[mw_shl_code=css,true]Dr.Web Scanner SE for Windows v9.1.3.08170
Scanning Engine version: 10.0.9.8310
Virus Finding Engine version: 7.0.15.8310
-----------------------------------------------------------------------------
Start scanning
-----------------------------------------------------------------------------
Object(s) to scan:
- C:\Users\Shiloh\Desktop\2015.9.11
C:\Users\Shiloh\Desktop\2015.9.11\01.vir:Zone.Identifier - Ok - 14ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\02.vir:Zone.Identifier - Ok - 8ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\03.vir is 7-ZIP archive
>>C:\Users\Shiloh\Desktop\2015.9.11\03.vir\Swift Details.exe is BINARYRES container
C:\Users\Shiloh\Desktop\2015.9.11\03.vir\Swift Details.exe\data001 - Ok
>>>C:\Users\Shiloh\Desktop\2015.9.11\03.vir\Swift Details.exe\data002 is NET container
C:\Users\Shiloh\Desktop\2015.9.11\03.vir\Swift Details.exe\data002 - Ok
C:\Users\Shiloh\Desktop\2015.9.11\03.vir\Swift Details.exe - Ok
C:\Users\Shiloh\Desktop\2015.9.11\03.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.11\03.vir - archive - 69ms, 112405 bytes
C:\Users\Shiloh\Desktop\2015.9.11\03.vir:Zone.Identifier - Ok - 5ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\01.vir is BINARYRES container
>>C:\Users\Shiloh\Desktop\2015.9.11\01.vir\data001 is NET container
C:\Users\Shiloh\Desktop\2015.9.11\01.vir\data001 - Ok
>>C:\Users\Shiloh\Desktop\2015.9.11\01.vir\data002 is NET container
>>>C:\Users\Shiloh\Desktop\2015.9.11\01.vir\data002\AthenaHttpBin is GZIP archive
C:\Users\Shiloh\Desktop\2015.9.11\01.vir\data002\AthenaHttpBin\AthenaHttpBin.exe - infected with BackDoor.Siggen.56198
C:\Users\Shiloh\Desktop\2015.9.11\01.vir\data002\AthenaHttpBin\AthenaHttpBin.exe - infected
C:\Users\Shiloh\Desktop\2015.9.11\01.vir\data002\AthenaHttpBin - infected archive
C:\Users\Shiloh\Desktop\2015.9.11\01.vir\data002 - infected container
>C:\Users\Shiloh\Desktop\2015.9.11\02.vir is RAR archive
>C:\Users\Shiloh\Desktop\2015.9.11\04.vir - packed by FLY-CODE
>>C:\Users\Shiloh\Desktop\2015.9.11\02.vir\Loader.vbe - packed by ENCODED SCRIPT
C:\Users\Shiloh\Desktop\2015.9.11\02.vir\Loader.vbe - Ok
C:\Users\Shiloh\Desktop\2015.9.11\02.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.11\02.vir - archive - 467ms, 408381 bytes
C:\Users\Shiloh\Desktop\2015.9.11\04.vir:Zone.Identifier - Ok - 6ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\04.vir - Ok - 411ms, 215552 bytes
C:\Users\Shiloh\Desktop\2015.9.11\05.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\06.vir - Ok - 6ms, 1762 bytes
C:\Users\Shiloh\Desktop\2015.9.11\06.vir:Zone.Identifier - Ok - 5ms, 26 bytes
>>C:\Users\Shiloh\Desktop\2015.9.11\01.vir\data003 - packed by UPX
>C:\Users\Shiloh\Desktop\2015.9.11\05.vir - packed by ASPACK
C:\Users\Shiloh\Desktop\2015.9.11\07.vir - is adware program Adware.AdPeak.6
C:\Users\Shiloh\Desktop\2015.9.11\01.vir\data003 - Ok
C:\Users\Shiloh\Desktop\2015.9.11\01.vir - infected container
C:\Users\Shiloh\Desktop\2015.9.11\01.vir - infected container - 881ms, 375296 bytes
C:\Users\Shiloh\Desktop\2015.9.11\07.vir:Zone.Identifier - Ok - 6ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\05.vir - infected with Trojan.DownLoader11.32745
C:\Users\Shiloh\Desktop\2015.9.11\05.vir - infected - 433ms, 90440 bytes
C:\Users\Shiloh\Desktop\2015.9.11\08.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\09.vir - infected with Trojan.Click3.7041
C:\Users\Shiloh\Desktop\2015.9.11\09.vir - infected - 282ms, 69632 bytes
C:\Users\Shiloh\Desktop\2015.9.11\09.vir:Zone.Identifier - Ok - 7ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\10.vir is RAR archive
C:\Users\Shiloh\Desktop\2015.9.11\08.vir - Ok - 338ms, 73209 bytes
