诺顿检测31个。
[mw_shl_code=html,true]Resolved Threats:
Trojan.Gen.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.5.17\24.vir - Deleted
Risks in compressed file "29.vir"
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
168 Files
[joanna.com] inside of [joanna.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jo_v111.com] inside of [jo_v111.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jo.com] inside of [jo.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-nov-30.com] inside of [j-nov-30.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-nov30.com] inside of [j-nov30.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-mule.com] inside of [j-mule.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-moctez.com] inside of [j-moctez.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-miky.com] inside of [j-miky.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-mendoz.com] inside of [j-mendoz.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-kylie.com] inside of [j-kylie.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-jvt1.com] inside of [j-jvt1.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jihuu621.com] inside of [jihuu621.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jihuu.com] inside of [jihuu.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-hk2886.exe] inside of [j-hk2886.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-hk2880.exe] inside of [j-hk2880.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-hk2358.exe] inside of [j-hk2358.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-grnl-c.com] inside of [j-grnl-c.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-grnl-b.com] inside of [j-grnl-b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-grnl-a.exe] inside of [j-grnl-a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-grlinx.com] inside of [j-grlinx.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-g1558.com] inside of [j-g1558.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-g.com] inside of [j-g.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-fumchu.com] inside of [j-fumchu.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-fri13x.com] inside of [j-fri13x.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-frerea.com] inside of [j-frerea.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-fmc-b.com] inside of [j-fmc-b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-fmc-a.com] inside of [j-fmc-a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-feb7.com] inside of [j-feb7.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-f13var.com] inside of [j-f13var.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-f13b.com] inside of [j-f13b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-f13416.com] inside of [j-f13416.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jer-var7.com] inside of [jer-var7.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jer-var6.com] inside of [jer-var6.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jer-var4.com] inside of [jer-var4.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jer-var3.com] inside of [jer-var3.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jer-var2.com] inside of [jer-var2.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jer-var1.com] inside of [jer-var1.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jerusl-b.com] inside of [jerusl-b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jerusalm.com] inside of [jerusalm.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jerusalb.com] inside of [jerusalb.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jerucarf.com] inside of [jerucarf.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jeru-b.com] inside of [jeru-b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jeru.com] inside of [jeru.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jerspain.com] inside of [jerspain.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jerk.com] inside of [jerk.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-einstn.com] inside of [j-einstn.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jeff.com] inside of [jeff.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-discom.exe] inside of [j-discom.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jd-460.com] inside of [jd-460.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jd-448.com] inside of [jd-448.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jd-392.com] inside of [jd-392.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jd-356.com] inside of [jd-356.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jd-276.com] inside of [jd-276.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jd-158a.com] inside of [jd-158a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jd_276.com] inside of [jd_276.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-czech.com] inside of [j-czech.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-cvex3.exe] inside of [j-cvex3.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-ctrip6.com] inside of [j-ctrip6.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-ctrip4.com] inside of [j-ctrip4.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-ctrip3.com] inside of [j-ctrip3.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-ctrip1.com] inside of [j-ctrip1.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-clippr.exe] inside of [j-clippr.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-carfld.com] inside of [j-carfld.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-blkfri.exe] inside of [j-blkfri.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-barcel.com] inside of [j-barcel.