本帖最后由 cxy密斯 于 2015-8-21 15:59 编辑
[mw_shl_code=css,true]
Dr.Web Scanner SE for Windows v9.1.3.08170
C:\Users\Shiloh\Desktop\2015.8.21\02.vir - infected with W97M.DownLoader.566
C:\Users\Shiloh\Desktop\2015.8.21\02.vir - infected - 60ms, 231936 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\03.vir - packed by ENCODED SCRIPT
C:\Users\Shiloh\Desktop\2015.8.21\03.vir - infected with VBS.DownLoader.312
C:\Users\Shiloh\Desktop\2015.8.21\03.vir - infected - 132ms, 4497 bytes
C:\Users\Shiloh\Desktop\2015.8.21\04.vir - infected with BackDoor.Optix.13
C:\Users\Shiloh\Desktop\2015.8.21\04.vir - infected - 599ms, 295031 bytes
C:\Users\Shiloh\Desktop\2015.8.21\01.vir - Ok - 1115ms, 340224 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\06.vir is RAR archive
C:\Users\Shiloh\Desktop\2015.8.21\06.vir\INV, BL, Phyto, complete shipping docs.exe - infected with Trojan.Siggen6.46521
C:\Users\Shiloh\Desktop\2015.8.21\06.vir\INV, BL, Phyto, complete shipping docs.exe - infected
C:\Users\Shiloh\Desktop\2015.8.21\06.vir - infected archive
C:\Users\Shiloh\Desktop\2015.8.21\06.vir - infected archive - 31ms, 314568 bytes
C:\Users\Shiloh\Desktop\2015.8.21\05.vir - infected with Trojan.Inject1.63890
C:\Users\Shiloh\Desktop\2015.8.21\05.vir - infected - 1051ms, 201204 bytes
C:\Users\Shiloh\Desktop\2015.8.21\07.vir - Ok - 1195ms, 909824 bytes
C:\Users\Shiloh\Desktop\2015.8.21\09.vir - Ok - 395ms, 16384 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\08.vir - packed by FLY-CODE
>C:\Users\Shiloh\Desktop\2015.8.21\10.vir - packed by UPX
C:\Users\Shiloh\Desktop\2015.8.21\10.vir - infected with Trojan.DownLoad3.38808
C:\Users\Shiloh\Desktop\2015.8.21\10.vir - infected - 1706ms, 405504 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\11.vir is BINARYRES container
C:\Users\Shiloh\Desktop\2015.8.21\11.vir\data001 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\11.vir\data002 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\11.vir - Ok
C:\Users\Shiloh\Desktop\2015.8.21\11.vir - container - 1061ms, 49152 bytes
C:\Users\Shiloh\Desktop\2015.8.21\12.vir - Ok - 47ms, 17495 bytes
C:\Users\Shiloh\Desktop\2015.8.21\13.vir - infected with Trojan.PWS.Panda.8013
C:\Users\Shiloh\Desktop\2015.8.21\13.vir - infected - 1050ms, 43008 bytes
>>C:\Users\Shiloh\Desktop\2015.8.21\08.vir - packed by FLY-CODE
C:\Users\Shiloh\Desktop\2015.8.21\08.vir - Ok - 5314ms, 1625600 bytes
C:\Users\Shiloh\Desktop\2015.8.21\14.vir - infected with Trojan.PWS.Panda.8013
C:\Users\Shiloh\Desktop\2015.8.21\14.vir - infected - 1010ms, 45568 bytes
C:\Users\Shiloh\Desktop\2015.8.21\16.vir - infected with W97M.DownLoader.566
C:\Users\Shiloh\Desktop\2015.8.21\16.vir - infected - 9ms, 250368 bytes
C:\Users\Shiloh\Desktop\2015.8.21\17.vir - infected with Trojan.PWS.Panda.8013
C:\Users\Shiloh\Desktop\2015.8.21\17.vir - infected - 358ms, 43008 bytes
C:\Users\Shiloh\Desktop\2015.8.21\15.vir - Ok - 1055ms, 30280 bytes
C:\Users\Shiloh\Desktop\2015.8.21\18.vir - Ok - 420ms, 186880 bytes
C:\Users\Shiloh\Desktop\2015.8.21\19.vir - Ok - 582ms, 166400 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\20.vir - packed by UPX
C:\Users\Shiloh\Desktop\2015.8.21\20.vir - infected with Win32.HLLW.Shadow.based
C:\Users\Shiloh\Desktop\2015.8.21\20.vir - infected - 853ms, 63488 bytes
C:\Users\Shiloh\Desktop\2015.8.21\21.vir - Ok - 743ms, 587776 bytes
C:\Users\Shiloh\Desktop\2015.8.21\22.vir - infected with Trojan.PWS.Stealer.13052
C:\Users\Shiloh\Desktop\2015.8.21\22.vir - infected - 364ms, 200704 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\23.vir is BINARYRES container
C:\Users\Shiloh\Desktop\2015.8.21\23.vir\data001 - Ok
>>C:\Users\Shiloh\Desktop\2015.8.21\23.vir\data002 is NET container
C:\Users\Shiloh\Desktop\2015.8.21\23.vir\data002 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\24.vir - Ok - 1218ms, 100112 bytes
>>C:\Users\Shiloh\Desktop\2015.8.21\23.vir\data003 - packed by ENIGMA
>C:\Users\Shiloh\Desktop\2015.8.21\25.vir - packed by FLY-CODE
C:\Users\Shiloh\Desktop\2015.8.21\25.vir - Ok - 3747ms, 284278 bytes
>>>C:\Users\Shiloh\Desktop\2015.8.21\23.vir\data003 - packed by FLY-CODE
C:\Users\Shiloh\Desktop\2015.8.21\26.vir - infected with Trojan.PWS.Panda.8013
