本帖最后由 wywt123 于 2024-8-7 23:30 编辑
- 13:38:23.753 0x30ec INF aveng [CTX:0x16457FE8] Context initialized : 0xc0102
- 13:38:23.753 0x4344 INF aveng DH: BSS, PDM:Trojan.Win32.Generic, [#311656], ert: 0, rt: 0x56010000, dg: 0, cf: 2, blck: 0, fs: 74582872, mm: AB751E69FCF50DAFDF0FF5F9C48BF5FF, ms2: 75AC5E7738BA038640AA119FC935146E776CF513193767246BE29EF149D85B7D, fp: c:\users\admin\downloads\1\sunloginclient_15.6.8.14962_x64.exe, dbt: 0x1dae8abacfa7e00 (2024.08.07 09:25:00:000), lus: pub
- 13:38:23.753 0x30ec INF aveng SafeScan State:1 Policy:0
- 13:38:23.753 0x4344 INF aveng bss: #66535(129): #PDMBssDetect("PDM:Trojan.Win32.Generic",311656,2,0);
- 13:38:23.753 0x30ec INF aveng [PJIM] PSP
- 13:38:23.753 0x30ec INF aveng [PJIM] pp-e
- 13:38:23.753 0x4344 DBG sw2 sw::bss::ScanContextInfo::AddMessageToLogWithPriority timeout: 0, priority: 0
- 13:38:23.753 0x30ec INF aveng [CTX:0x16457FE8] PP buf=0x00000000 size=0x00000000 flags=0x00000001 fmt=0x00000000 result=0x00000000
- 13:38:23.753 0x4344 INF sw2 sw::bss2::ContextMessages::AddMessage ctx: 992, priority: 0
- 13:38:23.753 0x4344 INF aveng VDM RMS-ON PDM:Trojan.Win32.Generic:311656 MD:1
- 13:38:23.753 0x4344 INF sw2 sw::bss::ContextInfo::GetProcess 6724
- 13:38:23.753 0x4344 INF sw2 sw::bss::ContextInfo::GetProcessByUniquePid uniquePid: e41e4e312e4e6ef2
- 13:38:23.753 0x4344 INF sw2 sw::bss::ContextInfo::GetProcess 6724
- 13:38:23.753 0x4344 DBG sw2 sw::bss::ScanContextInfo::AddMessageToLogWithPriority timeout: 0, priority: 0
- 13:38:23.753 0x4344 INF sw2 sw::bss2::ContextMessages::AddMessage ctx: 202, priority: 0
复制代码Hello,
Your request is processing.
Thank you for your inquiry to Kaspersky.
Best regards, Ilya, Malware Analyst, Kaspersky
确实被PDM干了,给毛子扔了个trace过去,后续看看咋回复
|