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jasmine.com] inside of [jasmine.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jap-xmas.com] inside of [jap-xmas.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[japxcook.com] inside of [japxcook.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[japx600f.com] inside of [japx600f.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[japx600c.com] inside of [japx600c.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[japx600b.com] inside of [japx600b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[japx600a.com] inside of [japx600a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[japx600.com] inside of [japx600.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[japan.com] inside of [japan.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-antisc.com] inside of [j-antisc.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-anark2.com] inside of [j-anark2.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[james.com] inside of [james.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jackal.com] inside of [jackal.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jack.com] inside of [jack.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[jabb812.com] inside of [jabb812.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j4j.com] inside of [j4j.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-2187.com] inside of [j-2187.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-1960.com] inside of [j-1960.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-1767.com] inside of [j-1767.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-1361.com] inside of [j-1361.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j13-1201.exe] inside of [j13-1201.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j-1244.com] inside of [j-1244.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_ten.com] inside of [j_ten.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_satan.com] inside of [j_satan.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_o.com] inside of [j_o.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_nai_ta.com] inside of [j_nai_ta.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_l.com] inside of [j_l.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_k.com] inside of [j_k.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_ii-b.com] inside of [j_ii-b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_ii-a.com] inside of [j_ii-a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_f.com] inside of [j_f.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_e.com] inside of [j_e.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_d.exe] inside of [j_d.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_c.com] inside of [j_c.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_b.com] inside of [j_b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_a.exe] inside of [j_a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_1813.com] inside of [j_1813.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_1720.com] inside of [j_1720.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j_1600.com] inside of [j_1600.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j&1489.exe] inside of [j&1489.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j&1399.exe] inside of [j&1399.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j&1364b.exe] inside of [j&1364b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j&1364a.exe] inside of [j&1364a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j#scott.com] inside of [j#scott.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j#aus-a.com] inside of [j#aus-a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!umsdos.com] inside of [j!umsdos.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!triple.com] inside of [j!triple.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!swiss.exe] inside of [j!swiss.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!sum-ao.com] inside of [j!sum-ao.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!sum-al.com] inside of [j!sum-al.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!standa.com] inside of [j!standa.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!spanis.com] inside of [j!spanis.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!skism.com] inside of [j!skism.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!puerto.exe] inside of [j!puerto.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!phenom.com] inside of [j!phenom.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!period.com] inside of [j!period.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!pay-d.com] inside of [j!pay-d.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!pay-c.com] inside of [j!pay-c.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!pay-b.com] inside of [j!pay-b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!pay-a.com] inside of [j!pay-a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!p.com] inside of [j!p.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!nul-a.com] inside of [j!nul-a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!new9.com] inside of [j!new9.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!new3.com] inside of [j!new3.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!new1.com] inside of [j!new1.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!nemesi.com] inside of [j!nemesi.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!messin.com] inside of [j!messin.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!mendoz.com] inside of [j!mendoz.