AVG:
扫描:killed.
"";"Trojan horse Inject2.APZF, c:\Users\Killer\Desktop\u.exe";"Healed, Moved to Virus Vault";"File or Directory";"2015/12/3, 17:56:53"
双击:实机双击(不入沙),样本成功添加启动项后,过了一会,IDP击杀之(需重启)。
"";"IDP.Trojan.7EB51C3C, C:\Users\Killer\Desktop\新建文件夹\u.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/3, 18:05:49"
"";", C:\Users\Killer\Desktop\新建文件夹\u.exe";"Object was blocked";"Process";"2015/12/3, 18:05:49"
"";", C:\Users\Killer\Desktop\新建文件夹\u.exe";"Object was blocked";"Process";"2015/12/3, 18:05:49"
"";", C:\Windows\explorer.exe";"Object was blocked";"Process";"2015/12/3, 18:05:49"
"";", C:\Windows\System32\svchost.exe";"Object was blocked";"Process";"2015/12/3, 18:05:49"
"";", C:\Windows\System32\WerFault.exe";"Object was blocked";"Process";"2015/12/3, 18:05:49"
"";", D:\sandboxie\SandboxieCrypto.exe";"Object was blocked";"Process";"2015/12/3, 18:05:49"
"";", C:\Users\Killer\AppData\Roaming\{F4601CD8-1540-7600-5000-ED5D49AA65}\puvbchmnst.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/3, 18:05:49"
"";", C:\Users\Killer\Desktop\新建文件夹\u.exe";"Object was blocked";"Process";"2015/12/3, 18:05:49"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\{F4601CD8-1540-7600-5000-ED5D49AA65}";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/3, 18:05:49"
看来,不一样的就是一定要重启。。。。。。 |