[mw_shl_code=css,true]Dr.Web Scanner SE for Windows v9.1.3.08170
Scanning Engine version: 10.0.9.8310
Virus Finding Engine version: 7.0.15.8310
-----------------------------------------------------------------------------
Start scanning
-----------------------------------------------------------------------------
Object(s) to scan:
- C:\Users\Shiloh\Desktop\2015.9.13
C:\Users\Shiloh\Desktop\2015.9.13\01.vir:Zone.Identifier - Ok - 10ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\01.vir - Ok - 13ms, 203843 bytes
C:\Users\Shiloh\Desktop\2015.9.13\02.vir:Zone.Identifier - Ok - 6ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\03.vir:Zone.Identifier - Ok - 8ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\03.vir is ZIP archive
>C:\Users\Shiloh\Desktop\2015.9.13\04.vir is OPEN XML container
C:\Users\Shiloh\Desktop\2015.9.13\03.vir\binary\IN_FILE.PRG - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\[Content_Types].xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\_rels\.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\_rels\document.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\document.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\_rels\vbaProject.bin.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\03.vir\binary\victim1.st - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\vbaProject.bin - infected with W97M.DownLoader.609
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\vbaProject.bin - infected
C:\Users\Shiloh\Desktop\2015.9.13\03.vir\binary\~.PRG - Ok
C:\Users\Shiloh\Desktop\2015.9.13\03.vir\readme.txt - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\theme\theme1.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\03.vir\source\A2B.S - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\vbaData.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\03.vir\source\a2b_drop.S - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\settings.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\03.vir\source\boot.inc - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\webSettings.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\03.vir\source\fileio.inc - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\styles.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\03.vir\source\in_file.S - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\numbering.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\03.vir\source\mem.inc - Ok
C:\Users\Shiloh\Desktop\2015.9.13\03.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.13\03.vir - archive - 148ms, 12139 bytes
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\docProps\app.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\stylesWithEffects.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\word\fontTable.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir\docProps\core.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\04.vir - infected container
C:\Users\Shiloh\Desktop\2015.9.13\04.vir - infected container - 160ms, 36282 bytes
C:\Users\Shiloh\Desktop\2015.9.13\05.vir:Zone.Identifier - Ok - 5ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\06.vir is ZIP archive
C:\Users\Shiloh\Desktop\2015.9.13\06.vir\ref. _3017842.scr - infected with Trojan.Inject1.54688
C:\Users\Shiloh\Desktop\2015.9.13\06.vir\ref. _3017842.scr - infected
C:\Users\Shiloh\Desktop\2015.9.13\06.vir - infected archive
C:\Users\Shiloh\Desktop\2015.9.13\06.vir - infected archive - 44ms, 32903 bytes
C:\Users\Shiloh\Desktop\2015.9.13\06.vir:Zone.Identifier - Ok - 6ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\02.vir - packed by UPX
C:\Users\Shiloh\Desktop\2015.9.13\07.vir - infected with BackDoor.Poison.686
C:\Users\Shiloh\Desktop\2015.9.13\07.vir - infected - 265ms, 8192 bytes
C:\Users\Shiloh\Desktop\2015.9.13\07.vir:Zone.Identifier - Ok - 7ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\05.vir - Ok - 399ms, 503808 bytes
C:\Users\Shiloh\Desktop\2015.9.13\08.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\02.vir - Ok - 598ms, 111104 bytes
