根据文件B超的检测结果来看,很有可能是木马,建议楼主用杀毒软件扫描下自己的系统,必要时可以使用大蜘蛛扫描器(绿色版)。
检测链接:
https://b-chao.com/index.php/Ind ... #analysis/ajax/demo
附带AVG IDP测试结果:
"";"IDP.Trojan.EE14B26B, C:\Users\kiiler\AppData\Roaming\NsMiner\IMG001.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/1/30, 23:56:33"
"";", C:\Users\kiiler\AppData\Roaming\NsMiner\IMG001.exe";"Object was blocked";"Process";"2016/1/30, 23:56:33"
"";", C:\Users\kiiler\Desktop\IMG001.scr";"Object was blocked";"Process";"2016/1/30, 23:56:33"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2016/1/30, 23:56:33"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2016/1/30, 23:56:33"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2016/1/30, 23:56:33"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2016/1/30, 23:56:33"
"";", C:\Windows\System32\reg.exe";"Object was blocked";"Process";"2016/1/30, 23:56:33"
"";", C:\Windows\System32\schtasks.exe";"Object was blocked";"Process";"2016/1/30, 23:56:33"
"";", C:\Windows\System32\schtasks.exe";"Object was blocked";"Process";"2016/1/30, 23:56:33"
"";", C:\Windows\System32\powercfg.exe";"Object was blocked";"Process";"2016/1/30, 23:56:33"
"";", C:\Windows\System32\powercfg.exe";"Object was blocked";"Process";"2016/1/30, 23:56:33"
"";", C:\Windows\System32\powercfg.exe";"Object was blocked";"Process";"2016/1/30, 23:56:33"
"";", C:\Users\kiiler\AppData\Roaming\NsMiner\NsCpuCNMiner32.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/1/30, 23:56:33"
"";", C:\Users\kiiler\AppData\Roaming\NsMiner\NsCpuCNMiner64.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/1/30, 23:56:33"
"";", C:\Users\kiiler\Desktop\IMG001.scr";"Deleted, Moved to Virus Vault";"File or Directory";"2016/1/30, 23:56:33"
"";", HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN";"Deleted, Moved to Virus Vault";"Registry value";"2016/1/30, 23:56:33"
"";", HKEY_USERS\S-1-5-21-2236816692-667211127-2861217297-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN";"Deleted, Moved to Virus Vault";"Registry value";"2016/1/30, 23:56:33"
"";", C:\Users\kiiler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Run.lnk";"Healed, Moved to Virus Vault";"File or Directory";"2016/1/30, 23:56:33" |