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!jvt1.com] inside of [j!jvt1.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!jan_25.exe] inside of [j!jan_25.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!fri_15.exe] inside of [j!fri_15.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!fre-j.com] inside of [j!fre-j.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!fre-c.com] inside of [j!fre-c.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!fre-b.com] inside of [j!fre-b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!fre-a.com] inside of [j!fre-a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!flagee.com] inside of [j!flagee.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!feb_7.com] inside of [j!feb_7.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!czech.com] inside of [j!czech.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ct-ski.com] inside of [j!ct-ski.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ct-sk9.com] inside of [j!ct-sk9.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ct-sba.com] inside of [j!ct-sba.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ct-i.com] inside of [j!ct-i.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ct-h.com] inside of [j!ct-h.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ct-g.com] inside of [j!ct-g.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ct-f.com] inside of [j!ct-f.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ct-e.com] inside of [j!ct-e.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ct-d.com] inside of [j!ct-d.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ct-c.com] inside of [j!ct-c.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ct-b.com] inside of [j!ct-b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ct-a.com] inside of [j!ct-a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!critic.com] inside of [j!critic.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!cnder.com] inside of [j!cnder.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!blanka.com] inside of [j!blanka.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!apocaa.com] inside of [j!apocaa.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ank-c.com] inside of [j!ank-c.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ank-b.com] inside of [j!ank-b.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!ank-a.com] inside of [j!ank-a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!a-204a.com] inside of [j!a-204a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!a.com] inside of [j!a.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!3503.com] inside of [j!3503.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!1d7f.com] inside of [j!1d7f.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!0ffd.com] inside of [j!0ffd.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
[j!052f.com] inside of [j!052f.zip] inside of [e:\virus\huge\2015.5.17\29.vir] - Fully Resolved
SAPE.Bladabindi.19
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.5.17\11.vir - Deleted
1 Browser Cache
Downloader
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.5.17\12.vir - Deleted
1 Browser Cache
W32.Spybot.Worm
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Restart Required
-----------
51 Registry Entries
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunServices\->Firewall Controls - Restart Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\RunServices\->Firewall Controls - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunServices\->Firewall Controls - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunServices\->Firewall Controls - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\->Firewall Controls - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\->246545 - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\->665578 - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\->7686743 - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\->rrrun - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Microsoft Visual Application - Restart Required
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\->C:\WINDOWS\system32\dllcache\winsno.exe - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunServices\->ATI Video Driver Controls - Restart Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\RunServices\->ATI Video Driver Controls - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunServices\->ATI Video Driver Controls - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunServices\->ATI Video Driver Controls - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunServices\->Microsoft Directxsp - Restart Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\RunServices\->Microsoft Directxsp - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunServices\->Microsoft Directxsp - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunServices\->Microsoft Directxsp - Restart Required
HKEY_CLASSES_ROOT\CLSID\{1C047C97-CA7F-BAF1-05A4-AEBA271281ED} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\->ATI Video Driver Controls - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\->Microsoft Directxsp - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->ATI Video Driver Controls - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Microsoft Directxsp - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\->1123 - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\->112 - Restart Required
