AVG:
扫描:miss;
双击:实机双击,IDP击杀之。(【又现ALEXA】断网情况下的较量)
"";"IDP.ALEXA.51, C:\Users\killer\Documents\dfwepo.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/3/15, 20:08:44"
"";", C:\USERS\KILLER\DESKTOP\B9A7.TMP.EXE";"Object was blocked";"Process";"2016/3/15, 20:08:44"
"";", C:\Windows\System32\vssadmin.exe";"Object was blocked";"Process";"2016/3/15, 20:08:44"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2016/3/15, 20:08:44"
"";", C:\USERS\KILLER\DESKTOP\B9A7.TMP.EXE";"Deleted";"File or Directory";"2016/3/15, 20:08:44"
"";", C:\Users\killer\Documents\dfwepo.exe";"Object was blocked";"Process";"2016/3/15, 20:08:44"
"";", HKEY_USERS\.DEFAULT\SOFTWARE\TRUEIMG";"Deleted, Moved to Virus Vault";"Registry key";"2016/3/15, 20:08:44"
"";", HKEY_USERS\S-1-5-21-3895625976-2995373382-4201264068-1000\SOFTWARE\69AA6C9091697F8";"Deleted, Moved to Virus Vault";"Registry key";"2016/3/15, 20:08:44"
"";", HKEY_USERS\S-1-5-21-3895625976-2995373382-4201264068-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\_GUSR";"Deleted, Moved to Virus Vault";"Registry value";"2016/3/15, 20:08:44"
继续上证据截图:
|