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\blog - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir:Zone.Identifier - Ok - 6ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\botlogger.php - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\css\bootstrap-theme.css - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\css\bootstrap-theme.css.map - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\css\bootstrap-theme.min.css - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\css\bootstrap.css - Ok
>C:\Users\Shiloh\Desktop\2015.9.11\11.vir - packed by UPX
C:\Users\Shiloh\Desktop\2015.9.11\11.vir - Ok - 517ms, 108032 bytes
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\css\bootstrap.css.map - Ok
C:\Users\Shiloh\Desktop\2015.9.11\11.vir:Zone.Identifier - Ok - 7ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\12.vir - Ok - 6ms, 1674 bytes
C:\Users\Shiloh\Desktop\2015.9.11\12.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\css\bootstrap.min.css - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\fonts\glyphicons-halflings-regular.eot - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\fonts\glyphicons-halflings-regular.svg - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\fonts\glyphicons-halflings-regular.ttf - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\fonts\glyphicons-halflings-regular.woff - Ok
>>C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\index.php is JS-HTML container
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\index.php - Ok
C:\Users\Shiloh\Desktop\2015.9.11\13.vir - infected with Trojan.DownLoad3.28059
C:\Users\Shiloh\Desktop\2015.9.11\13.vir - infected - 261ms, 77824 bytes
C:\Users\Shiloh\Desktop\2015.9.11\13.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\14.vir - Ok - 7ms, 2143 bytes
C:\Users\Shiloh\Desktop\2015.9.11\14.vir:Zone.Identifier - Ok - 6ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\js\bootstrap.js - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\js\bootstrap.min.js - Ok
>>C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\login.php is JS-HTML container
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\login.php\JSTAG_1[2f2][5b] - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\login.php - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\logout.php - Ok
>>C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\onlinebots.php is JS-HTML container
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\onlinebots.php - Ok
>>C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\register.php is JS-HTML container
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\register.php\JSTAG_1[575][5b] - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\register.php - Ok
>>C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\settings.php is JS-HTML container
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\settings.php - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\WebPanel\visitors.txt - Ok
>>C:\Users\Shiloh\Desktop\2015.9.11\10.vir\Builder\Blue Botnet Bot Builder.exe is BINARYRES container
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\Builder\Blue Botnet Bot Builder.exe\data001 - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\Builder\Blue Botnet Bot Builder.exe\data002 - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\Builder\Blue Botnet Bot Builder.exe - Ok
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\Builder\rawbot.exx - infected with Trojan.DownLoader11.38015
C:\Users\Shiloh\Desktop\2015.9.11\10.vir\Builder\rawbot.exx - infected
C:\Users\Shiloh\Desktop\2015.9.11\10.vir - infected archive
C:\Users\Shiloh\Desktop\2015.9.11\10.vir - infected archive - 1068ms, 233035 bytes
