123
返回列表 发新帖
楼主: 小鸟游真昼
收起左侧

[可疑文件] 1.exe

  [复制链接]
hzz2009
发表于 2014-9-18 21:16:02 | 显示全部楼层
卡巴杀了,开的自动处理,来不及截图
yicun
发表于 2014-9-18 21:58:46 | 显示全部楼层
The file will be detected as Trojan.Downloader.JRCM.
飞翔病毒
发表于 2014-9-18 22:09:56 | 显示全部楼层
minjiaming 发表于 2014-9-18 20:20
开了QVM的卫士也没报毒

没有入库的情况下系统环境不一样查杀检测率也不一样
cn86li
发表于 2014-9-19 10:12:49 | 显示全部楼层
大流氓啊

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
墨家小子
发表于 2014-9-20 12:14:59 | 显示全部楼层
09/20/14 12:12:14 Prevented <pid: 1904> from writing to memory of <Windows 资源管理器>.
09/20/14 12:12:14 Prevented <pid: 5772> from writing to <\registry\machine\software\wow6432node\ucbrowserpid>.
09/20/14 12:12:14 Prevented <pid: 3560> from writing to <\registry\machine\software\wow6432node\microsoft\windows\currentversion\explorer>.
09/20/14 12:12:14 Prevented process <pid: 3560> from writing to <c:\program files (x86)\9377÷èó°′«Ëμ\mylogger.ini>.
09/20/14 12:11:41 Prevented <pid: 5760> from writing to <\registry\machine\software\wow6432node\microsoft\windows\currentversion\explorer>.
09/20/14 12:11:41 Prevented process <pid: 5760> from writing to <c:\program files (x86)\baidu\baiduplayer\4.0.1.65\install.ini>.
09/20/14 12:11:30 Prevented process <setup_001.exe | c:\users\XXXX\desktop\1\1.exe> from launching from <c:\users\XXXX\appdata\local\temp\nsk405c.tmp>.
09/20/14 12:11:12 Prevented process <2345智能浏览器 v3.2 安装程序> from writing to <c:\program files (x86)\2345explorer\2345explorer.exe>.

