本帖最后由 aboringman 于 2016-1-30 16:38 编辑
KIS:
扫描:kill all files.
30.01.2016 16.10.07;Detected object (file) deleted.;C:\Users\kiiler\Desktop\drop\99F5F4689A4FB45FF88AB8379777D06F001030EB;C:\Users\kiiler\Desktop\drop\99F5F4689A4FB45FF88AB8379777D06F001030EB;UDS:DangerousObject.Multi.Generic;Unknown threat;01/30/2016 16:10:07
30.01.2016 16.08.51;Detected object (file) deleted.;C:\Users\kiiler\Desktop\sample\99F5F4689A4FB45FF88AB8379777D06F001030EB;C:\Users\kiiler\Desktop\sample\99F5F4689A4FB45FF88AB8379777D06F001030EB;UDS:DangerousObject.Multi.Generic;Unknown threat;01/30/2016 16:08:51
30.01.2016 16.08.51;Detected object (file) deleted.;C:\Users\kiiler\Desktop\dbust.exe;C:\Users\kiiler\Desktop\dbust.exe;UDS:DangerousObject.Multi.Generic;Unknown threat;01/30/2016 16:08:51
双击:已入库样本,无双击条件。
AVG:
扫描:kill all files(真罕见。。。。。。);
"";"Trojan horse MSIL9.BOMJ, C:\Users\kiiler\Desktop\dbust.exe";"Secured"
"";"Trojan horse MSIL9.BOMJ, C:\Users\kiiler\Desktop\99F5F4689A4FB45FF88AB8379777D06F001030EB";"Secured"
双击:关闭监控,实机双击,IDP双杀(以下为详细信息)。
dbust.exe(测了两次,第二次貌似IDP记住了,瞬间击杀。。。。。。):
第一次(need reboot):
"";"IDP.SMP.11, C:\Users\kiiler\Desktop\新建文件夹\dbust.exe";"Healed, Moved to Virus Vault";"File or Directory";"2016/1/30, 16:24:24"
"";", C:\Users\kiiler\Desktop\新建文件夹\dbust.exe";"Object was blocked";"Process";"2016/1/30, 16:24:24"
"";", C:\Users\kiiler\AppData\Roaming\Microsoft\HKRUN.exe";"Object was blocked";"Process";"2016/1/30, 16:24:24"
"";", C:\Users\kiiler\AppData\Roaming\Microsoft\HKRUN.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/1/30, 16:24:24"
"";", C:\Users\kiiler\Desktop\新建文件夹\dbust.exe";"Object was blocked";"Process";"2016/1/30, 16:24:24"
第二次无需重启,直接击杀:
"";"IDP.Program.D1B0A5C0, C:\Users\kiiler\Desktop\新建文件夹\dbust.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/1/30, 16:32:24"
"";", C:\Users\kiiler\Desktop\新建文件夹\dbust.exe";"Object was blocked";"Process";"2016/1/30, 16:32:24"
99F5F4689A4FB45FF88AB8379777D06F001030EB.exe(无需重启):
"";"IDP.Program.D1B0A5C0, C:\Users\kiiler\Desktop\新建文件夹\99F5F4689A4FB45FF88AB8379777D06F001030EB.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/1/30, 16:31:33"
"";", C:\Users\kiiler\Desktop\新建文件夹\99F5F4689A4FB45FF88AB8379777D06F001030EB.exe";"Object was blocked";"Process";"2016/1/30, 16:31:33"
"";", C:\Users\kiiler\AppData\Roaming\Microsoft\HKRUN.exe";"Object was blocked";"Process";"2016/1/30, 16:31:33"
"";", C:\Users\kiiler\AppData\Roaming\Microsoft\HKRUN.exe";"Object was blocked";"Process";"2016/1/30, 16:31:33"
"";", C:\Users\kiiler\AppData\Roaming\Microsoft\HKRUN.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/1/30, 16:31:33"
"";", HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{SL5JY177-PJ3Y-E8CD-646H-S0V6OY4OJKL6}";"Deleted, Moved to Virus Vault";"Registry key";"2016/1/30, 16:31:33"
"";", HKEY_USERS\S-1-5-21-2236816692-667211127-2861217297-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\REGEDIT1";"Deleted, Moved to Virus Vault";"Registry value";"2016/1/30, 16:31:33"
"";", C:\Users\kiiler\Desktop\新建文件夹\99F5F4689A4FB45FF88AB8379777D06F001030EB.exe";"Object was blocked";"Process";"2016/1/30, 16:31:33" |