AVG:
扫描:pass;
双击:关闭监控,实机双击,IDP 仅击杀 pclock_unpack.exe,另一个双击后未发现异常。
"";"IDP.Program.D1B0A5C0, C:\Users\kiiler\AppData\Local\Temp\WinFaxViewer.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/6, 17:23:13"
"";", C:\Users\kiiler\Desktop\pclock_unpack.exe";"Object was blocked";"Process";"2016/2/6, 17:23:13"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/2/6, 17:23:13"
"";", C:\Users\kiiler\Desktop\pclock_unpack.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/6, 17:23:13"
"";", HKEY_USERS\S-1-5-21-2236816692-667211127-2861217297-1000\SOFTWARE\VB AND VBA PROGRAM SETTINGS";"Deleted, Moved to Virus Vault";"Registry key";"2016/2/6, 17:23:13"
"";", C:\Users\kiiler\AppData\Local\Temp\WinFaxViewer.exe";"Object was blocked";"Process";"2016/2/6, 17:23:13"
|