AVG:
扫描:kill it.
"";"Trojan horse PSW.Generic12.TCT, c:\Users\Killer\Desktop\pdf.exe";"Healed, Moved to Virus Vault";"File or Directory";"2015/12/1, 18:27:01"
双击:关闭监控,保留IDP,实机不入沙,等到行为差不多都出来后(Windows防火墙已提示时),IDP瞬间击杀。
"";"Unknown, C:\Users\Killer\AppData\Roaming\Ovrays\hyba.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/1, 18:30:33"
"";", C:\USERS\KILLER\DESKTOP\新建文件夹\PDF.EXE";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\taskhost.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\dwm.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\explorer.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Program Files\AVG\Framework\Common\avguix.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", D:\sandboxie\SbieCtrl.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", D:\Advanced SystemCare\ASCTray.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\GWX\GWX.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\ctfmon.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\taskmgr.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\rundll32.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\dllhost.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", D:\sandboxie\Start.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\7.1.1.812\360bdoctor.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", D:\sandboxie\Start.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Program Files\AVG\Av\avgui.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Program Files\AVG\Av\avgcomdlgx.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Program Files\AVG\Av\avgcomdlgx.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Program Files\AVG\Av\avgcfgex.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\USERS\KILLER\APPDATA\LOCAL\TEMP\EBH2643.BAT";"Deleted";"File or Directory";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\User Data\v3update\download\~TA516E.cab";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\User Data\v3update\download\~520A.cab";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\360se6\User Data\safemon\urllib.dat";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/1, 18:30:33"
"";", C:\Windows\System32\dwm.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", C:\Users\Killer\AppData\Roaming\Ovrays\hyba.exe";"Object was blocked";"Process";"2015/12/1, 18:30:33"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\HYBA";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/1, 18:30:33"
目测AVG没有被成功入侵(详见IDP拦截和回滚的行为列表),用PC Hunter看了一下,没有可疑启动项或驱动存在,防御成功。
@驭龙 上次测试清毒时关闭了所有防护,可能是因为这样AVG的UI被入侵成功的吧。。。。。。 |