AVG:
扫描:miss;
双击:实机双击,随便输个钓鱼网址后启动线程,然后摧毁线程,弹出无数个重启IE生效还有重启生效的窗口,最终葬送在我IDP的手上。
"";"IDP.ALEXA.51, C:\Users\kiiler\Desktop\进化DDOS工具(2).exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", C:\Users\kiiler\Desktop\进化DDOS工具(2).exe";"Object was blocked";"Process";"2016/1/30, 21:42:03"
"";", HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER";"Deleted, Moved to Virus Vault";"Registry key";"2016/1/30, 21:42:03"
"";", HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\ADMINISTRATION";"Deleted, Moved to Virus Vault";"Registry value";"2016/1/30, 21:42:03"
"";", HKEY_USERS\S-1-5-21-2236816692-667211127-2861217297-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM";"Deleted, Moved to Virus Vault";"Registry key";"2016/1/30, 21:42:03"
"";", HKEY_USERS\S-1-5-21-2236816692-667211127-2861217297-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM\\DISABLEREGISTRYTOOLS";"Deleted";"Registry value";"2016/1/30, 21:42:03"
PS.真猛,多次调用taskkill.exe试图关闭某个程序,但均被IDP阻止,还修改重要注册表项,简直就是送自己入IDP之口啊。。。。。。 |