C:\Users\Shiloh\Desktop\2015.9.11\15.vir:Zone.Identifier - Ok - 4ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\16.vir is GZIP archive
C:\Users\Shiloh\Desktop\2015.9.11\16.vir\gziped.gz - infected with Trojan.PWS.Stealer.4118
C:\Users\Shiloh\Desktop\2015.9.11\16.vir\gziped.gz - infected
C:\Users\Shiloh\Desktop\2015.9.11\16.vir - infected archive
C:\Users\Shiloh\Desktop\2015.9.11\16.vir - infected archive - 16ms, 22414 bytes
C:\Users\Shiloh\Desktop\2015.9.11\16.vir:Zone.Identifier - Ok - 5ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\15.vir is BINARYRES container
C:\Users\Shiloh\Desktop\2015.9.11\15.vir\data001 - Ok
C:\Users\Shiloh\Desktop\2015.9.11\15.vir\data002 - Ok
C:\Users\Shiloh\Desktop\2015.9.11\15.vir\data003 - Ok
C:\Users\Shiloh\Desktop\2015.9.11\15.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.11\15.vir - container - 293ms, 35840 bytes
C:\Users\Shiloh\Desktop\2015.9.11\07.vir - infected with Trojan.AVKill.35957
C:\Users\Shiloh\Desktop\2015.9.11\07.vir - infected - 1819ms, 473944 bytes
C:\Users\Shiloh\Desktop\2015.9.11\17.vir:Zone.Identifier - Ok - 6ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\18.vir:Zone.Identifier - Ok - 6ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\18.vir - packed by ENCODED SCRIPT
C:\Users\Shiloh\Desktop\2015.9.11\18.vir - infected with VBS.DownLoader.396
C:\Users\Shiloh\Desktop\2015.9.11\18.vir - infected - 47ms, 5931 bytes
C:\Users\Shiloh\Desktop\2015.9.11\19.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\20.vir - Ok - 6ms, 976 bytes
C:\Users\Shiloh\Desktop\2015.9.11\19.vir - probably infected with SCRIPT.Virus
C:\Users\Shiloh\Desktop\2015.9.11\20.vir:Zone.Identifier - Ok - 6ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\19.vir is JS-HTML container
>C:\Users\Shiloh\Desktop\2015.9.11\21.vir is SWF container
>>C:\Users\Shiloh\Desktop\2015.9.11\21.vir\Data is SWF container
C:\Users\Shiloh\Desktop\2015.9.11\21.vir\Data\Code[3326] - Ok
C:\Users\Shiloh\Desktop\2015.9.11\21.vir\Data - Ok
C:\Users\Shiloh\Desktop\2015.9.11\21.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.11\21.vir - container - 23ms, 2611 bytes
C:\Users\Shiloh\Desktop\2015.9.11\21.vir:Zone.Identifier - Ok - 5ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\22.vir is ZIP archive
C:\Users\Shiloh\Desktop\2015.9.11\19.vir\JSFile_1[0][3b28] - Ok
C:\Users\Shiloh\Desktop\2015.9.11\19.vir\JSEval_2[32e] - infected with JS.DownLoader.365
>>C:\Users\Shiloh\Desktop\2015.9.11\22.vir\curriculo0182728.vbe - packed by ENCODED SCRIPT
C:\Users\Shiloh\Desktop\2015.9.11\19.vir\JSEval_2[32e] - infected
C:\Users\Shiloh\Desktop\2015.9.11\19.vir - infected container
C:\Users\Shiloh\Desktop\2015.9.11\19.vir - infected container - 113ms, 15144 bytes
C:\Users\Shiloh\Desktop\2015.9.11\22.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\22.vir\curriculo0182728.vbe - infected with VBS.DownLoader.398
C:\Users\Shiloh\Desktop\2015.9.11\22.vir\curriculo0182728.vbe - infected
C:\Users\Shiloh\Desktop\2015.9.11\22.vir - infected archive
C:\Users\Shiloh\Desktop\2015.9.11\22.vir - infected archive - 56ms, 4484 bytes
C:\Users\Shiloh\Desktop\2015.9.11\23.vir:Zone.Identifier - Ok - 6ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\24.vir - packed by ENCODED SCRIPT
C:\Users\Shiloh\Desktop\2015.9.11\24.vir - Ok - 29ms, 3674 bytes
C:\Users\Shiloh\Desktop\2015.9.11\24.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\25.vir - Ok - 19ms, 28672 bytes
C:\Users\Shiloh\Desktop\2015.9.11\25.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\26.vir - Ok - 6ms, 1645 bytes
C:\Users\Shiloh\Desktop\2015.9.11\26.vir:Zone.Identifier - Ok - 3ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\17.vir - Ok - 378ms, 28672 bytes
