双击敢死队,有意思
AVG:
扫描:pass;
双击:关闭监控,实机双击,在其成功关闭Windows防火墙后,被无情的IDP击杀了。
"";"IDP.Trojan.322C0649, C:\Users\killer\Desktop\新建文件夹\Evo.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/13, 21:40:21"
"";", C:\Windows\System32\sc.exe";"Object was blocked";"Process";"2016/2/13, 21:40:21"
"";", C:\Windows\System32\netsh.exe";"Object was blocked";"Process";"2016/2/13, 21:40:21"
"";", C:\Users\killer\Desktop\新建文件夹\Evo.exe";"Object was blocked";"Process";"2016/2/13, 21:40:21"
"";", HKEY_USERS\S-1-5-21-3490642848-900494750-2612034136-1000\SOFTWARE\CODEBLOCKS";"Deleted, Moved to Virus Vault";"Registry key";"2016/2/13, 21:40:21"
"";", HKEY_USERS\S-1-5-21-3490642848-900494750-2612034136-1000\SOFTWARE\HEX-RAYS";"Deleted, Moved to Virus Vault";"Registry key";"2016/2/13, 21:40:21"
"";", HKEY_USERS\S-1-5-21-3490642848-900494750-2612034136-1000\SOFTWARE\IMMUNITY INC";"Deleted, Moved to Virus Vault";"Registry key";"2016/2/13, 21:40:21"
"";", HKEY_USERS\S-1-5-21-3490642848-900494750-2612034136-1000\SOFTWARE\NMAP";"Deleted, Moved to Virus Vault";"Registry key";"2016/2/13, 21:40:21"
"";", HKEY_USERS\S-1-5-21-3490642848-900494750-2612034136-1000\SOFTWARE\SYSINTERNALS";"Deleted, Moved to Virus Vault";"Registry key";"2016/2/13, 21:40:21"
|