12
返回列表 发新帖
楼主: Flying_Bird
收起左侧

[病毒样本] HydraCrypt

[复制链接]
hooyuan
发表于 2016-2-6 17:43:16 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
aboringman
发表于 2016-2-6 18:22:01 | 显示全部楼层
AVG:

扫描:pass;

双击:关闭监控,实机双击,IDP三杀。

"";"IDP.Trojan.E57AE798, C:\Users\kiiler\Desktop\5479329c03e12e27adc81caeefe1a1dc26bf59d4dac36dd2eae008213e8fe0a2.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/6, 17:28:29"
"";", C:\Users\kiiler\Desktop\5479329c03e12e27adc81caeefe1a1dc26bf59d4dac36dd2eae008213e8fe0a2.exe";"Object was blocked";"Process";"2016/2/6, 17:28:29"
"";", C:\Users\kiiler\Desktop\5479329c03e12e27adc81caeefe1a1dc26bf59d4dac36dd2eae008213e8fe0a2.exe";"Object was blocked";"Process";"2016/2/6, 17:28:29"

"";"IDP.Trojan.2F94A581, C:\Users\kiiler\Desktop\afd3b729cf99fb9ea441f42862a4835d1d6eeb36ee535f9b206e3a00382c972e.exe";"Healed, Moved to Virus Vault";"File or Directory";"2016/2/6, 17:28:57"
"";", C:\Users\kiiler\Desktop\afd3b729cf99fb9ea441f42862a4835d1d6eeb36ee535f9b206e3a00382c972e.exe";"Object was blocked";"Process";"2016/2/6, 17:28:57"
"";", C:\Users\kiiler\Desktop\afd3b729cf99fb9ea441f42862a4835d1d6eeb36ee535f9b206e3a00382c972e.exe";"Object was blocked";"Process";"2016/2/6, 17:28:57"
"";", HKEY_USERS\S-1-5-21-2236816692-667211127-2861217297-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\MICROSOFT INTERNET EXPLORER UPDATE";"Deleted, Moved to Virus Vault";"Registry value";"2016/2/6, 17:28:57"

"";"IDP.Trojan.72776A42, C:\Users\kiiler\Desktop\1a6bed2afff1b9880e42a29cea9b8139bcb12e34085fb008de13aa983b82a4f2.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2016/2/6, 18:17:21"
"";", C:\Users\kiiler\Desktop\1a6bed2afff1b9880e42a29cea9b8139bcb12e34085fb008de13aa983b82a4f2.exe";"Object was blocked";"Process";"2016/2/6, 18:17:21"
"";", C:\Users\kiiler\Desktop\1a6bed2afff1b9880e42a29cea9b8139bcb12e34085fb008de13aa983b82a4f2.exe";"Object was blocked";"Process";"2016/2/6, 18:17:21"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2016/2/6, 18:17:21"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2016/2/6, 18:17:21"
"";", C:\Windows\System32\cmd.exe";"Object was blocked";"Process";"2016/2/6, 18:17:21"
"";", C:\Users\kiiler\Desktop\1a6bed2afff1b9880e42a29cea9b8139bcb12e34085fb008de13aa983b82a4f2.exe";"Object was blocked";"Process";"2016/2/6, 18:17:21"
"";", HKEY_USERS\S-1-5-21-2236816692-667211127-2861217297-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\MICROSOFT INTERNET EXPLORER UPDATE";"Deleted, Moved to Virus Vault";"Registry value";"2016/2/6, 18:17:21"

275751198
发表于 2016-2-6 19:35:23 | 显示全部楼层
扫描结果
======================
高危风险项
----------------------
D:\邮件\新建文件夹\新建文件夹 (2)\新建文件夹\新建文件夹 (3)\新建文件夹 (5)\搬运中转站\HydraCrypt\1a6bed2afff1b9880e42a29cea9b8139bcb12e34085fb008de13aa983b82a4f2        感染型病毒(Win32/Trojan.a61)        已删除
D:\邮件\新建文件夹\新建文件夹 (2)\新建文件夹\新建文件夹 (3)\新建文件夹 (5)\搬运中转站\HydraCrypt\5479329c03e12e27adc81caeefe1a1dc26bf59d4dac36dd2eae008213e8fe0a2        HEUR/QVM07.1.Malware.Gen        已删除
D:\邮件\新建文件夹\新建文件夹 (2)\新建文件夹\新建文件夹 (3)\新建文件夹 (5)\搬运中转站\HydraCrypt\afd3b729cf99fb9ea441f42862a4835d1d6eeb36ee535f9b206e3a00382c972e        HEUR/QVM07.1.Malware.Gen        已删除
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-16 11:29 , Processed in 0.094139 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表