本帖最后由 aboringman 于 2015-12-9 19:24 编辑
AVG:
扫描:miss;
双击:实机双击(不入沙),释放衍生物,添加启动项后不久,IDP击杀之(再次出现Unknown报法)。
"";"Unknown, C:\Users\killer.Killer-PC\Desktop\657668d589a3a03e24f6a821927d0f18a9034a44da1945bb63ee25def475ffa5.scr";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/9, 19:16:28"
"";", C:\Windows\explorer.exe";"Object was blocked";"Process";"2015/12/9, 19:16:28"
"";", C:\ProgramData\zKqoIyvTTVVo_L.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/9, 19:16:28"
"";", C:\Users\killer.Killer-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\360极速浏览器.lnk";"Healed, Moved to Virus Vault";"File or Directory";"2015/12/9, 19:16:28"
"";", C:\Users\killer.Killer-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\在沙盘中运行网页浏览器.lnk";"Healed, Moved to Virus Vault";"File or Directory";"2015/12/9, 19:16:28"
"";", C:\Users\killer.Killer-PC\Desktop\657668d589a3a03e24f6a821927d0f18a9034a44da1945bb63ee25def475ffa5.scr";"Object was blocked";"Process";"2015/12/9, 19:16:28"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\FTGWAYIDGNSITSZDOPMRUKSTPB";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/9, 19:16:28"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1003\CONTROL PANEL\DESKTOP\\WALLPAPER";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/9, 19:16:28" |