双击之后成功下载病毒并运行,卡巴检测到并回滚。
26.12.2015 10.38.39;回滚恶意程序的操作时文件被删除;c:\users\yingzhi\appdata\local\microsoft\windows\inetcache\ie\qf5193ao\ibd2[1].jpg;c:\users\yingzhi\appdata\local\microsoft\windows\inetcache\ie\qf5193ao\ibd2[1].jpg;Resource viewer, decompiler & recompiler.;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
26.12.2015 10.38.39;恶意程序的操作已回滚;UDS:DangerousPattern.Multi.Generic;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
26.12.2015 10.38.39;回滚恶意程序的操作时注册表键值被恢复;HKEY_USERS\s-1-5-21-1361356840-79821918-819351158-1001\software\microsoft\windows\currentversion\internet settings\autodetect;HKEY_USERS\s-1-5-21-1361356840-79821918-819351158-1001\software\microsoft\windows\currentversion\internet settings\autodetect;Resource viewer, decompiler & recompiler.;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
26.12.2015 10.38.39;回滚恶意程序的操作时注册表键值被恢复;HKEY_USERS\s-1-5-21-1361356840-79821918-819351158-1001\software\microsoft\windows\currentversion\internet settings\connections\savedlegacysettings;HKEY_USERS\s-1-5-21-1361356840-79821918-819351158-1001\software\microsoft\windows\currentversion\internet settings\connections\savedlegacysettings;Resource viewer, decompiler & recompiler.;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
26.12.2015 10.38.39;回滚恶意程序的操作时注册表键值被恢复;HKEY_USERS\s-1-5-21-1361356840-79821918-819351158-1001\software\microsoft\windows\currentversion\internet settings\autoconfigurl;HKEY_USERS\s-1-5-21-1361356840-79821918-819351158-1001\software\microsoft\windows\currentversion\internet settings\autoconfigurl;Resource viewer, decompiler & recompiler.;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
26.12.2015 10.38.39;回滚恶意程序的操作时注册表键值被恢复;HKEY_USERS\s-1-5-21-1361356840-79821918-819351158-1001\software\microsoft\windows\currentversion\internet settings\proxyoverride;HKEY_USERS\s-1-5-21-1361356840-79821918-819351158-1001\software\microsoft\windows\currentversion\internet settings\proxyoverride;Resource viewer, decompiler & recompiler.;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
26.12.2015 10.38.39;回滚恶意程序的操作时注册表键值被恢复;HKEY_USERS\s-1-5-21-1361356840-79821918-819351158-1001\software\microsoft\windows\currentversion\internet settings\proxyserver;HKEY_USERS\s-1-5-21-1361356840-79821918-819351158-1001\software\microsoft\windows\currentversion\internet settings\proxyserver;Resource viewer, decompiler & recompiler.;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
26.12.2015 10.38.39;回滚恶意程序的操作时注册表键值被恢复;HKEY_USERS\s-1-5-21-1361356840-79821918-819351158-1001\software\microsoft\windows\currentversion\internet settings\proxyenable;HKEY_USERS\s-1-5-21-1361356840-79821918-819351158-1001\software\microsoft\windows\currentversion\internet settings\proxyenable;Resource viewer, decompiler & recompiler.;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
26.12.2015 10.38.39;回滚恶意程序的操作时文件被删除;c:\users\yingzhi\appdata\local\temp\5573205.exe;c:\users\yingzhi\appdata\local\temp\5573205.exe;Resource viewer, decompiler & recompiler.;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
26.12.2015 10.38.39;回滚恶意程序的操作时文件被删除;c:\users\yingzhi\appdata\local\temp\2274935.exe;c:\users\yingzhi\appdata\local\temp\2274935.exe;Resource viewer, decompiler & recompiler.;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
26.12.2015 10.38.39;回滚恶意程序的操作时文件被删除;c:\users\yingzhi\appdata\local\temp\1954869.exe;c:\users\yingzhi\appdata\local\temp\1954869.exe;Resource viewer, decompiler & recompiler.;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
26.12.2015 10.38.39;回滚恶意程序的操作时文件被删除;c:\users\yingzhi\appdata\local\microsoft\windows\inetcache\ie\rgbsxse8\ibd1[1].jpg;c:\users\yingzhi\appdata\local\microsoft\windows\inetcache\ie\rgbsxse8\ibd1[1].jpg;Resource viewer, decompiler & recompiler.;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
26.12.2015 10.38.39;回滚恶意程序的操作时文件被删除;c:\users\yingzhi\appdata\local\microsoft\windows\inetcache\ie\qhpnhduj\ibd3[1].jpg;c:\users\yingzhi\appdata\local\microsoft\windows\inetcache\ie\qhpnhduj\ibd3[1].jpg;Resource viewer, decompiler & recompiler.;C:\Users\yingzhi\AppData\Local\Temp\2274935.exe;12/26/2015 10:38:39
|