本帖最后由 aboringman 于 2016-2-12 00:31 编辑
ESET:
扫描:kill 1 file;
C:\Users\killer\Desktop\“.exe - a variant of MSIL/Injector.OAP trojan - cleaned by deleting [1]
双击:关闭监控,实机双击,AMS kill 活动的“.exe(即带有无效数签的),另一个无反应。
Time;Scanner;Object type;Object;Threat;Action;User;Information;Hash
2016/2/12 0:13:51;Advanced memory scanner;file;Operating memory » “.exe(5648);MSIL/Agent.ABP trojan;cleaned - contained infected files;;;E3712FC2C200C65B1B6AB6AE63D3FA01CDF46DF4
AVG:
扫描:kill 1 file;
"";"Virus found Win32/Heur, C:\Users\killer\Desktop\'.exe";"Healed, Moved to Virus Vault";"File or Directory";"2016/2/12, 0:18:12"
双击:关闭监控,实机双击,IDP双杀。
'.exe:
"";"IDP.Virus.E2B43537, C:\Users\killer\Desktop\新建文件夹\'.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/12, 0:20:44"
"";", C:\Users\killer\Desktop\新建文件夹\'.exe";"Object was blocked";"Process";"2016/2/12, 0:20:44"
"";", C:\Users\killer\AppData\Local\Temp\MBX@2B8@1331B08.###";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/12, 0:20:44"
"";", C:\Users\killer\AppData\Local\Temp\MBX@2B8@1331AF8.###";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/12, 0:20:44"
“.exe:
"";"IDP.SMP.12, C:\Users\killer\Desktop\新建文件夹\“.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/12, 0:23:51"
"";", C:\Users\killer\Desktop\新建文件夹\“.exe";"Object was blocked";"Process";"2016/2/12, 0:23:51"
"";", C:\Windows\System32\spoolsv.exe";"Object was blocked";"Process";"2016/2/12, 0:23:51"
"";", C:\Windows\System32\svchost.exe";"Object was blocked";"Process";"2016/2/12, 0:23:51"
"";", D:\360se6\Application\360se.exe";"Object was blocked";"Process";"2016/2/12, 0:23:51"
"";", C:\Users\killer\Desktop\新建文件夹\“.exe";"Object was blocked";"Process";"2016/2/12, 0:23:51"
|