C:\Users\Shiloh\Desktop\2015.9.11\27.vir:Zone.Identifier - Ok - 12ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\23.vir is BINARYRES container
C:\Users\Shiloh\Desktop\2015.9.11\23.vir\data001 - Ok
>>C:\Users\Shiloh\Desktop\2015.9.11\23.vir\data002 is NET container
C:\Users\Shiloh\Desktop\2015.9.11\23.vir\data002 - Ok
C:\Users\Shiloh\Desktop\2015.9.11\23.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.11\23.vir - container - 321ms, 394752 bytes
C:\Users\Shiloh\Desktop\2015.9.11\28.vir:Zone.Identifier - Ok - 5ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\29.vir - packed by XOREXE
>C:\Users\Shiloh\Desktop\2015.9.11\28.vir is BASE64 container
>>C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part is OPEN XML container
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\[Content_Types].xml - Ok
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\_rels\.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.11\27.vir - infected with BackDoor.Gbot.1591
C:\Users\Shiloh\Desktop\2015.9.11\27.vir - infected - 290ms, 186880 bytes
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\word\_rels\document.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.11\29.vir:Zone.Identifier - Ok - 8ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\word\document.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\word\vbaProject.bin - infected with W97M.DownLoader.547
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\word\vbaProject.bin - infected
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\word\_rels\vbaProject.bin.rels - Ok
>C:\Users\Shiloh\Desktop\2015.9.11\30.vir - packed by ENCODED SCRIPT
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\word\theme\theme1.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\word\vbaData.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.11\30.vir - Ok - 50ms, 4642 bytes
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\word\settings.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.11\30.vir:Zone.Identifier - Ok - 7ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\docProps\app.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\word\styles.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\docProps\core.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\word\fontTable.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part\word\webSettings.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.11\28.vir\0.part - infected container
C:\Users\Shiloh\Desktop\2015.9.11\28.vir - infected mail
C:\Users\Shiloh\Desktop\2015.9.11\28.vir - infected mail - 265ms, 53788 bytes
C:\Users\Shiloh\Desktop\2015.9.11\31.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\32.vir - Ok - 8ms, 1426 bytes
C:\Users\Shiloh\Desktop\2015.9.11\32.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\29.vir - Ok - 190ms, 305664 bytes
C:\Users\Shiloh\Desktop\2015.9.11\33.vir:Zone.Identifier - Ok - 4ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\34.vir is ZIP archive
>>C:\Users\Shiloh\Desktop\2015.9.11\34.vir\e-Ticket_957-2116395082.vbe - packed by ENCODED SCRIPT
C:\Users\Shiloh\Desktop\2015.9.11\34.vir\e-Ticket_957-2116395082.vbe - Ok
C:\Users\Shiloh\Desktop\2015.9.11\34.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.11\34.vir - archive - 26ms, 1237 bytes
C:\Users\Shiloh\Desktop\2015.9.11\34.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\33.vir - probably infected with SCRIPT.Virus
>C:\Users\Shiloh\Desktop\2015.9.11\33.vir is JS-HTML container
C:\Users\Shiloh\Desktop\2015.9.11\33.vir\JSFile_1[0][3ee6] - Ok
C:\Users\Shiloh\Desktop\2015.9.11\33.vir\JSEval_2[339] - infected with JS.DownLoader.365
C:\Users\Shiloh\Desktop\2015.9.11\33.vir\JSEval_2[339] - infected