09/20/14 12:11:08 Prevented process <pid: 5760> from writing to <c:\program files (x86)\baidu\baiduplayer\4.0.1.65\baidumediaservice.exe>.
09/20/14 12:11:08 Prevented process <pid: 5760> from writing to <c:\program files (x86)\baidu\baiduplayer\4.0.1.65\bdyyhots.xml>.
09/20/14 12:11:08 Prevented <pid: 5760> from writing to memory of <Client Server Runtime Process>.
09/20/14 12:11:08 Prevented <pid: 5760> from writing to memory of <pid: 3196>.
09/20/14 12:11:08 Prevented process <pid: 5760> from writing to <c:\program files (x86)\baidu\baiduplayer\4.0.1.65\pages\tvlostplay.jpg>.
09/20/14 12:11:08 Prevented <pid: 5760> from reading memory of <Windows 会话管理器>.
09/20/14 12:11:08 Prevented <pid: 5760> from writing to <\registry\machine\software\wow6432node\baidu\baiduplayer>.
09/20/14 12:11:08 Prevented <pid: 5760> from writing to <\registry\machine\software\wow6432node\microsoft\windows\currentversion\uninstall\baiduplayer>.
09/20/14 12:11:08 Prevented process <pid: 5760> from writing to <c:\program files (x86)\baidu\baiduplayer\4.0.1.65\baidusetupax_0.exe>.
09/20/14 12:10:48 Prevented process <stats_uploader.exe | c:\users\XXXX\appdata\local\temp\nsk405c.tmp\browser_v3.0.1167.3_r_4279_(build14091614).exe> from launching from <c:\users\XXXX\appdata\local\temp\scoped_dir5772_10175>.
09/20/14 12:10:48 Prevented <setup.exe> from writing to <\registry\machine\software\wow6432node\ucbrowser>.
09/20/14 12:10:48 Prevented process <setup.exe> from writing to <c:\program files (x86)\ucbrowser\temp\source5504_12248\chrome.7z>.
09/20/14 12:10:42 Prevented <MYLogger> from writing to memory of <Windows 资源管理器>.
09/20/14 12:10:41 Prevented <9377魅影传说微端> from writing to <\registry\machine\software\wow6432node\microsoft\windows\currentversion\explorer>.
09/20/14 12:10:41 Prevented process <9377魅影传说微端> from writing to <c:\program files (x86)\9377÷èó°′«Ëμ\mylogger.ini>.
09/20/14 12:10:38 Prevented process <stats_uploader.exe | c:\users\XXXX\appdata\local\temp\nsk405c.tmp\browser_v3.0.1167.3_r_4279_(build14091614).exe> from launching from <c:\users\XXXX\appdata\local\temp\scoped_dir5772_10175>.
09/20/14 12:10:38 Prevented <UC浏览器安装程序> from writing to <\registry\machine\software\wow6432node\ucbrowserpid>.
09/20/14 12:10:34 Prevented <pid: 5760> from writing to memory of <Windows 会话管理器>.
09/20/14 12:10:34 Prevented <pid: 5760> from writing to <\registry\machine\software\wow6432node\microsoft\windows\currentversion\internet settings\zonemap>.
09/20/14 12:10:34 Prevented process <pid: 3196> from writing to <c:\windows\syswow64\bdsecushr.dat>.
09/20/14 12:09:39 Prevented <BaiduPlayer Setup> from writing to <\registry\machine\software\wow6432node\microsoft\windows\currentversion\explorer>.
09/20/14 12:09:39 Prevented process <BaiduPlayer Setup> from writing to <c:\program files (x86)\baidu\baiduplayer\4.0.1.65\install.ini>.
09/20/14 12:09:28 Prevented process <taskbar.vbs | C:\Windows\SysWOW64\cscript.exe> from launching from <c:\users\XXXX\appdata\local\temp>.
09/20/14 12:09:28 Prevented process <startmenu.vbs | C:\Windows\SysWOW64\cscript.exe> from launching from <c:\users\XXXX\appdata\local\temp>.
09/20/14 12:09:27 Prevented <BaiduPlayer Setup> from reading memory of <Windows 会话管理器>.
09/20/14 12:09:27 Prevented process <BaiduPlayer Setup> from writing to <c:\program files (x86)\baidu\baiduplayer\4.0.1.65\baidusetupax_0.exe>.
09/20/14 12:09:23 Prevented <BaiduPlayer Setup> from writing to memory of <百度影音网络安装程序>.
09/20/14 12:09:23 Prevented <BaiduPlayer Setup> from writing to <\registry\machine\software\wow6432node\microsoft\windows\currentversion\uninstall\baiduplayer>.
09/20/14 12:09:17 Prevented <BaiduPlayer Setup> from writing to <\registry\machine\software\wow6432node\baidu\baiduplayer>.
09/20/14 12:09:17 Prevented process <BaiduPlayer Setup> from writing to <c:\program files (x86)\baidu\baiduplayer\4.0.1.65\pages\tvlostplay.jpg>.
09/20/14 12:09:13 Prevented process <BaiduPlayer Setup> from writing to <c:\program files (x86)\baidu\baiduplayer\4.0.1.65\bdyyhots.xml>.
09/20/14 12:09:11 Prevented process <BaiduPlayer Setup> from writing to <c:\program files (x86)\baidu\baiduplayer\4.0.1.65\baidumediaservice.exe>.
09/20/14 12:09:11 Prevented <BaiduPlayer Setup> from writing to memory of <Client Server Runtime Process>.
09/20/14 12:08:37 Prevented process <startmenu_uninstall.vbs | C:\Windows\SysWOW64\cscript.exe> from launching from <c:\users\XXXX\appdata\local\temp>.
09/20/14 12:08:37 Prevented <BaiduPlayer Setup> from writing to memory of <Windows 会话管理器>.
09/20/14 12:08:36 Prevented <BaiduPlayer Setup> from writing to <\registry\machine\software\wow6432node\microsoft\windows\currentversion\internet settings\zonemap>.
09/20/14 12:08:34 Prevented process <百度影音网络安装程序> from writing to <c:\windows\syswow64\bdsecushr.dat>.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-20 19:48 , Processed in 0.419402 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表