AVG:
双击:实机双击,脚本和程序全部阵亡,IDP大获全胜。【我向来不玩dll】
"";"IDP.Trojan.A795607F, C:\Users\abori\Desktop\2016-09-26-EITest-Rig-EK-payload.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/9/27, 21:20:45"
"";", C:\Users\abori\Desktop\2016-09-26-EITest-Rig-EK-payload.exe";"Object was blocked";"Process";"2016/9/27, 21:20:45"
"";"General behavioral detection, C:\Users\abori\Desktop\2016-09-26-1840-UTC-extracted-file-Updated invoice pdf D32161A.wsf";"Deleted, Moved to Virus Vault";"File or Directory";"2016/9/27, 21:20:06"
"";", C:\Windows\System32\wscript.exe";"Object was blocked";"Process";"2016/9/27, 21:20:06"
"";"IDP.Trojan.1E35695E, C:\Users\abori\AppData\Local\Temp\gkrS6IPeMxdlcQhT.dll";"Deleted, Moved to Virus Vault";"File or Directory";"2016/9/27, 21:19:13"
"";", C:\Windows\System32\rundll32.exe";"Object was blocked";"Process";"2016/9/27, 21:19:13"
"";", C:\Windows\System32\wscript.exe";"Object was blocked";"Process";"2016/9/27, 21:19:13"
"";", C:\Users\abori\Desktop\Updated invoice pdf D32161A.wsf";"Deleted, Moved to Virus Vault";"File or Directory";"2016/9/27, 21:19:13"
"";"General behavioral detection, C:\Users\abori\Desktop\DGWV9M4027.wsf";"Deleted, Moved to Virus Vault";"File or Directory";"2016/9/27, 21:18:37"
"";", C:\Windows\System32\wscript.exe";"Object was blocked";"Process";"2016/9/27, 21:18:37"
"";", C:\Windows\System32\wscript.exe";"Object was blocked";"Process";"2016/9/27, 21:18:37"
"";", E:\QQPinyin\5.4.3311.400\QQPYService.exe";"Object was blocked";"Process";"2016/9/27, 21:18:37"
"";"IDP.Trojan.1CDD7C7A, C:\Users\abori\AppData\Local\Temp\xXINzimwQ2.dll";"Deleted, Moved to Virus Vault";"File or Directory";"2016/9/27, 21:17:57"
"";", C:\Windows\System32\rundll32.exe";"Object was blocked";"Process";"2016/9/27, 21:17:57"
"";", C:\Windows\System32\wscript.exe";"Object was blocked";"Process";"2016/9/27, 21:17:57"
"";", C:\Windows\System32\wscript.exe";"Object was blocked";"Process";"2016/9/27, 21:17:57"
"";", C:\Windows\System32\wscript.exe";"Object was blocked";"Process";"2016/9/27, 21:17:57"
"";", E:\QQPinyin\5.4.3311.400\QQPYService.exe";"Object was blocked";"Process";"2016/9/27, 21:17:57"
"";", C:\Users\abori\Desktop\2016-09-26-1804-UTC-extracted-file-DGWV9M4027.wsf";"Deleted, Moved to Virus Vault";"File or Directory";"2016/9/27, 21:17:57"
|