AVG:
扫描:miss;
双击:实机双击,IDP击杀之。(连同衍生物“svchost.exe”和“SYSE3BB.TMP”,阻止cmd.exe的后续操作,并删除其修改(添加/篡改)的一个注册表项)
"";"IDP.Program.D1B0A5C0, C:\Users\killer\AppData\Local\Temp\svchost.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/18, 21:34:12"
"";", C:\USERS\KILLER\DESKTOP\7647GD7B43F43.EXE";"Object was blocked";"Process";"2016/2/18, 21:34:12"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2016/2/18, 21:34:12"
"";", C:\USERS\KILLER\APPDATA\LOCAL\TEMP\SYSE3BB.TMP";"Deleted";"File or Directory";"2016/2/18, 21:34:12"
"";", C:\Users\killer\AppData\Local\Temp\svchost.exe";"Object was blocked";"Process";"2016/2/18, 21:34:12"
"";", HKEY_USERS\S-1-5-21-540828005-2055914412-3868506426-1000\SOFTWARE\LOCKY";"Deleted, Moved to Virus Vault";"Registry key";"2016/2/18, 21:34:12"
|