C:\Users\Shiloh\Desktop\2015.9.13\09.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\10.vir - infected with Linux.BackDoor.Fgt.44
C:\Users\Shiloh\Desktop\2015.9.13\10.vir - infected - 6ms, 200057 bytes
C:\Users\Shiloh\Desktop\2015.9.13\10.vir:Zone.Identifier - Ok - 4ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\11.vir is ZIP archive
C:\Users\Shiloh\Desktop\2015.9.13\11.vir\eFax Jakubowski Extension.exe - infected with Trojan.PWS.Panda.8013
C:\Users\Shiloh\Desktop\2015.9.13\11.vir\eFax Jakubowski Extension.exe - infected
C:\Users\Shiloh\Desktop\2015.9.13\11.vir - infected archive
C:\Users\Shiloh\Desktop\2015.9.13\11.vir - infected archive - 13ms, 18015 bytes
C:\Users\Shiloh\Desktop\2015.9.13\11.vir:Zone.Identifier - Ok - 5ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\12.vir - packed by ENCODED SCRIPT
C:\Users\Shiloh\Desktop\2015.9.13\12.vir - infected with VBS.DownLoader.399
C:\Users\Shiloh\Desktop\2015.9.13\12.vir - infected - 41ms, 6713 bytes
C:\Users\Shiloh\Desktop\2015.9.13\12.vir:Zone.Identifier - Ok - 5ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\13.vir is ZIP archive
C:\Users\Shiloh\Desktop\2015.9.13\13.vir\September 2015-_louytf-phalo.exe - infected with Trojan.DownLoader16.23911
C:\Users\Shiloh\Desktop\2015.9.13\13.vir\September 2015-_louytf-phalo.exe - infected
C:\Users\Shiloh\Desktop\2015.9.13\13.vir - infected archive
C:\Users\Shiloh\Desktop\2015.9.13\13.vir - infected archive - 7ms, 18102 bytes
C:\Users\Shiloh\Desktop\2015.9.13\13.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\14.vir - probably infected with SCRIPT.Virus
>C:\Users\Shiloh\Desktop\2015.9.13\14.vir is JS-HTML container
C:\Users\Shiloh\Desktop\2015.9.13\14.vir\JSFile_1[0][3fb5] - Ok
C:\Users\Shiloh\Desktop\2015.9.13\14.vir\JSEval_2[32b] - infected with JS.DownLoader.365
C:\Users\Shiloh\Desktop\2015.9.13\14.vir\JSEval_2[32b] - infected
C:\Users\Shiloh\Desktop\2015.9.13\14.vir - infected container
C:\Users\Shiloh\Desktop\2015.9.13\14.vir - infected container - 100ms, 16309 bytes
C:\Users\Shiloh\Desktop\2015.9.13\14.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\08.vir - Ok - 324ms, 200192 bytes
C:\Users\Shiloh\Desktop\2015.9.13\15.vir:Zone.Identifier - Ok - 5ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\09.vir - packed by UPX
C:\Users\Shiloh\Desktop\2015.9.13\09.vir - infected with Trojan.Encoder.1791
C:\Users\Shiloh\Desktop\2015.9.13\09.vir - infected - 321ms, 19456 bytes
C:\Users\Shiloh\Desktop\2015.9.13\16.vir:Zone.Identifier - Ok - 4ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\17.vir is ZIP archive
C:\Users\Shiloh\Desktop\2015.9.13\17.vir\ExplicityBoat.dll - Ok
C:\Users\Shiloh\Desktop\2015.9.13\17.vir\gmcl_dickwrap_win32.dll - Ok
C:\Users\Shiloh\Desktop\2015.9.13\17.vir\gmcl_Frozen_win32.dll - Ok
C:\Users\Shiloh\Desktop\2015.9.13\17.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.13\17.vir - archive - 81ms, 92972 bytes
C:\Users\Shiloh\Desktop\2015.9.13\17.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\15.vir - infected with BackDoor.Siggen.52725
C:\Users\Shiloh\Desktop\2015.9.13\15.vir - infected - 345ms, 33792 bytes
C:\Users\Shiloh\Desktop\2015.9.13\18.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\16.vir - infected with Trojan.Siggen3.53917
C:\Users\Shiloh\Desktop\2015.9.13\16.vir - infected - 306ms, 126982 bytes
C:\Users\Shiloh\Desktop\2015.9.13\19.vir - infected with W97M.DownLoader.612
C:\Users\Shiloh\Desktop\2015.9.13\19.vir - infected - 3ms, 527360 bytes
C:\Users\Shiloh\Desktop\2015.9.13\19.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\20.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\21.vir - Ok - 9ms, 73216 bytes
C:\Users\Shiloh\Desktop\2015.9.13\21.vir:Zone.Identifier - Ok - 6ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\18.vir - infected with Trojan.DownLoader16.23825
C:\Users\Shiloh\Desktop\2015.9.13\18.vir - infected - 306ms, 233472 bytes
C:\Users\Shiloh\Desktop\2015.9.13\22.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\20.vir - Ok - 376ms, 143372 bytes
