mes检测26,修复2个。
[mw_shl_code=css,true]5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\30.vir\__substg1.0_37010102\word/vbaProject.bin\_VBA_PROJECT. The Trojan named W97M/Downloader.bbl was detected and deleted.
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\_nUl.class. The Trojan named Adwind!0E5C2A119C7F was detected and deleted.
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\10.vir. The Trojan named JS/Nemucod.jt was detected and deleted.
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\49.vir\__substg1.0_37010102\ca4b4812.js. The Trojan named JS/Nemucod.ik was detected and deleted.
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\23.vir. The Trojan named Dropper-FQZ!E5E99CED98A8 was detected and deleted.
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:30 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\33.vir. The Trojan named Downloader-FBEY!1C16AB19DC59 was detected and deleted.
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\11.vir. The Trojan named Downloader-FBEW!0B8DC48FA95B was detected and deleted.
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\_aUX.class. The Trojan named Adwind!F44CE99ADFE6 was detected and deleted.
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\37.vir\classes.dex. The Trojan named Artemis!AB4E8BCAAC56 was detected and deleted.
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:31 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\_nuL.class. The Trojan named Adwind!A5DB890F249A was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\22.vir. The Trojan named GenericR-HRJ!B4AE56E690F9 was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\01.vir. The Trojan named Ransomware-FLY!185D64764428 was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\06.vir. The Trojan named GenericR-AWM!2708A9CFC5E6 was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\16.vir. The Trojan named Ransomware-FLY!590F171ECC84 was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\31.vir. The Trojan named Ransomware-FMC!A747CF73E5A6 was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\40.vir\__substg1.0_37010102\items65426004.pdf.exe. The Trojan named Downloader-FBEO!A08AB20ED4C3 was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\38.vir. The Trojan named Ransomware-FLY!9DF42576A539 was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\07.vir. The Trojan named Ransomware-FLW!691583917F38 was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\34.vir. The Trojan named Fareit-FEL!F636F1E07A34 was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\_CON.class. The Trojan named Adwind!A9327F17942A was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\_aux.class. The Trojan named Adwind!7D7ACDC3366A was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\_Con.class. The Trojan named Adwind!63B5E7585A4C was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\_nUL.class. The Trojan named Adwind!E23A17C2B04A was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\_cOn.class. The Trojan named RDN/Adwind was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\_Prn.class. The Trojan named RDN/Adwind was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\_auX.class. The Trojan named RDN/Adwind was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\NOD32.class. The Trojan named RDN/Adwind was detected and deleted.
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:32 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:33 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\_Nul.class. The Trojan named Adwind!99DDF9A3B6FF was detected and deleted.
5/31/2016 11:21:33 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:33 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:33 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:33 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:33 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\13.vir\_nul.class. The Trojan named RDN/Adwind was detected and deleted.
5/31/2016 11:21:33 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:33 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:33 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:33 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\18.vir\word/vbaProject.bin. The Trojan named Downloader-FBGA!658874D049C8 was detected and deleted.
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\24.vir\word/vbaProject.bin. The Trojan named Downloader-FBGA!D846F3C41737 was detected and deleted.
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\08.vir\word/vbaProject.bin. The Trojan named Downloader-FBGA!A4168EDBBB55 was detected and deleted.
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\17.vir\word/vbaProject.bin. The Trojan named Downloader-FBGA!72527BC245BE was detected and deleted.
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\28.vir\word/vbaProject.bin. The Trojan named Downloader-FBGA!EAA15E820D29 was detected and deleted.
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\41.vir\word/vbaProject.bin. The Trojan named Downloader-FBGA!F8225D64B572 was detected and deleted.
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\48.vir\word/vbaProject.bin. The Trojan named Downloader-FBGA!CCA36F5E66ED was detected and deleted.
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:35 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
5/31/2016 11:21:36 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\50.vir\__substg1.0_37010102. The Trojan named Downloader-FBDJ!DEAC7C285D12 was detected and deleted.
5/31/2016 11:21:36 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:36 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:36 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:36 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
5/31/2016 11:21:37 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: JEFF-ALIENW17\jeff6 ran C:\PROGRAM FILES\WINRAR\WINRAR.EXE, which attempted to access D:\Virus\2016.6.1\02.vir\5.nsis. The Trojan named RDN/Ransom was detected and deleted.
5/31/2016 11:21:37 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Additional information:
5/31/2016 11:21:37 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
5/31/2016 11:21:37 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
5/31/2016 11:21:37 PM mfetp(3972.4284) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027[/mw_shl_code] |