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\->Start:4 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry->Start:2 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusOverride:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->FirewallOverride:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\->Shell:Explorer.exe - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr->Start:3 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole->EnableDCOM:Y - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->UpdatesDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control->WaitToKillServiceTimeout:20000 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon->SFCDisable:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa->restrictanonymous:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ccEvtMgr->Start:2 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ccSetMgr->Start:2 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\navapsvc->Start:3 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVRT->Start:3 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVRTPEL->Start:1 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NAVENG->Start:3 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NAVEX15->Start:3 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SymEvent->Start:3 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\->TransportBindName:\Device\ - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\->Start:2 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableRegistryTools:0 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableTaskMgr:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->FirewallDisableNotify:0 - Repaired
12 Files
C:\Users\winter0614\AppData\Local\Temp\1.reg - Restart Required
C:\Users\winter0614\AppData\Local\Temp\sysremove.bat - Restart Required
C:\a.bat - Restart Required
e:\virus\huge\2015.5.17\03.vir - Deleted
e:\virus\huge\2015.5.17\08.vir - Deleted
e:\virus\huge\2015.5.17\09.vir - Deleted
e:\virus\huge\2015.5.17\05.vir - Deleted
e:\virus\huge\2015.5.17\28.vir - Deleted
e:\virus\huge\2015.5.17\42.vir - Deleted
e:\virus\huge\2015.5.17\36.vir - Deleted
e:\virus\huge\2015.5.17\50.vir - Deleted
e:\virus\huge\2015.5.17\30.vir - Deleted
1 Browser Cache
W32.Whybo.Z
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
9 Registry Entries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon->Userinit:C:\WINDOWS\SysWOW64\userinit.exe, - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main->Start Page:http://www.symantec.com/redirect ... &pvid=22.2.0.31 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Internet Explorer\Main->Start Page:http://www.symantec.com/redirect ... &pvid=22.2.0.31 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main->Start Page:http://www.symantec.com/redirect ... &pvid=22.2.0.31 - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main->Start Page:http://www.symantec.com/redirect ... &pvid=22.2.0.31 - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1 - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1 - Repaired
1 File
e:\virus\huge\2015.5.17\04.vir - Deleted
1 Browser Cache
W32.IRCbot
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
126 Registry Entries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->UacDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess->Start:2 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->FirewallDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->UpdatesDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows->DisableSR:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa->restrictanonymous:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa->AUOptions:3 - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Security Center->FirewallDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Security Center->FirewallDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Security Center->FirewallDisableNotify:0 - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Security Center->FirewallDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Security Center->UpdatesDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Security Center->UpdatesDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Security Center->UpdatesDisableNotify:0 - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Security Center->UpdatesDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Security Center->AntiVirusDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Security Center->AntiVirusDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Security Center->AntiVirusDisableNotify:0 - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Security Center->AntiVirusDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusOverride:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->FirewallOverride:0 - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows->DisableSR:0 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows NT\CurrentVersion\Windows->DisableSR:0 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows->DisableSR:0 - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Windows->DisableSR:0 - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1 - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc->AntiVirusDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\->FirewallDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\->UpdatesDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\->AntiVirusOverride:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\->FirewallOverride:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\->FirstRunDisabled:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\->UacDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->SuperHidden:1 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->SuperHidden:1 