AVG:
扫描:miss;
双击:测试了两次,第一次双击后衍生物报错,愣是没有加密到。第二次终于现形,IDP击杀之。
"";"IDP.ARES.Generic, C:\Users\kiiler\Desktop\DMALocker.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/9, 0:46:58"
"";", C:\Users\kiiler\Desktop\DMALocker.exe";"Object was blocked";"Process";"2016/2/9, 0:46:58"
"";", C:\PROGRAMDATA\SVCHOSD.EXE";"Object was blocked";"Process";"2016/2/9, 0:46:58"
"";", C:\PROGRAMDATA\SVCHOSD.EXE";"Object was blocked";"Process";"2016/2/9, 0:46:58"
"";", C:\PROGRAMDATA\SVCHOSD.EXE";"Object was blocked";"Process";"2016/2/9, 0:46:58"
"";", C:\PROGRAMDATA\SVCHOSD.EXE";"Deleted";"File or Directory";"2016/2/9, 0:46:58"
"";", C:\Users\kiiler\Desktop\DMALocker.exe";"Object was blocked";"Process";"2016/2/9, 0:46:58"
"";", HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\CRYPTEDINFO";"Deleted, Moved to Virus Vault";"Registry value";"2016/2/9, 0:46:58"
"";", HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\CSSYS";"Deleted, Moved to Virus Vault";"Registry value";"2016/2/9, 0:46:58"
@cepots 这只是一个例子,在样本未经入库的情况下,IDP出面应对威胁。 |