C:\Users\Shiloh\Desktop\2015.9.13\23.vir:Zone.Identifier - Ok - 16ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\23.vir - infected with Trojan.DownLoader15.16402
C:\Users\Shiloh\Desktop\2015.9.13\23.vir - infected - 401ms, 673280 bytes
C:\Users\Shiloh\Desktop\2015.9.13\24.vir:Zone.Identifier - Ok - 10ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\25.vir is RAR archive
C:\Users\Shiloh\Desktop\2015.9.13\22.vir - infected with Win32.Fortax
C:\Users\Shiloh\Desktop\2015.9.13\22.vir - infected - 560ms, 152025 bytes
C:\Users\Shiloh\Desktop\2015.9.13\25.vir:Zone.Identifier - Ok - 8ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\24.vir - infected with BackDoor.Bladabindi.11315
C:\Users\Shiloh\Desktop\2015.9.13\24.vir - infected - 288ms, 35840 bytes
C:\Users\Shiloh\Desktop\2015.9.13\26.vir:Zone.Identifier - Ok - 7ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\27.vir is RAR archive
C:\Users\Shiloh\Desktop\2015.9.13\27.vir\wpe\Leeme !.txt - Ok
C:\Users\Shiloh\Desktop\2015.9.13\27.vir\wpe\Packets-DaRK-AnGeL.spt - Ok
C:\Users\Shiloh\Desktop\2015.9.13\25.vir\FireCheats ( Ultimate v3.1 ) Trainer.exe - infected with Win32.HLLW.SpyNet.233
C:\Users\Shiloh\Desktop\2015.9.13\25.vir\FireCheats ( Ultimate v3.1 ) Trainer.exe - infected
C:\Users\Shiloh\Desktop\2015.9.13\25.vir\Leia Antes de usar.txt - Ok
C:\Users\Shiloh\Desktop\2015.9.13\25.vir - infected archive
C:\Users\Shiloh\Desktop\2015.9.13\25.vir - infected archive - 219ms, 355064 bytes
C:\Users\Shiloh\Desktop\2015.9.13\27.vir:Zone.Identifier - Ok - 10ms, 26 bytes
>>C:\Users\Shiloh\Desktop\2015.9.13\27.vir\wpe\SetPriv.dll - packed by UPX
C:\Users\Shiloh\Desktop\2015.9.13\28.vir - Ok - 10ms, 49152 bytes
C:\Users\Shiloh\Desktop\2015.9.13\28.vir:Zone.Identifier - Ok - 7ms, 26 bytes
>>>C:\Users\Shiloh\Desktop\2015.9.13\27.vir\wpe\SetPriv.dll - packed by FLY-CODE
C:\Users\Shiloh\Desktop\2015.9.13\26.vir - infected with Trojan.Encoder.514
C:\Users\Shiloh\Desktop\2015.9.13\26.vir - infected - 301ms, 216067 bytes
C:\Users\Shiloh\Desktop\2015.9.13\29.vir:Zone.Identifier - Ok - 9ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\30.vir is RAR archive
>>C:\Users\Shiloh\Desktop\2015.9.13\30.vir\RASTREAMENTO_COD_UNI=PE179897046BR.vbe - packed by ENCODED SCRIPT
C:\Users\Shiloh\Desktop\2015.9.13\30.vir\RASTREAMENTO_COD_UNI=PE179897046BR.vbe - infected with VBS.DownLoader.399
C:\Users\Shiloh\Desktop\2015.9.13\30.vir\RASTREAMENTO_COD_UNI=PE179897046BR.vbe - infected
C:\Users\Shiloh\Desktop\2015.9.13\30.vir - infected archive
C:\Users\Shiloh\Desktop\2015.9.13\30.vir - infected archive - 67ms, 3688 bytes
C:\Users\Shiloh\Desktop\2015.9.13\30.vir:Zone.Identifier - Ok - 7ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\29.vir - infected with Trojan.Packed.32793
C:\Users\Shiloh\Desktop\2015.9.13\29.vir - infected - 308ms, 182074 bytes
C:\Users\Shiloh\Desktop\2015.9.13\31.vir:Zone.Identifier - Ok - 11ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\27.vir\wpe\SetPriv.dll - Ok
C:\Users\Shiloh\Desktop\2015.9.13\27.vir\wpe\WPE PRO - modified.exe - is riskware program Program.Wpe.645
C:\Users\Shiloh\Desktop\2015.9.13\27.vir\wpe\WPE PRO - modified.exe - infected
C:\Users\Shiloh\Desktop\2015.9.13\31.vir - Ok - 331ms, 124416 bytes
C:\Users\Shiloh\Desktop\2015.9.13\32.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\27.vir\wpe\WpeSpy.dll - is riskware program Program.Wpe.863
C:\Users\Shiloh\Desktop\2015.9.13\27.vir\wpe\WpeSpy.dll - infected
C:\Users\Shiloh\Desktop\2015.9.13\27.vir - infected archive
C:\Users\Shiloh\Desktop\2015.9.13\27.vir - infected archive - 638ms, 355468 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\33.vir is RTF container
C:\Users\Shiloh\Desktop\2015.9.13\33.vir:Zone.Identifier - Ok - 7ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\33.vir\OLEstream-1 - Ok
C:\Users\Shiloh\Desktop\2015.9.13\33.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.13\33.vir - container - 17ms, 105772 bytes
C:\Users\Shiloh\Desktop\2015.9.13\34.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\34.vir - infected with Trojan.DownLoader10.29171