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->SuperHidden:1 - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->SuperHidden:1 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess->Type:32 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc->Type:32 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv->Type:32 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{23KLN5J0-4OPM-11WE-AAX5-24EF1D187332} - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\->Windows唀瀀搀愀琀攀猀 - No Action Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Run\->Windows唀瀀搀愀琀攀猀 - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\->Windows唀瀀搀愀琀攀猀 - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\->Windows唀瀀搀愀琀攀猀 - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Windows唀瀀搀愀琀攀猀 - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->windows?updates - No Action Required
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Windows?Updates - No Action Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Windows?Updates - No Action Required
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Windows?Updates - No Action Required
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Windows?Updates - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Startup Cleaner Service - No Action Required
HKEY_USERS\S-1-5-19\Software\VB and VBA Program Settings\rn1 - No Action Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\VB and VBA Program Settings\rn1 - No Action Required
HKEY_USERS\S-1-5-20\Software\VB and VBA Program Settings\rn1 - No Action Required
HKEY_USERS\.DEFAULT\Software\VB and VBA Program Settings\rn1 - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612} - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run->LSA Shellu - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run->NvGraphicsInterface - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run->outlook - No Action Required
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List->1024:TCP - No Action Required
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List->1900:UDP - No Action Required
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List->2869:TCP - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\HWyYjqbH - No Action Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\HWyYjqbH - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\HWyYjqbH - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\HWyYjqbH - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Windows Logon Application - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Application Layer Gateway Service - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Local Security Authority Service - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Spooler SubSystem App - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Winamp Agent - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Windows Explorer - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Microsoft Internet Explorer - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunServices\->Server Runtime Process - No Action Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\RunServices\->Server Runtime Process - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunServices\->Server Runtime Process - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunServices\->Server Runtime Process - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\->Server Runtime Process - No Action Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Run\->Server Runtime Process - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\->Server Runtime Process - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\->Server Runtime Process - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\->Server Runtime Process - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\->Server Runtime Process - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Server Runtime Process - No Action Required
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\->C:\WINDOWS\sysdiag64.exe - No Action Required
HKEY_CLASSES_ROOT\exefile\->NeverShowExt - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Acha.exe - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AmyMastura.exe - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BabyRina.exe - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SMSSS.exe - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cscript.exe - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csrsz.exe - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsasc.exe - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\registry.exe - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscript.exe - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon->Shell - No Action Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon->Shell - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon->Shell - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon->Shell - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{12LOP3S8-1VRX-81VS-JKL6-61OP5G7774441} - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67KLN5J0-4OPM-00WE-AAX5-14KC2A323342} - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components\{12LOP3S8-1VRX-81VS-JKL6-61OP5G7774441} - No Action Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Active Setup\Installed Components\{12LOP3S8-1VRX-81VS-JKL6-61OP5G7774441} - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components\{12LOP3S8-1VRX-81VS-JKL6-61OP5G7774441} - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components\{12LOP3S8-1VRX-81VS-JKL6-61OP5G7774441} - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components\{67KLN5J0-4OPM-00WE-AAX5-14KC2A323342} - No Action Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Active Setup\Installed Components\{67KLN5J0-4OPM-00WE-AAX5-14KC2A323342} - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components\{67KLN5J0-4OPM-00WE-AAX5-14KC2A323342} - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components\{67KLN5J0-4OPM-00WE-AAX5-14KC2A323342} - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\->WMISYswewe - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU->NoAutoUpdate:0 - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU->AUOptions:3 - No Action Required
HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Windows\WindowsUpdate\AU->NoAutoUpdate:0 - No Action Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Policies\Microsoft\Windows\WindowsUpdate\AU->NoAutoUpdate:0 - No Action Required
HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Windows\WindowsUpdate\AU->NoAutoUpdate:0 - No Action Required
HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Windows\WindowsUpdate\AU->NoAutoUpdate:0 - No Action Required
HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Windows\WindowsUpdate\AU->AUOptions:3 - No Action Required
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Policies\Microsoft\Windows\WindowsUpdate\AU->AUOptions:3 - No Action Required
HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Windows\WindowsUpdate\AU->AUOptions:3 - No Action Required
HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Windows\WindowsUpdate\AU->AUOptions:3 - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\->UncheckedValue:1 - No Action Required
86 Files
c:\users\winter0614\appdata\local\temp\~df328b5d3646b2d691.tmp - Deleted
c:\users\winter0614\appdata\local\temp\~df465a643acee747a3.tmp - Deleted
c:\users\winter0614\appdata\local\temp\~dfaefc187ff5eaa84f.tmp - Deleted
C:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\outlook\p.zip - No Action Required
C:\Program Files (x86)\outlook\p.zip - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\microsoft office\office11\control.ini - No Action Required
C:\Program Files (x86)\Microsoft Office\OFFICE11\control.ini - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\microsoft office\office11\drvics32.dll - No Action Required
C:\Program Files (x86)\Microsoft Office\OFFICE11\Drvics32.dll - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\microsoft office\office11\hjwgsd.dll - No Action Required
C:\Program Files (x86)\Microsoft Office\OFFICE11\hjwgsd.dll - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\microsoft office\office11\jwiegh.dll - No Action Required
C:\Program Files (x86)\Microsoft Office\OFFICE11\jwiegh.dll - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\microsoft office\office11\pub60sp.mrc - No Action Required
C:\Program Files (x86)\Microsoft Office\OFFICE11\PUB60SP.mrc - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\microsoft office\office11\remote.ini - No Action Required
C:\Program Files (x86)\Microsoft Office\OFFICE11\remote.ini - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\microsoft office\office11\ruimsbbe.dll - No Action Required
C:\Program Files (x86)\Microsoft Office\OFFICE11\ruimsbbe.dll - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\microsoft office\office11\yofc.dll - No Action Required
C:\Program Files (x86)\Microsoft Office\OFFICE11\yofc.dll - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\1661724784.dat - No Action Required
C:\WINDOWS\SysWOW64\1661724784.dat - No Action Required
C:\RESTORE\k-1-3542-4232123213-7676767-8888886\Desktop.ini - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\mirc\irc bot\anjing_malingsia.sys - No Action Required
C:\Program Files (x86)\mIRC\IRC Bot\Anjing_Malingsia.sys - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\mirc\irc bot\asshole.sys - No Action Required
C:\Program Files (x86)\mIRC\IRC Bot\Asshole.sys - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\mirc\irc bot\channel_babi.sys - No Action Required
C:\Program Files (x86)\mIRC\IRC Bot\Channel_Babi.sys - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\mirc\irc bot\control.ini - No Action Required
C:\Program Files (x86)\mIRC\IRC Bot\control.ini - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\mirc\irc bot\fuck.sys - No Action Required
C:\Program Files (x86)\mIRC\IRC Bot\fuck.sys - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\mirc\irc bot\kontol.mrc - No Action Required
C:\Program Files (x86)\mIRC\IRC Bot\kontol.mrc - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\mirc\irc bot\nama_anjing.sys - No Action Required
C:\Program Files (x86)\mIRC\IRC Bot\Nama_Anjing.sys - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\mirc\irc bot\nama_babi.sys - No Action Required
C:\Program Files (x86)\mIRC\IRC Bot\Nama_Babi.sys - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\mirc\irc bot\perampok_budaya.sys - No Action Required
C:\Program Files (x86)\mIRC\IRC Bot\perampok_budaya.sys - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\mirc\irc bot\remote.ini - No Action Required
C:\Program Files (x86)\mIRC\IRC Bot\remote.ini - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\mirc\irc bot\stupid.sys - No Action Required
C:\Program Files (x86)\mIRC\IRC Bot\Stupid.sys - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\program files (x86)\mirc\irc bot\svchost.exe - No Action Required
C:\Program Files (x86)\mIRC\IRC Bot\svchost.exe - No Action Required
C:\SYSTEM\FILES\Desktop.ini - No Action Required
C:\WIN\DOWS\desKtOp.InI - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\0004d5f4.sys - No Action Required
