AVG:
双击【仅测试母体】:关闭监控,实机双击,IDP击杀之。【并回滚其衍生物】
"";"IDP.Trojan.4E345CBF, C:\Users\abori\Desktop\1.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/10/1, 21:25:05"
"";", C:\USERS\ABORI\APPDATA\LOCAL\TEMP\IXP000.TMP\GMCHFKSWND.EXE";"Object was blocked";"Process";"2016/10/1, 21:25:05"
"";", C:\USERS\ABORI\APPDATA\ROAMING\SPFG.EXE";"Object was blocked";"Process";"2016/10/1, 21:25:05"
"";", C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe";"Object was blocked";"Process";"2016/10/1, 21:25:05"
"";", C:\Users\abori\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hWBfSAaAiEYL.lnk";"Deleted, Moved to Virus Vault";"File or Directory";"2016/10/1, 21:25:05"
"";", C:\USERS\ABORI\APPDATA\LOCAL\TEMP\IXP000.TMP\GMCHFKSWND.EXE";"Deleted";"File or Directory";"2016/10/1, 21:25:05"
"";", C:\Users\abori\Desktop\1.exe";"Object was blocked";"Process";"2016/10/1, 21:25:05"
"";", HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\\WEXTRACT_CLEANUP0";"Deleted";"Registry value";"2016/10/1, 21:25:05"
|