C:\Users\Shiloh\Desktop\2015.9.13\34.vir - infected - 292ms, 29184 bytes
C:\Users\Shiloh\Desktop\2015.9.13\35.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\35.vir - Ok - 339ms, 31232 bytes
C:\Users\Shiloh\Desktop\2015.9.13\36.vir:Zone.Identifier - Ok - 11ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\37.vir is RAR archive
C:\Users\Shiloh\Desktop\2015.9.13\37.vir\Nota-fiscal-eletronica-PDF.exe - Ok
C:\Users\Shiloh\Desktop\2015.9.13\37.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.13\37.vir - archive - 365ms, 181409 bytes
C:\Users\Shiloh\Desktop\2015.9.13\36.vir - infected with BackDoor.Comet.2020
C:\Users\Shiloh\Desktop\2015.9.13\36.vir - infected - 427ms, 674304 bytes
C:\Users\Shiloh\Desktop\2015.9.13\37.vir:Zone.Identifier - Ok - 7ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\38.vir is OPEN XML container
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\[Content_Types].xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir:Zone.Identifier - Ok - 33ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\_rels\.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\_rels\workbook.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\workbook.xml - Ok
>C:\Users\Shiloh\Desktop\2015.9.13\39.vir is RTF container
C:\Users\Shiloh\Desktop\2015.9.13\39.vir\OLEstream-1 - Ok
C:\Users\Shiloh\Desktop\2015.9.13\39.vir - probably infected with Exploit.Rtf.CVE2012-0158
C:\Users\Shiloh\Desktop\2015.9.13\39.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.13\39.vir - infected container - 47ms, 39917 bytes
C:\Users\Shiloh\Desktop\2015.9.13\39.vir:Zone.Identifier - Ok - 10ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\worksheets\sheet1.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\sharedStrings.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\drawings\vmlDrawing1.vml - Ok
>C:\Users\Shiloh\Desktop\2015.9.13\32.vir is NSIS container
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\script.bin - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\Alarm1.bat - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\Alarm2.bat - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\ApacheExit.Bat - Ok
C:\Users\Shiloh\Desktop\2015.9.13\40.vir - infected with Trojan.DownLoader16.6815
C:\Users\Shiloh\Desktop\2015.9.13\40.vir - infected - 456ms, 331264 bytes
C:\Users\Shiloh\Desktop\2015.9.13\40.vir:Zone.Identifier - Ok - 26ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\41.vir - infected with Linux.BackDoor.Tsunami.77
C:\Users\Shiloh\Desktop\2015.9.13\41.vir - infected - 50ms, 178408 bytes
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENS.exe - Ok
C:\Users\Shiloh\Desktop\2015.9.13\41.vir:Zone.Identifier - Ok - 25ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENSApp.exe - Ok
>C:\Users\Shiloh\Desktop\2015.9.13\42.vir is ZIP archive
C:\Users\Shiloh\Desktop\2015.9.13\42.vir\uvd16\DATA.UVD - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENSDCry.exe - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir\uvd16\INSTAL.TXT - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir\uvd16\UVD.001 - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENSExit.Bat - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir\uvd16\UVD.002 - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir\uvd16\UVD.003 - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir\uvd16\UVDICON.RSC - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir\uvd16\UVD_1_6.PRG - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENSMail.exe - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir\uvd16\DOCS\HISTORY.TXT - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir\uvd16\DOCS\MANUAL.TXT - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir\uvd16\DOCS\SEX.TXT - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir\uvd16\DOCS\STATS.TXT - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir\uvd16\DOCS\UPDATE.TXT - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.13\42.vir - archive - 166ms, 80960 bytes