C:\Users\Shiloh\Desktop\2015.8.21\26.vir - infected - 314ms, 43008 bytes
>>>>C:\Users\Shiloh\Desktop\2015.8.21\23.vir\data003 is BINARYRES container
C:\Users\Shiloh\Desktop\2015.8.21\27.vir - is adware program Adware.Downware.11256
C:\Users\Shiloh\Desktop\2015.8.21\23.vir\data003\data001 - infected with Trojan.Encoder.567
C:\Users\Shiloh\Desktop\2015.8.21\23.vir\data003\data001 - infected
C:\Users\Shiloh\Desktop\2015.8.21\23.vir\data003\data002 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\23.vir\data003 - infected container
C:\Users\Shiloh\Desktop\2015.8.21\23.vir - infected container
C:\Users\Shiloh\Desktop\2015.8.21\23.vir - infected container - 5808ms, 1380864 bytes
C:\Users\Shiloh\Desktop\2015.8.21\27.vir - infected - 545ms, 75752 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\29.vir is ZIP archive
C:\Users\Shiloh\Desktop\2015.8.21\29.vir\swift 00987.exe - infected with Trojan.Proxy.27230
C:\Users\Shiloh\Desktop\2015.8.21\29.vir\swift 00987.exe - infected
C:\Users\Shiloh\Desktop\2015.8.21\29.vir - infected archive
C:\Users\Shiloh\Desktop\2015.8.21\29.vir - infected archive - 60ms, 171673 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\28.vir is NET container
C:\Users\Shiloh\Desktop\2015.8.21\28.vir\巁_叇_a_>"_頮}> - Ok
C:\Users\Shiloh\Desktop\2015.8.21\28.vir\閞_<耧_鑼_> - Ok
C:\Users\Shiloh\Desktop\2015.8.21\28.vir\__頕_F闍_巁 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\28.vir\_颻_頮>_F<閰倠K.bmp - Ok
C:\Users\Shiloh\Desktop\2015.8.21\28.vir\a1s!~8e_?8e_8d8eef_i8e849f - Ok
C:\Users\Shiloh\Desktop\2015.8.21\28.vir\a184l~>a1"ee_aaefec__\e9 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\28.vir\__痨_~>__K媉 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\28.vir\_0`}>_K - Ok
C:\Users\Shiloh\Desktop\2015.8.21\28.vir\___~饆_阓~値 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\28.vir - Ok
C:\Users\Shiloh\Desktop\2015.8.21\28.vir - container - 473ms, 412672 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\31.vir is OPEN XML container
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\[Content_Types].xml - Ok
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\_rels\.rels - Ok
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\word\_rels\document.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\word\document.xml - Ok
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\word\media\image1.emf - Ok
>>C:\Users\Shiloh\Desktop\2015.8.21\31.vir\word\embeddings\oleObject1.bin is OLE container
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\word\embeddings\oleObject1.bin\_crypt594F230.exe - infected with Trojan.PWS.Siggen1.40670
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\word\embeddings\oleObject1.bin\_crypt594F230.exe - infected
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\word\embeddings\oleObject1.bin - infected container
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\word\theme\theme1.xml - Ok
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\word\settings.xml - Ok
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\word\webSettings.xml - Ok
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\docProps\core.xml - Ok
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\word\styles.xml - Ok
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\word\fontTable.xml - Ok
C:\Users\Shiloh\Desktop\2015.8.21\31.vir\docProps\app.xml - Ok
C:\Users\Shiloh\Desktop\2015.8.21\31.vir - infected container
C:\Users\Shiloh\Desktop\2015.8.21\31.vir - infected container - 178ms, 136080 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\32.vir is JS-HTML container
C:\Users\Shiloh\Desktop\2015.8.21\32.vir\JSTAG_1[b9][176] - Ok
C:\Users\Shiloh\Desktop\2015.8.21\32.vir\JSTAG_2[4fb][1ae] - Ok
C:\Users\Shiloh\Desktop\2015.8.21\32.vir\JSTAG_3[6d6][1ad] - Ok
C:\Users\Shiloh\Desktop\2015.8.21\32.vir\JSTAG_4[8ac][1a1] - infected with JS.Seospam.1
C:\Users\Shiloh\Desktop\2015.8.21\32.vir\JSTAG_4[8ac][1a1] - infected
C:\Users\Shiloh\Desktop\2015.8.21\32.vir\JSTAG_5[a67][88] - Ok
C:\Users\Shiloh\Desktop\2015.8.21\32.vir - infected container
C:\Users\Shiloh\Desktop\2015.8.21\32.vir - infected container - 99ms, 7000 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\33.vir is ZIP archive
