本帖最后由 欧阳宣 于 2015-8-1 12:28 编辑
norton
扫描检测18个,剩余有请双击党。
[mw_shl_code=css,true]Resolved Threats:
Trojan Horse
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.8.1\11.vir - Deleted
Risks in compressed file "32.vir"
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
7 Files
[sc2.dll] inside of [e:\virus\huge\2015.8.1\32.vir] - Fully Resolved
[pw.dll] inside of [e:\virus\huge\2015.8.1\32.vir] - Fully Resolved
[mic.dll] inside of [e:\virus\huge\2015.8.1\32.vir] - Fully Resolved
[fm.dll] inside of [e:\virus\huge\2015.8.1\32.vir] - Fully Resolved
[ch.dll] inside of [e:\virus\huge\2015.8.1\32.vir] - Fully Resolved
[cam.dll] inside of [e:\virus\huge\2015.8.1\32.vir] - Fully Resolved
[njrat.exe] inside of [e:\virus\huge\2015.8.1\32.vir] - Fully Resolved
W97M.Downloader
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
4 Files
e:\virus\huge\2015.8.1\07.vir - Deleted
e:\virus\huge\2015.8.1\06.vir - Deleted
e:\virus\huge\2015.8.1\30.vir - Deleted
e:\virus\huge\2015.8.1\13.vir - Deleted
1 Browser Cache
Trojan.Zbot
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Restart Required
-----------
41 Registry Entries
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\gHcq8R9 - Restart Required
HKEY_USERS\S-1-5-19\Software\gHcq8R9 - Restart Required
HKEY_USERS\S-1-5-20\Software\gHcq8R9 - Restart Required
HKEY_USERS\.DEFAULT\Software\gHcq8R9 - Restart Required
HKEY_CLASSES_ROOT\CLSID\{DE7CBE17-0368-40E2-8357-1639DA027BAB} - Restart Required
HKEY_CLASSES_ROOT\PPT_Test.Application - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon->Userinit:C:\WINDOWS\SysWOW64\userinit.exe, - Restart Required
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\Microsoft\Windows\CurrentVersion\Run->userinit - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run->userinit - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run->userinit - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run->userinit - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion->Win32 - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network->UID - Restart Required
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network->UID - Restart Required
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network->UID - Restart Required
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network->UID - Restart Required
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network->UID - Restart Required
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\{19127AD2-394B-70F5-C650-B97867BAA1F7} - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\{19127AD2-394B-70F5-C650-B97867BAA1F7} - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\{19127AD2-394B-70F5-C650-B97867BAA1F7} - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{19127AD2-394B-70F5-C650-B97867BAA1F7} - Restart Required
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\{35106240-D2F0-DB35-716E-127EB80A0299} - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\{35106240-D2F0-DB35-716E-127EB80A0299} - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\{35106240-D2F0-DB35-716E-127EB80A0299} - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{35106240-D2F0-DB35-716E-127EB80A0299} - Restart Required
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} - Restart Required
HKEY_CLASSES_ROOT\Cad.Document - Restart Required
HKEY_CLASSES_ROOT\.max - Restart Required
HKEY_CLASSES_ROOT\.max - Restart Required
HKEY_CLASSES_ROOT\Matrix.Document - Restart Required
HKEY_CLASSES_ROOT\Matrix.Document - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.max - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Matrix.Document - Restart Required
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableTaskMgr:0 - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableTaskMgr:0 - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableTaskMgr:0 - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableTaskMgr:0 - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system->EnableLUA:1 - Restart Required
9 Files
C:\Users\jeff6\AppData\Local\virtualstore\windows\syswow64\ntos.exe - Restart Required
C:\WINDOWS\SysWOW64\ntos.exe - Restart Required
C:\Users\jeff6\AppData\Local\virtualstore\windows\syswow64\wsnpoem\audio.dll - Restart Required
C:\WINDOWS\SysWOW64\wsnpoem\audio.dll - Restart Required
C:\Users\jeff6\AppData\Local\virtualstore\windows\syswow64\wsnpoem\video.dll - Restart Required
C:\WINDOWS\SysWOW64\wsnpoem\video.dll - Restart Required
C:\Users\jeff6\AppData\Local\virtualstore\windows\syswow64\wsnpoem - Restart Required
C:\WINDOWS\SysWOW64\wsnpoem - Restart Required
e:\virus\huge\2015.8.1\03.vir - Deleted
1 Browser Cache
Trojan.Gen
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
5 Files
e:\virus\huge\2015.8.1\02.vir - Deleted
e:\virus\huge\2015.8.1\23.vir - Deleted
e:\virus\huge\2015.8.1\43.vir - Deleted
e:\virus\huge\2015.8.1\46.vir - Deleted
e:\virus\huge\2015.8.1\33.vir - Deleted
1 Browser Cache
W32.Spyrat
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Restart Required
-----------
22 Registry Entries
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\INFCT K.L - Restart Required
HKEY_USERS\S-1-5-19\Software\INFCT K.L - Restart Required
HKEY_USERS\S-1-5-20\Software\INFCT K.L - Restart Required
HKEY_USERS\.DEFAULT\Software\INFCT K.L - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{XHIY7M7P-0CD3-6O7E-G1JR-5IQV0C3J3D2P} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5257J270-BCY8-B212-I8RM-O658CNV82K28} - Restart Required
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\Louka78 - Restart Required
HKEY_USERS\S-1-5-19\Software\Louka78 - Restart Required
HKEY_USERS\S-1-5-20\Software\Louka78 - Restart Required
HKEY_USERS\.DEFAULT\Software\Louka78 - Restart Required
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\lolzer - Restart Required
HKEY_USERS\S-1-5-19\Software\lolzer - Restart Required
HKEY_USERS\S-1-5-20\Software\lolzer - Restart Required
HKEY_USERS\.DEFAULT\Software\lolzer - Restart Required
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\--((Mutex))-- - Restart Required
HKEY_USERS\S-1-5-19\Software\--((Mutex))-- - Restart Required
HKEY_USERS\S-1-5-20\Software\--((Mutex))-- - Restart Required
HKEY_USERS\.DEFAULT\Software\--((Mutex))-- - Restart Required
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\XtremeRAT - Restart Required
HKEY_USERS\S-1-5-19\Software\XtremeRAT - Restart Required
HKEY_USERS\S-1-5-20\Software\XtremeRAT - Restart Required
HKEY_USERS\.DEFAULT\Software\XtremeRAT - Restart Required
1 File
e:\virus\huge\2015.8.1\19.vir - Deleted
1 Browser Cache
Trojan Horse
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.8.1\15.vir - Deleted
1 Browser Cache
Pwdump
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Security Assessment Tool
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.8.1\16.vir - Deleted
1 Browser Cache
Infostealer.Bancos
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
3 Registry Entries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->UacDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN->iexplore.exe:1 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system->EnableLUA:1 - Repaired
1 File
e:\virus\huge\2015.8.1\26.vir - Deleted
1 Browser Cache
Infostealer.Limitail
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
6 Registry Entries
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:0 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusDisableNotify:0 - Repaired
HKEY_USERS\S-1-5-21-1864693499-3227222065-3676373339-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:0 - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:0 - Repaired
1 File
e:\virus\huge\2015.8.1\36.vir - Deleted
1 Browser Cache
Trojan!gm
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.8.1\12.vir - Deleted
1 Browser Cache
W32.IRCBot.NG
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
e:\virus\huge\2015.8.1\12.vir - No Action Required
1 Browser Cache[/mw_shl_code] |