C:\Users\Shiloh\Desktop\2015.9.13\42.vir:Zone.Identifier - Ok - 14ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\43.vir is JAR container
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\META-INF\MANIFEST.MF - Ok
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\b.txt - Ok
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\a.txt - Ok
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\a\CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzl.class - Ok
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\b\CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzl.class - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENScan.exe - Ok
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\c\CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzl.class - Ok
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzl.class - Ok
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\Main.class - infected with Java.Adwind.37
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\Main.class - infected
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzc.class - Ok
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzo.class - Ok
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzf.class - Ok
C:\Users\Shiloh\Desktop\2015.9.13\43.vir\CBRaYGoSqAslV5N2LMjnAIfijUjaJw7cErINltFlUD2VbarFqfRtVTJ0jQ1ZQw2ZXMvqCZgaMwILaBVbxFi6Y7TJPbEji4uI2v6UxnZQwf9tWlUTQzWCr4RcxwTV8UVadJ5IqdhlgRwS6HjzmTpm3fHEHl4Rzipdgrgr0qn7htqJtcFndtcioul6fejHJ0JNDkFuCjnjDalba4Jb1dRaA75JCpu0wu1rhydnX5595ikAB6sw2tfnQoC6Dr1mtlYLEYNBGK6E9ZKjSYJgksNnQEYHJ7ygVPAKzb.class - Ok
C:\Users\Shiloh\Desktop\2015.9.13\43.vir - infected container
C:\Users\Shiloh\Desktop\2015.9.13\43.vir - infected container - 303ms, 110679 bytes
C:\Users\Shiloh\Desktop\2015.9.13\43.vir:Zone.Identifier - Ok - 8ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\sqlite3.dll - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\Admin.php - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\Test.php - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\.sqliterc - Ok
C:\Users\Shiloh\Desktop\2015.9.13\44.vir - Ok - 446ms, 169984 bytes
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\APT1.ocfg - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\AddBlock.bat - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\AddPBKDF2.bat - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\AddShare.bat - Ok
C:\Users\Shiloh\Desktop\2015.9.13\44.vir:Zone.Identifier - Ok - 75ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\AddVT.bat - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\styles.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\AddWGet.bat - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\worksheets\_rels\sheet1.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\Apache.db - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\ApacheView.db - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\theme\theme1.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\externalLinks\externalLink3.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENSApp.html - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\externalLinks\_rels\externalLink1.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENSIIS.db - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\externalLinks\_rels\externalLink3.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENScan.db - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\externalLinks\externalLink1.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\externalLinks\_rels\externalLink4.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\externalLinks\_rels\externalLink2.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\docProps\core.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\docProps\app.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\externalLinks\externalLink4.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\printerSettings\printerSettings1.bin - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\comments1.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\calcChain.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir\xl\externalLinks\externalLink2.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.13\38.vir - container - 1858ms, 350173 bytes