C:\Users\Shiloh\Desktop\2015.8.21\33.vir\Invoice.scr - infected with Trojan.Upatre.7045
C:\Users\Shiloh\Desktop\2015.8.21\33.vir\Invoice.scr - infected
C:\Users\Shiloh\Desktop\2015.8.21\33.vir - infected archive
C:\Users\Shiloh\Desktop\2015.8.21\33.vir - infected archive - 33ms, 21749 bytes
C:\Users\Shiloh\Desktop\2015.8.21\34.vir - Ok - 38ms, 17495 bytes
C:\Users\Shiloh\Desktop\2015.8.21\35.vir - infected with Trojan.Packed.24465
C:\Users\Shiloh\Desktop\2015.8.21\35.vir - infected - 305ms, 116736 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\36.vir - packed by ENCODED SCRIPT
C:\Users\Shiloh\Desktop\2015.8.21\36.vir - Ok - 46ms, 5061 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\37.vir is ZIP archive
>>C:\Users\Shiloh\Desktop\2015.8.21\37.vir\foto-part1.2015-08-19(jpeg).exe - packed by FLY-CODE
>C:\Users\Shiloh\Desktop\2015.8.21\30.vir - packed by FLY-CODE
C:\Users\Shiloh\Desktop\2015.8.21\30.vir - Ok - 1420ms, 682160 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\38.vir is BINARYRES container
>>C:\Users\Shiloh\Desktop\2015.8.21\38.vir\data001 is NET container
C:\Users\Shiloh\Desktop\2015.8.21\38.vir\data001 - Ok
>>C:\Users\Shiloh\Desktop\2015.8.21\38.vir\data002 is NET container
C:\Users\Shiloh\Desktop\2015.8.21\38.vir\data002 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\38.vir\data003 - Ok
>>C:\Users\Shiloh\Desktop\2015.8.21\38.vir\data004 is ZLIB container
C:\Users\Shiloh\Desktop\2015.8.21\38.vir\data004\data001 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\38.vir\data004 - Ok
>>C:\Users\Shiloh\Desktop\2015.8.21\38.vir\data005 is ZLIB container
C:\Users\Shiloh\Desktop\2015.8.21\38.vir\data005\data001 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\38.vir\data005 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\38.vir - Ok
C:\Users\Shiloh\Desktop\2015.8.21\38.vir - container - 582ms, 379904 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\39.vir - packed by UPX
C:\Users\Shiloh\Desktop\2015.8.21\37.vir\foto-part1.2015-08-19(jpeg).exe - Ok
C:\Users\Shiloh\Desktop\2015.8.21\37.vir - Ok
C:\Users\Shiloh\Desktop\2015.8.21\37.vir - archive - 2284ms, 216056 bytes
C:\Users\Shiloh\Desktop\2015.8.21\39.vir - Ok - 1526ms, 405504 bytes
C:\Users\Shiloh\Desktop\2015.8.21\41.vir - infected with Trojan.Backoff.5
C:\Users\Shiloh\Desktop\2015.8.21\41.vir - infected - 1029ms, 143360 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\40.vir is RAR archive
>>C:\Users\Shiloh\Desktop\2015.8.21\40.vir\VMware Workstation Keygen.exe is BINARYRES container
>>>C:\Users\Shiloh\Desktop\2015.8.21\40.vir\VMware Workstation Keygen.exe\data001 is NET container
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\VMware Workstation Keygen.exe\data001 - Ok
>>>C:\Users\Shiloh\Desktop\2015.8.21\40.vir\VMware Workstation Keygen.exe\data002 is NET container
>>>>C:\Users\Shiloh\Desktop\2015.8.21\40.vir\VMware Workstation Keygen.exe\data002\youwave_android is ZLIB container
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\VMware Workstation Keygen.exe\data002\youwave_android\data001 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\VMware Workstation Keygen.exe\data002\youwave_android - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\VMware Workstation Keygen.exe\data002 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\VMware Workstation Keygen.exe - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.Design.dll - Ok
>>C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.dll is BINARYRES container
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.dll\data001 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.dll\data002 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.dll\data003 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.dll\data004 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.dll\data005 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.dll - Ok
>>C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.Fonts.dll is BINARYRES container
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.Fonts.dll\data001 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.Fonts.dll\data002 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.Fonts.dll\data003 - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir\MetroFramework.Fonts.dll - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir - Ok
