本帖最后由 nick20010117 于 2016-6-26 16:10 编辑
"";"IDP.ALEXA.51, C:\Program Files\windowsupdate.exe";"已隔离, 需要重新启动才能完成操作";"文件或目录";"2016/6/26, 16:04:12"
"";", C:\USERS\ADMINISTRATOR\DESKTOP\SAMPLES\APOCALYPSE RANSOMWARE.EXE";"已阻止该对象";"进程";"2016/6/26, 16:04:12"
"";", C:\dosh\ghos\DOS之家.url.encrypted";"已删除, 已隔离";"文件或目录";"2016/6/26, 16:04:12"
"";", C:\USERS\ADMINISTRATOR\DESKTOP\SAMPLES\APOCALYPSE RANSOMWARE.EXE";"需要重新启动才能完成操作";"文件或目录";"2016/6/26, 16:04:12"
"";", C:\Program Files\windowsupdate.exe";"已阻止该对象";"进程";"2016/6/26, 16:04:12"
"";", HKEY_USERS\S-1-5-21-4035673165-3688820562-1120568024-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\WINDOWS UPDATE SVC";"已删除, 已隔离";"注册表值";"2016/6/26, 16:04:12"
"";", HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\WINDOWS UPDATE SVC";"已删除, 已隔离";"注册表值";"2016/6/26, 16:04:12"
"";"IDP.Trojan.6011931D, C:\Users\Administrator\Desktop\samples\DELoader.exe";"已隔离, 需要重新启动才能完成操作";"文件或目录";"2016/6/26, 16:07:17"
"";", C:\Users\Administrator\Desktop\samples\DELoader.exe";"已阻止该对象";"进程";"2016/6/26, 16:07:17"
"";"IDP.Trojan.E13F31C, C:\Users\Administrator\Desktop\samples\Kozy.Jozy Ransomware.exe";"已隔离, 需要重新启动才能完成操作";"文件或目录";"2016/6/26, 16:08:06"
"";", C:\Windows\System32\vssadmin.exe";"已阻止该对象";"进程";"2016/6/26, 16:08:06"
"";", C:\Users\Administrator\Desktop\samples\w.jpg";"已删除, 已隔离";"文件或目录";"2016/6/26, 16:08:06"
"";", C:\Users\Administrator\Desktop\samples\Kozy.Jozy Ransomware.exe";"已阻止该对象";"进程";"2016/6/26, 16:08:06"
"";", HKEY_USERS\S-1-5-21-4035673165-3688820562-1120568024-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\WALL";"已删除, 已隔离";"注册表值";"2016/6/26, 16:08:06"
@230f4
|