本帖最后由 ak666 于 2017-11-5 18:21 编辑
之前有个叫什么eGambit什么的报毒,就他一个。现在看来是没问题了,用破解软件,心里总是不踏实。。
用ssf,总是监控到要键盘记录。。===============================
- Filename: Tu.exe
- Threat name: SONAR.AM.C!g3Full Path: c:\program files\total uninstall 6\tu.exe
- ____________________________
- ____________________________
- On computers as of
- 2017/11/5 at 18:16:52
- Last Used
- 2017/11/5 at 18:16:52
- Startup Item
- No
- Launched
- Yes
- SONAR Protection monitors for suspicious program activity on your computer.
- ____________________________
- Tu.exe Threat name: SONAR.AM.C!g3
- Locate
- Few Users
- Fewer than 100 users in the Norton Community have used this file.
- New
- This file was released 14 days ago.
- High
- This file risk is high.
- ____________________________
- Source: External Media
- Source File:
- tu.exe
- ____________________________
- System Settings Actions
- Event: Process start (Performed by c:\program files\total uninstall 6\tu.exe, PID:1772) No fix attempted
- Event: Process start: c:\program files\total uninstall 6\ Tu.exe, PID:1772 (Performed by c:\program files\total uninstall 6\tu.exe, PID:1772) No fix attempted
- Event: Process start (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG:mcsmetwu (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG:tupnhdxm (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- c:\programdata\Martau\total uninstall 6\ monitored programs.folders (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- Event: Process start: c:\Windows\System32\windowspowershell\v1.0\ powershell.exe, PID:3372 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- c:\users\27526\appdata\local\temp\ __psscriptpolicytest_4lrvd2lt.n23.ps1 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- c:\users\27526\appdata\local\temp\ __psscriptpolicytest_coh1njsr.rha.psm1 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- c:\users\27526\appdata\local\temp\ tul8a31.tmp (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- c:\Users\27526\AppData\Local\microsoft\Windows\powershell\ startupprofiledata-noninteractive (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- Event: Process start: c:\Windows\System32\windowspowershell\v1.0\ powershell.exe, PID:9828 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- c:\programdata\Martau\total uninstall 6\ installed programs2.cache (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- c:\users\27526\appdata\local\temp\ __psscriptpolicytest_gdlvx3ut.x1m.ps1 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- c:\users\27526\appdata\local\temp\ __psscriptpolicytest_caotiay1.x3r.psm1 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- Event: Process start: c:\program files (x86)\Tencent\QQPinyin\5.6.4107.400\ qqpyservice.exe, PID:9800 (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- c:\programdata\Martau\total uninstall 6\ installed programs3.cache (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- c:\programdata\Martau\total uninstall 6\ installed programs.folders (Performed by c:\program files\total uninstall 6\tu.exe, PID:4512) No fix attempted
- ____________________________
- File Thumbprint - SHA:
- 44ba84d6193b2b15c18146af05da336049e883f413df313fc2b7570d77f3353d
- File Thumbprint - MD5:
- Not available
复制代码
|