AVG:
扫描:miss;
双击:实机双击(不入沙),创建启动项后不久IDP击杀母体及衍生物(need reboot)。
"";"IDP.Program.D1B0A5C0, C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18611771\KdjSaS011arhaaaa.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/27, 22:48:02"
"";", C:\Windows\explorer.exe";"Reboot is required to finish the action";"Process";"2015/12/27, 22:48:02"
"";", C:\USERS\KILLER\DESKTOP\197FJR1DKQW.EXE";"Object was blocked";"Process";"2015/12/27, 22:48:02"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1005\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\KDJSAS011ARHAAA";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/27, 22:48:02"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1005\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\\KDJSAS011ARHAAA";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/27, 22:48:02"
|