AVG:
扫描:miss;
双击:实机双击,IDP击杀之。(连同其衍生物“svchost.exe”【真是热门的衍生物啊】及“SYS6AEB.TMP”和一个注册表项)
"";"IDP.Program.D1B0A5C0, C:\Users\killer\AppData\Local\Temp\svchost.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/17, 22:55:41"
"";", C:\USERS\KILLER\DESKTOP\EXE.EXE";"Object was blocked";"Process";"2016/2/17, 22:55:41"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2016/2/17, 22:55:41"
"";", C:\USERS\KILLER\APPDATA\LOCAL\TEMP\SYS6AEB.TMP";"Deleted";"File or Directory";"2016/2/17, 22:55:41"
"";", C:\Users\killer\AppData\Local\Temp\svchost.exe";"Object was blocked";"Process";"2016/2/17, 22:55:41"
"";", HKEY_USERS\S-1-5-21-540828005-2055914412-3868506426-1000\SOFTWARE\LOCKY";"Deleted, Moved to Virus Vault";"Registry key";"2016/2/17, 22:55:41"
|