诺顿检测24,修复3个。
[mw_shl_code=css,true]Resolved Threats:
Trojan.Gen.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
- Deleted
Trojan.Gen
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
- Deleted
W97M.Downloader
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
4 Files
d:\virus\2016.2.7\10.vir - Deleted
d:\virus\2016.2.7\50.vir - Repaired
d:\virus\2016.2.7\43.vir - Deleted
d:\virus\2016.2.7\44.vir - Deleted
1 Browser Cache
Trojan.Gen
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
2 Files
d:\virus\2016.2.7\06.vir - Deleted
d:\virus\2016.2.7\47.vir - Deleted
1 Browser Cache
JS.Downloader
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
2 Files
d:\virus\2016.2.7\15.vir - Deleted
d:\virus\2016.2.7\49.vir - Deleted
1 Browser Cache
Trojan.Gen.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
3 Files
d:\virus\2016.2.7\11.vir - Deleted
d:\virus\2016.2.7\03.vir - Deleted
d:\virus\2016.2.7\35.vir - Deleted
1 Browser Cache
PUA.MyPCBackup
Type: Anomaly
Risk: Low (Low Stealth, Low Removal, Low Performance, Low Privacy)
Categories: Security Risk
Status: Fully Resolved
-----------
82 Registry Entries
HKEY_CLASSES_ROOT\CLSID\{2097A1B6-E86A-4072-A32D-2249A3ECBC5A} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{2097A1B6-E86A-4072-A32D-2249A3ECBC5A} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{3070CF0C-F396-3DCA-87D6-9DBF3D77B610} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{3070CF0C-F396-3DCA-87D6-9DBF3D77B610} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{4529EB14-6B38-3CC4-9504-6EAB6C9E1255} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{4529EB14-6B38-3CC4-9504-6EAB6C9E1255} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{BEEA930F-CD8A-341E-B6B5-5BAF659685D5} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{BEEA930F-CD8A-341E-B6B5-5BAF659685D5} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00004} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00004} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00005} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00005} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00006} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00006} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00007} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00007} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00008} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00008} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00009} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00009} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000A} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000A} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000B} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000B} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000C} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000C} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000D} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000D} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000E} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000E} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000F} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000F} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{F03955F1-309E-34E9-A021-1399C3532273} - No Action Required
HKEY_CLASSES_ROOT\CLSID\{F03955F1-309E-34E9-A021-1399C3532273} - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MyPC Backup - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MyPC Backup - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup - No Action Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\MyPC Backup - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\MyPC Backup - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\MyPC Backup - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\MyPC Backup - No Action Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\MyPC Backup - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\MyPC Backup - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\MyPC Backup - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\MyPC Backup - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\BackupGenie - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\BackupGenie - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BackupGenie - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BackupGenie - No Action Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\BackupGenie - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\BackupGenie - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\BackupGenie - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\BackupGenie - No Action Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\BackupGenie - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\BackupGenie - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\BackupGenie - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\BackupGenie - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\JustCloud - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\JustCloud - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\JustCloud - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\JustCloud - No Action Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\JustCloud - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\JustCloud - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\JustCloud - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\JustCloud - No Action Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\JustCloud - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\JustCloud - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\JustCloud - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\JustCloud - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ZipCloud - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ZipCloud - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZipCloud - No Action Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZipCloud - No Action Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\ZipCloud - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\ZipCloud - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\ZipCloud - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\ZipCloud - No Action Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\ZipCloud - No Action Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\ZipCloud - No Action Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\ZipCloud - No Action Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\ZipCloud - No Action Required
21 Files
C:\Users\jeff6\Desktop\MyPC Backup.lnk - No Action Required
C:\Users\Public\Desktop\MyPC Backup.lnk - No Action Required
