AVG:
扫描:miss all;
双击:实机双击(不入沙),IDP三杀,最后一个怀疑不是程序。。。。。。
4601699e3dad1987c51af95fff0aafd38c7555f87f2c93da1a1a8540f5779f52.exe:
"";"Unknown, C:\Users\Killer\Desktop\4601699e3dad1987c51af95fff0aafd38c7555f87f2c93da1a1a8540f5779f52.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/4, 19:41:17"
"";", C:\Users\Killer\Desktop\4601699e3dad1987c51af95fff0aafd38c7555f87f2c93da1a1a8540f5779f52.exe";"Object was blocked";"Process";"2015/12/4, 19:41:17"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/4, 19:41:17"
"";", C:\Users\Killer\AppData\Roaming\360se6\Application\360se.exe";"Object was blocked";"Process";"2015/12/4, 19:41:17"
"";", C:\Users\Killer\AppData\Local\Temp\jikhrgleg.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/4, 19:41:17"
"";", C:\Users\Killer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0I8UZZG\7za[1].mkv";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/4, 19:41:17"
caitlyn.exe:
"";"IDP.ALEXA.51, C:\uoscnassc\hrthfkcbccia.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/4, 19:43:25"
"";", C:\uoscnassc\kxt8e95b24uztoaggvsp.exe";"Object was blocked";"Process";"2015/12/4, 19:43:25"
"";", C:\uoscnassc\xdaeqxhaq.exe";"Object was blocked";"Process";"2015/12/4, 19:43:25"
"";", C:\Users\Killer\Desktop\caitlyn.exe";"Object was blocked";"Process";"2015/12/4, 19:43:25"
"";", C:\Users\Killer\Desktop\caitlyn.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/4, 19:43:25"
"";", C:\uoscnassc\xdaeqxhaq.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/4, 19:43:25"
"";", C:\uoscnassc\kxt8e95b24uztoaggvsp.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/4, 19:43:25"
"";", C:\uoscnassc\hrthfkcbccia.exe";"Object was blocked";"Process";"2015/12/4, 19:43:25"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\PANEL POLICY WIRED SECURITY";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/4, 19:43:25"
godfrey.exe:
"";"IDP.ALEXA.51, C:\qoddilfu\vrafmeg.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/4, 19:44:37"
"";", C:\qoddilfu\ywdsajiyp.exe";"Object was blocked";"Process";"2015/12/4, 19:44:37"
"";", C:\QODDILFU\FU73O96T9XJNFURYBPWNI.EXE";"Object was blocked";"Process";"2015/12/4, 19:44:37"
"";", C:\Users\Killer\Desktop\godfrey.exe";"Object was blocked";"Process";"2015/12/4, 19:44:37"
"";", C:\Users\Killer\Desktop\godfrey.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/4, 19:44:37"
"";", C:\QODDILFU\FU73O96T9XJNFURYBPWNI.EXE";"Deleted";"File or Directory";"2015/12/4, 19:44:37"
"";", C:\qoddilfu\ywdsajiyp.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/4, 19:44:37"
"";", C:\qoddilfu\vrafmeg.exe";"Object was blocked";"Process";"2015/12/4, 19:44:37"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\PLAY THREAD CONNECTION ADAPTER LIST SPOOLER EVENT";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/4, 19:44:37"
caitlyn.exe和godfrey.exe貌似是一样的(从行为看有些相似)。 |