹\e2c857f506eea6f01c40239992480c90f92d7d4c69ae594141cfc8a8a4577b15.exe";"Object was blocked";"Process";"2015/12/3, 21:56:48"
"";", C:\Users\Killer\Desktop\新建文件夹\e2c857f506eea6f01c40239992480c90f92d7d4c69ae594141cfc8a8a4577b15.exe";"Object was blocked";"Process";"2015/12/3, 21:56:48"
"";", C:\Users\Killer\Desktop\新建文件夹\e2c857f506eea6f01c40239992480c90f92d7d4c69ae594141cfc8a8a4577b15.exe";"Object was blocked";"Process";"2015/12/3, 21:56:48"
"";", C:\Windows\System32\msiexec.exe";"Object was blocked";"Process";"2015/12/3, 21:56:48"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/3, 21:56:48"
|