C:\Users\jeff6\Start Menu\Programs\Startup\MyPC Backup.lnk - No Action Required
C:\Users\jeff6\AppData\Local\virtualstore\programdata\microsoft\windows\start menu\programs\startup\mypc backup.lnk - No Action Required
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk - No Action Required
C:\Users\Public\Desktop\JustCloud.lnk - No Action Required
C:\Users\jeff6\Desktop\JustCloud.lnk - No Action Required
C:\Users\jeff6\Start Menu\Programs\Startup\JustCloud.lnk - No Action Required
C:\Users\jeff6\AppData\Local\virtualstore\programdata\microsoft\windows\start menu\programs\startup\justcloud.lnk - No Action Required
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\JustCloud.lnk - No Action Required
C:\Users\Public\Desktop\ZipCloud.lnk - No Action Required
C:\Users\jeff6\Desktop\ZipCloud.lnk - No Action Required
C:\Users\jeff6\Start Menu\Programs\Startup\ZipCloud.lnk - No Action Required
C:\Users\jeff6\AppData\Local\virtualstore\programdata\microsoft\windows\start menu\programs\startup\zipcloud.lnk - No Action Required
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ZipCloud.lnk - No Action Required
C:\Users\Public\Desktop\BackupGenie.lnk - No Action Required
C:\Users\jeff6\Desktop\BackupGenie.lnk - No Action Required
C:\Users\jeff6\Start Menu\Programs\Startup\BackupGenie.lnk - No Action Required
C:\Users\jeff6\AppData\Local\virtualstore\programdata\microsoft\windows\start menu\programs\startup\backupgenie.lnk - No Action Required
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BackupGenie.lnk - No Action Required
d:\virus\2016.2.7\12.vir - Deleted
1 Browser Cache
Trojan.Cryptolocker.H
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\virus\2016.2.7\20.vir - Deleted
1 Browser Cache
Infostealer.Limitail
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
8 Registry Entries
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NofolderOptions:0 - Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:0 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:0 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sr\Parameters\->FirstRun:0 - Repaired
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:0 - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusDisableNotify:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusDisableNotify:0 - Repaired
2 Files
d:\virus\2016.2.7\13.vir - Deleted
d:\virus\2016.2.7\17.vir - Deleted
1 Browser Cache
W32.Pilleuz
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\virus\2016.2.7\31.vir - Deleted
1 Browser Cache
Trojan.Zbot
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Restart Required
-----------
41 Registry Entries
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\gHcq8R9 - Restart Required
HKEY_USERS\S-1-5-19\Software\gHcq8R9 - Restart Required
HKEY_USERS\S-1-5-20\Software\gHcq8R9 - Restart Required
HKEY_USERS\.DEFAULT\Software\gHcq8R9 - Restart Required
HKEY_CLASSES_ROOT\CLSID\{DE7CBE17-0368-40E2-8357-1639DA027BAB} - Restart Required
HKEY_CLASSES_ROOT\PPT_Test.Application - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon->Userinit:C:\WINDOWS\SysWOW64\userinit.exe, - Restart Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Run->userinit - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run->userinit - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run->userinit - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run->userinit - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion->Win32 - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network->UID - Restart Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network->UID - Restart Required
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network->UID - Restart Required
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network->UID - Restart Required
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network->UID - Restart Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\{19127AD2-394B-70F5-C650-B97867BAA1F7} - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\{19127AD2-394B-70F5-C650-B97867BAA1F7} - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\{19127AD2-394B-70F5-C650-B97867BAA1F7} - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{19127AD2-394B-70F5-C650-B97867BAA1F7} - Restart Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\{35106240-D2F0-DB35-716E-127EB80A0299} - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\{35106240-D2F0-DB35-716E-127EB80A0299} - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\{35106240-D2F0-DB35-716E-127EB80A0299} - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{35106240-D2F0-DB35-716E-127EB80A0299} - Restart Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} - Restart Required
HKEY_CLASSES_ROOT\Cad.Document - Restart Required
HKEY_CLASSES_ROOT\.max - Restart Required
HKEY_CLASSES_ROOT\.max - Restart Required
HKEY_CLASSES_ROOT\Matrix.Document - Restart Required
HKEY_CLASSES_ROOT\Matrix.Document - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.max - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Matrix.Document - Restart Required
HKEY_USERS\S-1-5-21-1523581685-1367262481-2280446090-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableTaskMgr:0 - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableTaskMgr:0 - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableTaskMgr:0 - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableTaskMgr:0 - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system->EnableLUA:1 - Restart Required
9 Files
C:\Users\jeff6\AppData\Local\virtualstore\windows\syswow64\ntos.exe - Restart Required
C:\WINDOWS\SysWOW64\ntos.exe - Restart Required
C:\Users\jeff6\AppData\Local\virtualstore\windows\syswow64\wsnpoem\audio.dll - Restart Required
C:\WINDOWS\SysWOW64\wsnpoem\audio.dll - Restart Required
C:\Users\jeff6\AppData\Local\virtualstore\windows\syswow64\wsnpoem\video.dll - Restart Required
C:\WINDOWS\SysWOW64\wsnpoem\video.dll - Restart Required
C:\Users\jeff6\AppData\Local\virtualstore\windows\syswow64\wsnpoem - Restart Required
C:\WINDOWS\SysWOW64\wsnpoem - Restart Required
d:\virus\2016.2.7\39.vir - Deleted
1 Browser Cache
Trojan.Potao
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\virus\2016.2.7\16.vir - Deleted
1 Browser Cache
Suspicious.Cloud.5
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
d:\virus\2016.2.7\42.vir - Deleted
1 Browser Cache
Trojan.Cryptlock.N!g1
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\virus\2016.2.7\46.vir - Deleted
1 Browser Cache
Trojan.Gen.SMH
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\virus\2016.2.7\27.vir - Deleted
1 Browser Cache
SAPE.Heur.AAF10
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
d:\virus\2016.2.7\28.vir - Deleted
1 Browser Cache[/mw_shl_code] |