KAV:
扫描:killed;
27.12.2015 21.17.29;Detected object (file) was deleted.;C:\Users\killer\Desktop\KB29703437.exe;C:\Users\killer\Desktop\KB29703437.exe;UDS:DangerousObject.Multi.Generic;Unknown threat;12/27/2015 21:17:29
双击:已入库样本,pass。
AVG:
扫描:miss;
双击:实机双击(不入沙),创建启动项后不久IDP击杀之(need reboot)。
"";"IDP.Program.D1B0A5C0, C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18623451\we1a12a13a1ab.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/27, 21:20:45"
"";", C:\USERS\KILLER\DESKTOP\KB29703437.EXE";"Object was blocked";"Process";"2015/12/27, 21:20:45"
"";", C:\Windows\explorer.exe";"Object was blocked";"Process";"2015/12/27, 21:20:45"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1005\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\WE121ZA13A1AB";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/27, 21:20:45"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1005\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\\WE121ZA13A1AB";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/27, 21:20:45"
|