本帖最后由 aboringman 于 2015-12-1 20:28 编辑
AVG:
扫描:miss;
双击:实机双击(不入沙),样本释放衍生物后自删除,衍生物运行不久后被IDP击杀。
"";"IDP.Trojan.964F1FF2, C:\Users\Killer\AppData\Roaming\xhbom-a.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/1, 20:23:52"
"";", C:\USERS\KILLER\DESKTOP\73.EXE";"Object was blocked";"Process";"2015/12/1, 20:23:52"
"";", C:\Windows\System32\bcdedit.exe";"Object was blocked";"Process";"2015/12/1, 20:23:52"
"";", C:\Windows\System32\bcdedit.exe";"Object was blocked";"Process";"2015/12/1, 20:23:52"
"";", C:\USERS\KILLER\DESKTOP\73.EXE";"Object was blocked";"Process";"2015/12/1, 20:23:52"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/1, 20:23:52"
"";", C:\Windows\System32\WerFault.exe";"Object was blocked";"Process";"2015/12/1, 20:23:52"
"";", D:\sandboxie\SandboxieCrypto.exe";"Object was blocked";"Process";"2015/12/1, 20:23:52"
"";", C:\USERS\KILLER\DESKTOP\73.EXE";"Deleted";"File or Directory";"2015/12/1, 20:23:52"
"";", C:\Users\Killer\AppData\Roaming\xhbom-a.exe";"Object was blocked";"Process";"2015/12/1, 20:23:52"
|