AVG:
扫描:pass;
双击:关闭监控,实机双击,起初被锁屏,然而,一切都是假象,IDP击杀之!(又现Unknown报法【需重启】)
"";"Unknown, C:\Users\killer\Desktop\网赚教程.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/21, 14:06:10"
"";", C:\Users\killer\Desktop\网赚教程.exe";"Object was blocked";"Process";"2016/2/21, 14:06:10"
"";", C:\Windows\System32\winlogon.exe";"Object was blocked";"Process";"2016/2/21, 14:06:10"
"";", C:\Windows\System32\userinit.exe";"Object was blocked";"Process";"2016/2/21, 14:06:10"
"";", C:\Windows\explorer.exe";"Object was blocked";"Process";"2016/2/21, 14:06:10"
"";", C:\Windows\explorer.exe";"Object was blocked";"Process";"2016/2/21, 14:06:10"
"";", C:\Windows\explorer.exe";"Object was blocked";"Process";"2016/2/21, 14:06:10"
"";", C:\Windows\System32\WinLockDll.dll";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/21, 14:06:10"
"";", HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\BLUE";"Deleted, Moved to Virus Vault";"Registry value";"2016/2/21, 14:06:10"
"";", HKEY_USERS\S-1-5-21-540828005-2055914412-3868506426-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM";"Deleted, Moved to Virus Vault";"Registry key";"2016/2/21, 14:06:10"
"";", HKEY_USERS\S-1-5-21-540828005-2055914412-3868506426-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM\\DISABLETASKMGR";"Deleted";"Registry value";"2016/2/21, 14:06:10"
|