AVG:
扫描:pass;
双击:关闭除IDP之外的所有防护,实机双击,IDP击杀之。(【又现ALEXA】)
"";"IDP.ALEXA.51, C:\Users\killer\Desktop\6be25bfb5389966cf7dcf0aec508bce6.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/3/20, 13:54:18"
"";", C:\Users\killer\Desktop\6be25bfb5389966cf7dcf0aec508bce6.exe";"Object was blocked";"Process";"2016/3/20, 13:54:18"
"";", C:\Users\killer\Desktop\6be25bfb5389966cf7dcf0aec508bce6.exe";"Object was blocked";"Process";"2016/3/20, 13:54:18"
"";", C:\Windows\System32\taskkill.exe";"Object was blocked";"Process";"2016/3/20, 13:54:18"
"";", HKEY_USERS\S-1-5-21-3895625976-2995373382-4201264068-1000\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\\SHELL";"Deleted, Moved to Virus Vault";"Registry value";"2016/3/20, 13:54:18"
"";", HKEY_USERS\S-1-5-21-3895625976-2995373382-4201264068-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\EXPLORER";"Deleted, Moved to Virus Vault";"Registry value";"2016/3/20, 13:54:18"
只不过是利用taskkill结束了explorer而已,谈什么锁机。。。。。。
@墨家小子 |