AVG:
扫描:miss;
双击:实机双击,IDP击杀之。(【又现Unknown】连同其衍生物及添加/更改的注册表项)
"";"Unknown, C:\USERS\KILLER\DESKTOP\48B1.TMP.EXE";"Deleted";"File or Directory";"2016/3/12, 21:39:14"
"";", C:\Windows\qfbjskqyvvvm.exe";"Object was blocked";"Process";"2016/3/12, 21:39:14"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2016/3/12, 21:39:14"
"";", C:\Windows\System32\wbem\WMIC.exe";"Object was blocked";"Process";"2016/3/12, 21:39:14"
"";", C:\Windows\qfbjskqyvvvm.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/3/12, 21:39:14"
"";", HKEY_USERS\S-1-5-21-3895625976-2995373382-4201264068-1000\SOFTWARE\68CB71BF42530FE";"Deleted, Moved to Virus Vault";"Registry key";"2016/3/12, 21:39:14"
"";", HKEY_USERS\S-1-5-21-3895625976-2995373382-4201264068-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\AROINICS_SVC";"Deleted, Moved to Virus Vault";"Registry value";"2016/3/12, 21:39:14"
"";", C:\USERS\KILLER\DESKTOP\48B1.TMP.EXE";"Object was blocked";"Process";"2016/3/12, 21:39:14"
|