C:\Users\Shiloh\Desktop\2015.8.21\40.vir - archive - 1969ms, 1374938 bytes
C:\Users\Shiloh\Desktop\2015.8.21\43.vir - probably infected with SCRIPT.Virus
>C:\Users\Shiloh\Desktop\2015.8.21\43.vir is JS-HTML container
C:\Users\Shiloh\Desktop\2015.8.21\43.vir\JSTAG_1[c4e][144] - probably infected with SCRIPT.Virus
C:\Users\Shiloh\Desktop\2015.8.21\43.vir\JSTAG_1[c4e][144] - infected
C:\Users\Shiloh\Desktop\2015.8.21\43.vir - infected container
C:\Users\Shiloh\Desktop\2015.8.21\43.vir - infected container - 27ms, 3500 bytes
C:\Users\Shiloh\Desktop\2015.8.21\44.vir - infected with Trojan.DownLoader11.18111
C:\Users\Shiloh\Desktop\2015.8.21\44.vir - infected - 293ms, 23040 bytes
C:\Users\Shiloh\Desktop\2015.8.21\42.vir - infected with Trojan.PWS.Panda.8013
C:\Users\Shiloh\Desktop\2015.8.21\42.vir - infected - 1024ms, 45568 bytes
C:\Users\Shiloh\Desktop\2015.8.21\46.vir - infected with JS.Muldrop.39
C:\Users\Shiloh\Desktop\2015.8.21\46.vir - infected - 7ms, 3997 bytes
C:\Users\Shiloh\Desktop\2015.8.21\47.vir - Ok - 365ms, 224256 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\48.vir - packed by NSPACK
C:\Users\Shiloh\Desktop\2015.8.21\48.vir - infected with Trojan.Click3.14076
C:\Users\Shiloh\Desktop\2015.8.21\48.vir - infected - 481ms, 105321 bytes
>C:\Users\Shiloh\Desktop\2015.8.21\45.vir is AUTOIT container
>>C:\Users\Shiloh\Desktop\2015.8.21\45.vir\Users\Gyu\AppData\Local\AutoIt v3\Aut2Exe\aut6DF3.tmp.tok - packed by ASCRIPT
C:\Users\Shiloh\Desktop\2015.8.21\45.vir\Users\Gyu\AppData\Local\AutoIt v3\Aut2Exe\aut6DF3.tmp.tok - Ok
C:\Users\Shiloh\Desktop\2015.8.21\45.vir - Ok
C:\Users\Shiloh\Desktop\2015.8.21\45.vir - container - 1722ms, 953856 bytes
C:\Users\Shiloh\Desktop\2015.8.21\49.vir - infected with Trojan.Kovter.69
C:\Users\Shiloh\Desktop\2015.8.21\49.vir - infected - 1054ms, 327726 bytes
C:\Users\Shiloh\Desktop\2015.8.21\50.vir - infected with Trojan.Inject1.54916
C:\Users\Shiloh\Desktop\2015.8.21\50.vir - infected - 422ms, 868864 bytes
Total 14559429 bytes in 50 files scanned (114 objects, 3 containers)
Total 22 files (77 objects) are clean
Total 27 files are infected
Total 1 file (2 objects) are suspicious
Scan time is 00:00:23.258
Start curing
C:\Users\Shiloh\Desktop\2015.8.21\02.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\03.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\04.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\06.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\05.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\10.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\13.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\14.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\16.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\17.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\20.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\22.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\26.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\23.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\27.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\29.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\31.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\32.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\33.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\35.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\41.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\43.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\44.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\42.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\46.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\48.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\49.vir - quarantined
C:\Users\Shiloh\Desktop\2015.8.21\50.vir - quarantined
Total 14559429 bytes in 50 files scanned (114 objects, 3 containers)
Total 22 files (77 objects) are clean
Total 27 files are infected
Total 1 file (2 objects) are suspicious
Total 28 files (29 objects) are neutralized
Scan time is 00:00:23.258
[/mw_shl_code] |