C:\Users\Shiloh\Desktop\2015.9.11\33.vir - infected container
C:\Users\Shiloh\Desktop\2015.9.11\33.vir - infected container - 108ms, 16102 bytes
C:\Users\Shiloh\Desktop\2015.9.11\35.vir:Zone.Identifier - Ok - 4ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\36.vir is ZIP archive
C:\Users\Shiloh\Desktop\2015.9.11\36.vir\Court_Notification_000866121.doc.js - probably infected with SCRIPT.Virus
>>C:\Users\Shiloh\Desktop\2015.9.11\36.vir\Court_Notification_000866121.doc.js is JS-HTML container
C:\Users\Shiloh\Desktop\2015.9.11\36.vir\Court_Notification_000866121.doc.js\JSFile_1[0][3f4e] - Ok
C:\Users\Shiloh\Desktop\2015.9.11\36.vir\Court_Notification_000866121.doc.js\JSEval_2[328] - infected with JS.DownLoader.365
C:\Users\Shiloh\Desktop\2015.9.11\36.vir\Court_Notification_000866121.doc.js\JSEval_2[328] - infected
C:\Users\Shiloh\Desktop\2015.9.11\36.vir\Court_Notification_000866121.doc.js - infected container
C:\Users\Shiloh\Desktop\2015.9.11\36.vir - infected archive
C:\Users\Shiloh\Desktop\2015.9.11\36.vir - infected archive - 102ms, 3586 bytes
C:\Users\Shiloh\Desktop\2015.9.11\36.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\31.vir - infected with Trojan.PWS.Stealer.4118
C:\Users\Shiloh\Desktop\2015.9.11\31.vir - infected - 271ms, 42051 bytes
C:\Users\Shiloh\Desktop\2015.9.11\37.vir:Zone.Identifier - Ok - 6ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\37.vir is RAR archive
>>C:\Users\Shiloh\Desktop\2015.9.11\37.vir\52150603317431000174550010000015631000015630-NFe.PDF.exe - packed by UPX
>C:\Users\Shiloh\Desktop\2015.9.11\35.vir is BINARYRES container
C:\Users\Shiloh\Desktop\2015.9.11\35.vir\data001 - Ok
>>C:\Users\Shiloh\Desktop\2015.9.11\35.vir\data002 is NET container
C:\Users\Shiloh\Desktop\2015.9.11\35.vir\data002 - Ok
C:\Users\Shiloh\Desktop\2015.9.11\35.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.11\35.vir - container - 334ms, 343552 bytes
C:\Users\Shiloh\Desktop\2015.9.11\38.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\37.vir\52150603317431000174550010000015631000015630-NFe.PDF.exe - Ok
C:\Users\Shiloh\Desktop\2015.9.11\37.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.11\37.vir - archive - 244ms, 97374 bytes
C:\Users\Shiloh\Desktop\2015.9.11\39.vir:Zone.Identifier - Ok - 4ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\40.vir is PDF container
C:\Users\Shiloh\Desktop\2015.9.11\40.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.11\40.vir - container - 9ms, 306352 bytes
C:\Users\Shiloh\Desktop\2015.9.11\40.vir:Zone.Identifier - Ok - 4ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\38.vir is BINARYRES container
C:\Users\Shiloh\Desktop\2015.9.11\38.vir\data001 - Ok
>>C:\Users\Shiloh\Desktop\2015.9.11\38.vir\data002 is NET container
C:\Users\Shiloh\Desktop\2015.9.11\38.vir\data002 - Ok
C:\Users\Shiloh\Desktop\2015.9.11\38.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.11\38.vir - container - 295ms, 142848 bytes
C:\Users\Shiloh\Desktop\2015.9.11\41.vir:Zone.Identifier - Ok - 4ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\39.vir - packed by UPX
C:\Users\Shiloh\Desktop\2015.9.11\41.vir - Ok - 345ms, 360448 bytes
C:\Users\Shiloh\Desktop\2015.9.11\42.vir:Zone.Identifier - Ok - 6ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\43.vir - packed by ENCODED SCRIPT
C:\Users\Shiloh\Desktop\2015.9.11\43.vir - Ok - 17ms, 581 bytes
C:\Users\Shiloh\Desktop\2015.9.11\43.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\39.vir - Ok - 466ms, 43008 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\42.vir - packed by FLY-CODE
C:\Users\Shiloh\Desktop\2015.9.11\44.vir:Zone.Identifier - Ok - 6ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\45.vir is JS-HTML container
