本帖最后由 aboringman 于 2015-12-5 22:49 编辑
AVG:
扫描:miss all;
双击:
实机双击(不入沙),情况如下:
878342.exe:直接双击,闪退,什么都没留下;
doc_oPkul1LL4Pi.js:直接双击,AVG的网页防护报毒(拦截下载73.exe?1),后调用878342.exe被IDP击杀(非调用样本,应该是衍生物)。
"";"Could be a Trojan horse Susphdo.I, aawraa.com/wp-includes/theme-compat/73.exe?1";"Object was blocked";"URL";"2015/12/5, 22:28:48"
"";"IDP.ARES.Generic, C:\Users\Killer\AppData\Local\Temp\878342.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/5, 22:29:05"
"";", C:\Windows\System32\wscript.exe";"Object was blocked";"Process";"2015/12/5, 22:29:05"
"";", C:\Users\Killer\Desktop\doc_oPkuI1LL4Pi.js";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/5, 22:29:05"
"";", C:\Users\Killer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NKEHOW8M\73[1]";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/5, 22:29:05"
"";", C:\Users\Killer\AppData\Local\Temp\878342.exe";"Object was blocked";"Process";"2015/12/5, 22:29:05"
ec078b9.exe:直接双击,AVG网页防护报毒(拦截下载afdb5be.exe),本体在拦截后自动退出。
"";"Site serves malicious executable files, exeupp.com//uploads/afdb5be.exe";"Object was blocked";"URL";"2015/12/5, 22:25:55"
sitecaldbflaaa.exe:直接双击,无反应。 |