AVG:
扫描:killed;(【by WP】很有意思,居然入库了,说好的新呢。。。。。。)
"";"Virus found Win32/Cryptor, https://att.kafan.cn/forum.php?mod=attachment&aid=Mjc2NzA4Nnw4MzBlOWFkMnwxNDU4MDM3OTUzfDEwMDA1MDF8MjAzMzAyNw%3D%3D";"Object was blocked";"URL";"2016/3/15, 18:32:45"
"";"Virus found Win32/Cryptor, https://att.kafan.cn/forum.php?mod=attachment&aid=Mjc2NzA4Nnw4MzBlOWFkMnwxNDU4MDM3OTUzfDEwMDA1MDF8MjAzMzAyNw%3D%3D:\522.tmp.exe";"Unr
esolved";"Embedded element in the archive, email attachment, cookie etc.";"2016/3/15, 18:32:45"
双击:关闭监控,实机双击,IDP击杀之。(【又现ALEXA】断网情况下的双击)
"";"IDP.ALEXA.51, C:\USERS\KILLER\DESKTOP\522.TMP.EXE";"Deleted";"File or Directory";"2016/3/15, 18:35:28"
"";", C:\USERS\KILLER\DESKTOP\522.TMP.EXE";"Object was blocked";"Process";"2016/3/15, 18:35:28"
"";", C:\Users\killer\Documents\wdbpnp.exe";"Object was blocked";"Process";"2016/3/15, 18:35:28"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2016/3/15, 18:35:28"
"";", C:\Users\killer\Documents\wdbpnp.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/3/15, 18:35:28"
"";", C:\USERS\KILLER\DESKTOP\522.TMP.EXE";"Object was blocked";"Process";"2016/3/15, 18:35:28"
继续上证据:
|