C:\Users\Shiloh\Desktop\2015.9.13\45.vir:Zone.Identifier - Ok - 4ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\46.vir - infected with Linux.Mrblack.6
C:\Users\Shiloh\Desktop\2015.9.13\46.vir - infected - 0ms, 763528 bytes
C:\Users\Shiloh\Desktop\2015.9.13\46.vir:Zone.Identifier - Ok - 5ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OShells.ocfg - Ok
C:\Users\Shiloh\Desktop\2015.9.13\45.vir - infected with Trojan.Packed.2364
C:\Users\Shiloh\Desktop\2015.9.13\45.vir - infected - 293ms, 252766 bytes
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OmensList.bat - Ok
C:\Users\Shiloh\Desktop\2015.9.13\47.vir:Zone.Identifier - Ok - 7ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\48.vir is OPEN XML container
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\[Content_Types].xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\_rels\.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\RedOct.ocfg - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\_rels\workbook.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\SLIC-APT1.ocfg - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\workbook.xml - Ok
>>C:\Users\Shiloh\Desktop\2015.9.13\32.vir\WGetIni.ocfg is JS-HTML container
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\WGetIni.ocfg\JSTag_1[eb][711] - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\WGetIni.ocfg - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\worksheets\sheet1.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\sharedStrings.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\drawings\vmlDrawing1.vml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\47.vir - infected with Trojan.Siggen3.46029
C:\Users\Shiloh\Desktop\2015.9.13\47.vir - infected - 368ms, 335360 bytes
C:\Users\Shiloh\Desktop\2015.9.13\48.vir:Zone.Identifier - Ok - 12ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\sqlite3.exe - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\CreditsAndLcense.txt - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OBlockIIS.html - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENS.css - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENS.html - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENSApp.html - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir\OMENSLogo2.png - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.13\32.vir - container - 3320ms, 996800 bytes
C:\Users\Shiloh\Desktop\2015.9.13\49.vir:Zone.Identifier - Ok - 8ms, 26 bytes
C:\Users\Shiloh\Desktop\2015.9.13\50.vir - Ok - 312ms, 131072 bytes
C:\Users\Shiloh\Desktop\2015.9.13\50.vir:Zone.Identifier - Ok - 5ms, 26 bytes
>C:\Users\Shiloh\Desktop\2015.9.13\49.vir is BINARYRES container
>>C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001 is RAR archive
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cba - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cbb - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cbc - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cbe - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cbg - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cbgi - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cbh - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cbj - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cbm - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cbp - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cbs - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cbt - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cbtt - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cib - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.cit - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001\Anti-Stonewall\Anti-Stonewall.flags - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data001 - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\styles.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir\data002 - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.13\49.vir - container - 775ms, 192784 bytes
