本帖最后由 sunnyjianna 于 2015-8-31 22:03 编辑
过咖啡
沙盘运行,SSF高等安全级别+自动拦截可疑行为
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\install1078565.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\install1078565.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\install1078565.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\install1078565.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\install1078565.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\install1078565.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\install1078565.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\install1078565.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\install1078565.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\install1078565.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\KeLe2014Beta3.6.2Promote0714_20090195130.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\KeLe2014Beta3.6.2Promote0714_20090195130.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\KeLe2014Beta3.6.2Promote0714_20090195130.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\KeLe2014Beta3.6.2Promote0714_20090195130.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\KeLe2014Beta3.6.2Promote0714_20090195130.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\KeLe2014Beta3.6.2Promote0714_20090195130.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\KeLe2014Beta3.6.2Promote0714_20090195130.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\KeLe2014Beta3.6.2Promote0714_20090195130.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\KeLe2014Beta3.6.2Promote0714_20090195130.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\KeLe2014Beta3.6.2Promote0714_20090195130.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 ("C:\Program Files\Internet Explorer\iexplore.exe" http://120.55.106.231/dnVoaWxkamdsYmZhZC5leGU=/40.html)
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\kpjdi_1202000183.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\kpjdi_1202000183.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\kpjdi_1202000183.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\kpjdi_1202000183.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\kpjdi_1202000183.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\kpjdi_1202000183.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\kpjdi_1202000183.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\kpjdi_1202000183.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\kpjdi_1202000183.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\kpjdi_1202000183.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\meoid_1202000157.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\meoid_1202000157.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\meoid_1202000157.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\meoid_1202000157.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\meoid_1202000157.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\meoid_1202000157.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\meoid_1202000157.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\meoid_1202000157.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\meoid_1202000157.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\meoid_1202000157.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\BFVCenter-y4bd[[AB031]].exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\BFVCenter-y4bd[[AB031]].exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\BFVCenter-y4bd[[AB031]].exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\BFVCenter-y4bd[[AB031]].exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\BFVCenter-y4bd[[AB031]].exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\BFVCenter-y4bd[[AB031]].exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\BFVCenter-y4bd[[AB031]].exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\BFVCenter-y4bd[[AB031]].exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\BFVCenter-y4bd[[AB031]].exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\BFVCenter-y4bd[[AB031]].exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\tribute.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\tribute.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\tribute.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\tribute.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\tribute.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\tribute.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\tribute.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\tribute.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\tribute.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\tribute.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\SoHuVA_4.2.0.16-c204900003-ng-nti-tp-s-x.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\SoHuVA_4.2.0.16-c204900003-ng-nti-tp-s-x.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\SoHuVA_4.2.0.16-c204900003-ng-nti-tp-s-x.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\SoHuVA_4.2.0.16-c204900003-ng-nti-tp-s-x.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\SoHuVA_4.2.0.16-c204900003-ng-nti-tp-s-x.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\SoHuVA_4.2.0.16-c204900003-ng-nti-tp-s-x.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\SoHuVA_4.2.0.16-c204900003-ng-nti-tp-s-x.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\SoHuVA_4.2.0.16-c204900003-ng-nti-tp-s-x.exe")
2015/8/31 19:05:13,C:\Users\Penny\Downloads\vuhildjglbfad\vuhildjglbfad.exe,53,Blocked ;执行应用程序 (C:\windows\system32\cmd.exe /C copy /b "C:\Users\Penny\AppData\Local\Temp\SoHuVA_4.2.0.16-c204900003-ng-nti-tp-s-x.exe" + "C:\windows\Fonts\verdana.ttf" "C:\Users\Penny\AppData\Local\Temp\SoHuVA_4.2.0.16-c204900003-ng-nti-tp-s-x.exe")
沙盘运行,SSF没有弹窗,直接消息通知已经拉黑该EXE |