| 本帖最后由 ak666 于 2017-11-5 18:21 编辑 
 之前有个叫什么eGambit什么的报毒,就他一个。现在看来是没问题了,用破解软件,心里总是不踏实。。
 用ssf,总是监控到要键盘记录。。===============================
 
 复制代码Filename: Tu.exe
Threat name: SONAR.AM.C!g3Full Path: c:\program files\total uninstall 6\tu.exe
____________________________
____________________________
On computers as of 
2017/11/5 at 18:16:52
Last Used 
2017/11/5 at 18:16:52
Startup Item 
No
Launched 
Yes
SONAR Protection monitors for suspicious program activity on your computer.
____________________________
Tu.exe Threat name: SONAR.AM.C!g3
Locate
Few Users
Fewer than 100 users in the Norton Community have used this file.
New
This file was released 14 days ago.
High
This file risk is high.
____________________________
Source: External Media
Source File:
tu.exe
____________________________
System Settings Actions
Event: Process start (Performed by c:\program files\total uninstall 6\tu.exe, PID:1772) No fix attempted
Event: Process start: c:\program files\total uninstall 6\ Tu.exe, PID:1772 (Performed by c:\program files\total uninstall 6\tu.exe, PID:1772) No fix attempted
Event: Process start (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG:mcsmetwu (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG:tupnhdxm (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
c:\programdata\Martau\total uninstall 6\ monitored programs.folders (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
Event: Process start: c:\Windows\System32\windowspowershell\v1.0\ powershell.exe, PID:3372 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
c:\users\27526\appdata\local\temp\ __psscriptpolicytest_4lrvd2lt.n23.ps1 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
c:\users\27526\appdata\local\temp\ __psscriptpolicytest_coh1njsr.rha.psm1 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
c:\users\27526\appdata\local\temp\ tul8a31.tmp (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
c:\Users\27526\AppData\Local\microsoft\Windows\powershell\ startupprofiledata-noninteractive (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
Event: Process start: c:\Windows\System32\windowspowershell\v1.0\ powershell.exe, PID:9828 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
c:\programdata\Martau\total uninstall 6\ installed programs2.cache (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
c:\users\27526\appdata\local\temp\ __psscriptpolicytest_gdlvx3ut.x1m.ps1 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
c:\users\27526\appdata\local\temp\ __psscriptpolicytest_caotiay1.x3r.psm1 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
Event: Process start: c:\program files (x86)\Tencent\QQPinyin\5.6.4107.400\ qqpyservice.exe, PID:9800 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
c:\programdata\Martau\total uninstall 6\ installed programs3.cache (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
c:\programdata\Martau\total uninstall 6\ installed programs.folders (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
____________________________
File Thumbprint - SHA:
44ba84d6193b2b15c18146af05da336049e883f413df313fc2b7570d77f3353d
File Thumbprint - MD5:
Not available
 |