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\worksheets\_rels\sheet1.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\theme\theme1.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\externalLinks\externalLink3.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\externalLinks\_rels\externalLink1.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\externalLinks\_rels\externalLink3.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\externalLinks\externalLink1.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\externalLinks\_rels\externalLink4.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\externalLinks\_rels\externalLink2.xml.rels - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\docProps\core.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\docProps\app.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\externalLinks\externalLink4.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\printerSettings\printerSettings1.bin - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\comments1.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\calcChain.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir\xl\externalLinks\externalLink2.xml - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir - Ok
C:\Users\Shiloh\Desktop\2015.9.13\48.vir - container - 1109ms, 350167 bytes
Total 10072418 bytes in 100 files scanned (271 objects, 6 containers)
Total 70 files (232 objects) are clean
Total 29 files (30 objects) are infected
Total 1 file (2 objects) are suspicious
Scan time is 00:00:06.328
-----------------------------------------------------------------------------
Start curing
-----------------------------------------------------------------------------
C:\Users\Shiloh\Desktop\2015.9.13\04.vir - quarantined - 1047 ms
C:\Users\Shiloh\Desktop\2015.9.13\06.vir - quarantined - 27 ms
C:\Users\Shiloh\Desktop\2015.9.13\07.vir - quarantined - 27 ms
C:\Users\Shiloh\Desktop\2015.9.13\10.vir - quarantined - 33 ms
C:\Users\Shiloh\Desktop\2015.9.13\11.vir - quarantined - 23 ms
C:\Users\Shiloh\Desktop\2015.9.13\12.vir - quarantined - 71 ms
C:\Users\Shiloh\Desktop\2015.9.13\13.vir - quarantined - 26 ms
C:\Users\Shiloh\Desktop\2015.9.13\14.vir - quarantined - 123 ms
C:\Users\Shiloh\Desktop\2015.9.13\09.vir - quarantined - 82 ms
C:\Users\Shiloh\Desktop\2015.9.13\15.vir - quarantined - 82 ms
C:\Users\Shiloh\Desktop\2015.9.13\16.vir - quarantined - 55 ms
C:\Users\Shiloh\Desktop\2015.9.13\19.vir - quarantined - 47 ms
C:\Users\Shiloh\Desktop\2015.9.13\18.vir - quarantined - 44 ms
C:\Users\Shiloh\Desktop\2015.9.13\23.vir - quarantined - 118 ms
C:\Users\Shiloh\Desktop\2015.9.13\22.vir - quarantined - 555 ms
C:\Users\Shiloh\Desktop\2015.9.13\24.vir - quarantined - 39 ms
C:\Users\Shiloh\Desktop\2015.9.13\25.vir - quarantined - 31 ms
C:\Users\Shiloh\Desktop\2015.9.13\26.vir - quarantined - 49 ms
C:\Users\Shiloh\Desktop\2015.9.13\30.vir - quarantined - 25 ms
C:\Users\Shiloh\Desktop\2015.9.13\29.vir - quarantined - 49 ms
C:\Users\Shiloh\Desktop\2015.9.13\27.vir - quarantined - 32 ms
C:\Users\Shiloh\Desktop\2015.9.13\34.vir - quarantined - 41 ms
C:\Users\Shiloh\Desktop\2015.9.13\36.vir - quarantined - 79 ms
C:\Users\Shiloh\Desktop\2015.9.13\39.vir - quarantined - 24 ms
C:\Users\Shiloh\Desktop\2015.9.13\40.vir - quarantined - 71 ms
C:\Users\Shiloh\Desktop\2015.9.13\41.vir - quarantined - 33 ms
C:\Users\Shiloh\Desktop\2015.9.13\43.vir - quarantined - 29 ms
C:\Users\Shiloh\Desktop\2015.9.13\46.vir - quarantined - 43 ms
C:\Users\Shiloh\Desktop\2015.9.13\45.vir - quarantined - 51 ms
C:\Users\Shiloh\Desktop\2015.9.13\47.vir - quarantined - 55 ms
Total 10072418 bytes in 100 files scanned (271 objects, 6 containers)
Total 70 files (232 objects) are clean
Total 29 files (30 objects) are infected
Total 1 file (2 objects) are suspicious
Total 30 files (32 objects) are neutralized
Scan time is 00:00:06.328
[/mw_shl_code] |