C:\Users\Shiloh\Desktop\2015.9.11\45.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.11\45.vir - container - 56ms, 9564 bytes
C:\Users\Shiloh\Desktop\2015.9.11\45.vir:Zone.Identifier - Ok - 6ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\46.vir is ZIP archive
C:\Users\Shiloh\Desktop\2015.9.11\46.vir\80aae2 e1a2a5e0aaa8. 8ea1aee0aee2adae-e1a0abeca4aea2eba5 a4a0adadeba5 ada0 11.08.15 a7a0 88eeabec. 8da5aea1e5aea4a8acae e1aea3aba0e1aea2a0e2ec a2 e1e0aee7adaeac afaee0efa4aaa5.daee1 .jsd - infected with JS.DownLoader.451
C:\Users\Shiloh\Desktop\2015.9.11\46.vir\80aae2 e1a2a5e0aaa8. 8ea1aee0aee2adae-e1a0abeca4aea2eba5 a4a0adadeba5 ada0 11.08.15 a7a0 88eeabec. 8da5aea1e5aea4a8acae e1aea3aba0e1aea2a0e2ec a2 e1e0aee7adaeac afaee0efa4aaa5.daee1 .jsd - infected
C:\Users\Shiloh\Desktop\2015.9.11\46.vir - infected archive
C:\Users\Shiloh\Desktop\2015.9.11\46.vir - infected archive - 13ms, 2389 bytes
C:\Users\Shiloh\Desktop\2015.9.11\46.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\42.vir - Ok - 503ms, 487424 bytes
C:\Users\Shiloh\Desktop\2015.9.11\47.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\48.vir - Ok - 4ms, 1168 bytes
C:\Users\Shiloh\Desktop\2015.9.11\48.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\47.vir - probably infected with DLOADER.Trojan
C:\Users\Shiloh\Desktop\2015.9.11\47.vir - infected - 292ms, 8704 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\44.vir - packed by FLY-CODE
C:\Users\Shiloh\Desktop\2015.9.11\49.vir:Zone.Identifier - Ok - 7ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\44.vir - Ok - 457ms, 215552 bytes
C:\Users\Shiloh\Desktop\2015.9.11\50.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.11\49.vir - infected with BackDoor.Gbot.2028
C:\Users\Shiloh\Desktop\2015.9.11\49.vir - infected - 287ms, 279040 bytes
>C:\Users\Shiloh\Desktop\2015.9.11\50.vir - packed by FLY-CODE
C:\Users\Shiloh\Desktop\2015.9.11\50.vir - Ok - 967ms, 563200 bytes
Total 6266024 bytes in 100 files scanned (174 objects, 5 containers)
Total 82 files (143 objects) are clean
Total 17 files (18 objects) are infected
Total 1 file (4 objects) are suspicious
Scan time is 00:00:05.188
-----------------------------------------------------------------------------
Start curing
-----------------------------------------------------------------------------
C:\Users\Shiloh\Desktop\2015.9.11\01.vir - quarantined - 914 ms
C:\Users\Shiloh\Desktop\2015.9.11\05.vir - quarantined - 173 ms
C:\Users\Shiloh\Desktop\2015.9.11\09.vir - quarantined - 41 ms
C:\Users\Shiloh\Desktop\2015.9.11\13.vir - quarantined - 41 ms
C:\Users\Shiloh\Desktop\2015.9.11\10.vir - quarantined - 30 ms
C:\Users\Shiloh\Desktop\2015.9.11\16.vir - quarantined - 26 ms
C:\Users\Shiloh\Desktop\2015.9.11\07.vir - quarantined - 1185 ms
C:\Users\Shiloh\Desktop\2015.9.11\18.vir - quarantined - 75 ms
C:\Users\Shiloh\Desktop\2015.9.11\19.vir - quarantined - 115 ms
C:\Users\Shiloh\Desktop\2015.9.11\22.vir - quarantined - 28 ms
C:\Users\Shiloh\Desktop\2015.9.11\27.vir - quarantined - 58 ms
C:\Users\Shiloh\Desktop\2015.9.11\28.vir - quarantined - 32 ms
C:\Users\Shiloh\Desktop\2015.9.11\33.vir - quarantined - 123 ms
C:\Users\Shiloh\Desktop\2015.9.11\36.vir - quarantined - 28 ms
C:\Users\Shiloh\Desktop\2015.9.11\31.vir - quarantined - 42 ms
C:\Users\Shiloh\Desktop\2015.9.11\46.vir - quarantined - 29 ms
C:\Users\Shiloh\Desktop\2015.9.11\47.vir - quarantined - 29 ms
C:\Users\Shiloh\Desktop\2015.9.11\49.vir - quarantined - 58 ms
Total 6266024 bytes in 100 files scanned (174 objects, 5 containers)
Total 82 files (143 objects) are clean
Total 17 files (18 objects) are infected
Total 1 file (4 objects) are suspicious
Total 18 files (22 objects) are neutralized
Scan time is 00:00:05.188
[/mw_shl_code] |