本帖最后由 aboringman 于 2016-7-12 01:56 编辑
我回来了
AVG:
扫描:kill 1 file;
"";"Trojan horse FileCryptor.LYT, C:\Users\Killer\Desktop\unpack.bin";"Unresolved"
双击:
unpack.bin:添加.exe后缀,实机双击运行,IDP瞬间击杀之。【首现IDP.SEMS.AH1报法】
"";"IDP.SEMS.AH1, C:\Users\Killer\Desktop\unpack.bin.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/7/12, 1:49:34"
"";", C:\Users\Killer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\quser.lnk";"Deleted, Moved to Virus Vault";"File or Directory";"2016/7/12, 1:49:34"
"";", C:\Users\Killer\Desktop\unpack.bin.exe";"Object was blocked";"Process";"2016/7/12, 1:49:34"
"";", HKEY_USERS\S-1-5-21-3481082169-311058013-23538480-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\QUSER";"Deleted, Moved to Virus Vault";"Registry value";"2016/7/12, 1:49:34"
"";", HKEY_USERS\S-1-5-21-3481082169-311058013-23538480-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\\QUSER";"Deleted, Moved to Virus Vault";"Registry value";"2016/7/12, 1:49:34"
2.gif:实机双击,似乎是一个脚本,但,好像触发失败了,pass......
|