C:\WINDOWS\SysWOW64\0004d5f4.sys - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\adri4n.memory - No Action Required
C:\WINDOWS\SysWOW64\nvidia\Adri4n.memory - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\ady.memory - No Action Required
C:\WINDOWS\SysWOW64\nvidia\ady.memory - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\dchelp.memory - No Action Required
C:\WINDOWS\SysWOW64\nvidia\dchelp.memory - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\emech1.users - No Action Required
C:\WINDOWS\SysWOW64\nvidia\emech1.users - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\emech2.users - No Action Required
C:\WINDOWS\SysWOW64\nvidia\emech2.users - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\emech3.users - No Action Required
C:\WINDOWS\SysWOW64\nvidia\emech3.users - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\emech4.users - No Action Required
C:\WINDOWS\SysWOW64\nvidia\emech4.users - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\mech.levels - No Action Required
C:\WINDOWS\SysWOW64\nvidia\mech.levels - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\mech.pid - No Action Required
C:\WINDOWS\SysWOW64\nvidia\mech.pid - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\mech.set - No Action Required
C:\WINDOWS\SysWOW64\nvidia\mech.set - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\mech.usage - No Action Required
C:\WINDOWS\SysWOW64\nvidia\mech.usage - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\paul.memory - No Action Required
C:\WINDOWS\SysWOW64\nvidia\Paul.memory - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\sytes.memory - No Action Required
C:\WINDOWS\SysWOW64\nvidia\sytes.memory - No Action Required
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\nvidia\versions - No Action Required
C:\WINDOWS\SysWOW64\nvidia\VERSIONS - No Action Required
e:\virus\huge\2015.5.17\16.vir - Deleted
e:\virus\huge\2015.5.17\09.vir - No Action Required
e:\virus\huge\2015.5.17\27.vir - Deleted
e:\virus\huge\2015.5.17\37.vir - Deleted
e:\virus\huge\2015.5.17\47.vir - Deleted
1 Service
Spoolsv - No Action Required
135 Host File Entries
127.0.0.1:Merijn.org - No Action Required
127.0.0.1:www.Merijn.org - No Action Required
127.0.0.1:www.spywareinfo.com - No Action Required
127.0.0.1:spywareinfo.com - No Action Required
127.0.0.1:www.spybot.info - No Action Required
127.0.0.1:spybot.info - No Action Required
127.0.0.1:www.viruslist.com - No Action Required
127.0.0.1:viruslist.com - No Action Required
127.0.0.1:www.hijackthis.de - No Action Required
127.0.0.1:hijackthis.de - No Action Required
127.0.0.1:www.majorgeeks.com - No Action Required
127.0.0.1:majorgeeks.com - No Action Required
127.0.0.1:www.virustotal.com - No Action Required
127.0.0.1:virustotal.com - No Action Required
127.0.0.1:kaspersky.com - No Action Required
127.0.0.1:kaspersky-labs.com - No Action Required
127.0.0.1:www.kaspersky.com - No Action Required
127.0.0.1:www.sophos.com - No Action Required
127.0.0.1:sophos - No Action Required
127.0.0.1:securityresponse.symantec.com - No Action Required
127.0.0.1:symantec.com - No Action Required
127.0.0.1:www.symantec.com - No Action Required
127.0.0.1:updates.symantec.com - No Action Required
127.0.0.1:liveupdate.symantecliveupdate.com - No Action Required
127.0.0.1:liveupdate.symantec.com - No Action Required
127.0.0.1:customer.symantec.com - No Action Required
127.0.0.1:update.symantec.com - No Action Required
127.0.0.1:www.mcafee.com - No Action Required
127.0.0.1:mcafee.com - No Action Required
127.0.0.1:rads.mcafee.com - No Action Required
127.0.0.1:mast.mcafee.com - No Action Required
127.0.0.1:download.mcafee.com - No Action Required
127.0.0.1:dispatch.mcafee.com - No Action Required
127.0.0.1:us.mcafee.com - No Action Required
127.0.0.1:www.trendsecure.com - No Action Required
127.0.0.1:trendsecure.com - No Action Required
127.0.0.1:www.avp.com - No Action Required
127.0.0.1:avp.com - No Action Required
127.0.0.1:analysis.seclab.tuwien.ac.at - No Action Required
127.0.0.1:www.bleepingcomputer.com - No Action Required
127.0.0.1:bleepingcomputer.com - No Action Required
127.0.0.1:guru0.grisoft.cz - No Action Required
127.0.0.1:guru1.grisoft.cz - No Action Required
127.0.0.1:guru2.grisoft.cz - No Action Required
127.0.0.1:guru3.grisoft.cz - No Action Required
127.0.0.1:guru4.grisoft.cz - No Action Required
127.0.0.1:guru5.grisoft.cz - No Action Required
127.0.0.1:download.f-secure.com - No Action Required
127.0.0.1:www.download.f-secure.com - No Action Required
127.0.0.1:avg-antivirus.net - No Action Required
127.0.0.1:www.avg-antivirus.net - No Action Required
127.0.0.1:f-secure.com - No Action Required
127.0.0.1:www.f-secure.com - No Action Required
127.0.0.1:free.grisoft.com - No Action Required
127.0.0.1:www.free.grisoft.com - No Action Required
127.0.0.1:free.avg.com - No Action Required
127.0.0.1:www.free.avg.com - No Action Required
127.0.0.1:avast.com - No Action Required
127.0.0.1:www.avast.com - No Action Required
127.0.0.1:onlinescan.avast.com - No Action Required
127.0.0.1:www.onlinescan.avast.com - No Action Required
127.0.0.1:housecall.trendmicro.com - No Action Required
127.0.0.1:www.housecall.trendmicro.com - No Action Required
127.0.0.1:bitdefender.com - No Action Required
127.0.0.1:www.bitdefender.com - No Action Required
127.0.0.1:futurenow.bitdefender.com - No Action Required
127.0.0.1:www.futurenow.bitdefender.com - No Action Required
127.0.0.1:f-prot.com - No Action Required
127.0.0.1:www.f-prot.com - No Action Required
127.0.0.1:eset.com - No Action Required
127.0.0.1:www.eset.com - No Action Required
127.0.0.1:free-av.com - No Action Required
127.0.0.1:www.free-av.com - No Action Required
