本帖最后由 aboringman 于 2015-12-5 21:24 编辑
AVG:
扫描:miss;
双击:带监控双击,在衍生物kb.exe出现后,监控报毒,居然还回滚了(本体及其恶意行为);关闭监控后双击,IDP则秒杀(可能已被缓存)。【以上均为无沙环境】
带监控双击:
"";"Trojan horse MSIL9.TJJ, c:\ProgramData\kb.exe";"Healed, Moved to Virus Vault";"File or Directory";"2015/12/5, 20:48:18"
"";", C:\Users\Killer\AppData\Roaming\Microsoft\Blend\14.0\FeedCache\ScriptedSandbox.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Users\Killer\AppData\Roaming\Microsoft\Blend\14.0\FeedCache\ScriptedSandbox.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Users\Killer\AppData\Roaming\Microsoft\Blend\14.0\FeedCache\ScriptedSandbox.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Users\Killer\AppData\Roaming\Microsoft\Blend\14.0\FeedCache\xpsrchw.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Users\Killer\Desktop\shipping-documents pdf.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Users\Killer\AppData\Roaming\Microsoft\Blend\14.0\FeedCache\xpsrchw.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Users\Killer\Desktop\shipping-documents pdf.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Users\Killer\Desktop\shipping-documents pdf.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Users\Killer\Desktop\shipping-documents pdf.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2015/12/5, 20:48:18"
"";", C:\Users\Killer\Desktop\shipping-documents pdf.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/5, 20:48:18"
"";", C:\Users\Killer\AppData\Roaming\Microsoft\Blend\14.0\FeedCache\xpsrchw.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/5, 20:48:18"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1001\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS\\LOAD";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/5, 20:48:18"
"";", C:\Users\Killer\AppData\Roaming\Microsoft\Blend\14.0\FeedCache\ScriptedSandbox.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/5, 20:48:18"
不带监控双击:
"";"Unknown, C:\Users\Killer\Desktop\新建文件夹\shipping-documents pdf.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/5, 21:10:36"
"";", C:\Users\Killer\Desktop\新建文件夹\shipping-documents pdf.exe";"Object was blocked";"Process";"2015/12/5, 21:10:36"
|