127.0.0.1:avira.com - No Action Required
127.0.0.1:www.avira.com - No Action Required
127.0.0.1:antivir.es - No Action Required
127.0.0.1:www.antivir.es - No Action Required
127.0.0.1:ikarus.net - No Action Required
127.0.0.1:www.ikarus.net - No Action Required
127.0.0.1:prevx.com - No Action Required
127.0.0.1:www.prevx.com - No Action Required
127.0.0.1:2-spyware.com - No Action Required
127.0.0.1:www.2-spyware.com - No Action Required
127.0.0.1:castlecops.com - No Action Required
127.0.0.1:www.castlecops.com - No Action Required
127.0.0.1:virusinfo.prevx.com - No Action Required
127.0.0.1:www.virusinfo.prevx.com - No Action Required
127.0.0.1:forums.majorgeeks.com - No Action Required
127.0.0.1:www.forums.majorgeeks.com - No Action Required
127.0.0.1:eradicatespyware.net - No Action Required
127.0.0.1:www.eradicatespyware.net - No Action Required
127.0.0.1:fortinet.com - No Action Required
127.0.0.1:www.fortinet.com - No Action Required
127.0.0.1:fortiguardcenter.com - No Action Required
127.0.0.1:www.fortiguardcenter.com - No Action Required
127.0.0.1:trendmicro.com - No Action Required
127.0.0.1:www.trendmicro.com - No Action Required
127.0.0.1:www.safer-networking.org - No Action Required
127.0.0.1:safer-networking.org - No Action Required
127.0.0.1:auditmypc.com - No Action Required
127.0.0.1:www.auditmypc.com - No Action Required
127.0.0.1:pctools.com - No Action Required
127.0.0.1:www.pctools.com - No Action Required
127.0.0.1:firewallguide.com - No Action Required
127.0.0.1:www.firewallguide.com - No Action Required
127.0.0.1:spywaredb.com - No Action Required
127.0.0.1:www.spywaredb.com - No Action Required
127.0.0.1:virusspy.com - No Action Required
127.0.0.1:www.virusspy.com - No Action Required
127.0.0.1:spywareterminator.com - No Action Required
127.0.0.1:www.spywareterminator.com - No Action Required
127.0.0.1:freespywareremoval.info - No Action Required
127.0.0.1:www.freespywareremoval.info - No Action Required
127.0.0.1:antivirus.about.com - No Action Required
127.0.0.1:www.antivirus.about.com - No Action Required
127.0.0.1:antivirus.comodo.com - No Action Required
127.0.0.1:www.antivirus.comodo.com - No Action Required
127.0.0.1:clamav.net - No Action Required
127.0.0.1:www.clamav.net - No Action Required
127.0.0.1:pandasecurity.com - No Action Required
127.0.0.1:www.pandasecurity.com - No Action Required
127.0.0.1:clamwin.com - No Action Required
127.0.0.1:www.clamwin.com - No Action Required
127.0.0.1:shop.symantecstore.com - No Action Required
127.0.0.1:www.shop.symantecstore.com - No Action Required
127.0.0.1:shop.ca.com - No Action Required
127.0.0.1:www.shop.ca.com - No Action Required
127.0.0.1:ca.com - No Action Required
127.0.0.1:www.ca.com - No Action Required
127.0.0.1:networkworld.com - No Action Required
127.0.0.1:www.networkworld.com - No Action Required
127.0.0.1:norman.com - No Action Required
127.0.0.1:www.norman.com - No Action Required
127.0.0.1:grisoft.com - No Action Required
127.0.0.1:www.grisoft.com - No Action Required
1 Browser Cache
SAPE.Xtrat.1
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.5.17\10.vir - Deleted
1 Browser Cache
Trojan Horse
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
2 Files
e:\virus\huge\2015.5.17\18.vir - Deleted
e:\virus\huge\2015.5.17\44.vir - Deleted
1 Browser Cache
Backdoor.Ratenjay
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
3 Files
e:\virus\huge\2015.5.17\20.vir - Deleted
e:\virus\huge\2015.5.17\40.vir - Deleted
e:\virus\huge\2015.5.17\31.vir - Deleted
1 Browser Cache
SAPE.SMSHoax.17
Type: Anomaly
Risk: Low (Low Stealth, Low Removal, Low Performance, Low Privacy)
Categories: Adware
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.5.17\22.vir - Deleted
1 Browser Cache
PUA.Gen.2
Type: Anomaly
Risk: Low (Low Stealth, Low Removal, Low Performance, Low Privacy)
Categories: Security Risk
Status: Excluded
-----------
1 File
e:\virus\huge\2015.5.17\22.vir - Excluded
1 Browser Cache
Trojan.Gen.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.5.17\06.vir - Deleted
1 Browser Cache
Suspicious.MH690
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.5.17\34.vir - Deleted
1 Browser Cache
Trojan.Klovbot
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Restart Required
-----------
14 Registry Entries
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Internet Explorer\New Windows\->PopupMgr:yes - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System->DisableRegistryTools:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->UpdatesDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableTaskMgr:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\->Start:2 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NofolderOptions:0 - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Repaired
HKEY_USERS\S-1-5-21-199303550-3880348569-3445812084-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\New Windows\->PopupMgr:yes - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\New Windows\->PopupMgr:yes - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\New Windows\->PopupMgr:yes - Repaired
3 Files
C:\Users\winter0614\AppData\Local\virtualstore\windows\syswow64\installed.dat - Restart Required
C:\WINDOWS\SysWOW64\Installed.dat - Restart Required
e:\virus\huge\2015.5.17\35.vir - Deleted
1 Browser Cache
1 System Action
Trojan.Ducky.B
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.5.17\27.vir - No Action Required
1 Browser Cache
Trojan.Gen
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.5.17\25.vir - Deleted
1 Browser Cache
Suspicious.MH690.A
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.5.17\48.vir - Deleted
1 Browser Cache[/mw_shl_code] |