本帖最后由 驭龙 于 2016-9-6 11:08 编辑
蜘蛛11 杀24个,剩余26个,其中四个应用程序双击,一个需NET 4,三个运行成功,蜘蛛未拦截,其余样本没有测试。
============================================
SEP 14.0 Beta杀十六个
剩余的样本中EXE双击,其中02 39 41需要NET 架构,没有运行成功
01样本杀。
48样本杀。
08样本杀。
38样本,机器学习杀衍生物,之后样本崩溃。
============================================
NS 22.8杀15个?咋比SEP 14.0 Beta少杀一个45个?
双击剩余的EXE样本,SONAR杀5个,比SEP 14.0 Beta多杀两个?41和02样本我这里是没有运行基础的,双击为啥杀?
扫描日志
[mw_shl_code=css,true]Scan Information:
Virus Defs Version: 2016.09.05.008
Virus Defs Seq ID: 180362
Scan Statistics:
Scan Start:
Local: 2016/9/6 10:36
UTC: 2016/9/6 2:36
Scan Time: 173 seconds
Scan Targets: C:\Users\win7\Desktop\2016.9.6
Counts:
Total items scanned: 166
- Files & Directories: 166
- Registry Entries: 0
- Processes & Start-up Items: 0
- Network & Browser Items: 0
- Other: 0
- Trusted Files: 0
- Skipped Files: 0
Total security risks detected: 15
Total items resolved: 15
Total items that require attention: 0
Resolved Threats:
Trojan.Gen.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 Infected File
- Deleted
Trojan.Gen.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 Infected File
- Deleted
Trojan.Gen.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 Infected File
- Deleted
Trojan.Gen.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 Infected File
- Deleted
Trojan.Gen.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 Infected File
- Deleted
Trojan.Gen.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 Infected File
- Deleted
W97M.Downloader
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
4 Infected Files
c:\users\win7\desktop\2016.9.6\32.vir.docx - Deleted
c:\users\win7\desktop\2016.9.6\25.vir.docx - Deleted
c:\users\win7\desktop\2016.9.6\18.vir.docx - Deleted
c:\users\win7\desktop\2016.9.6\46.vir.doc - Deleted
1 Browser Cache
JS.Downloader
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
4 Infected Files
c:\users\win7\desktop\2016.9.6\26.vir.js - Deleted
c:\users\win7\desktop\2016.9.6\34.vir.js - Deleted
c:\users\win7\desktop\2016.9.6\43.vir.js - Deleted
c:\users\win7\desktop\2016.9.6\47.vir.html - Deleted
1 Browser Cache
Infostealer.Limitail
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Restart Required
-----------
4 Registry Entries
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:0 - Repaired
HKEY_USERS\S-1-5-21-2659075863-1198174949-3749575506-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:0 - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusDisableNotify:0 - Repaired
1 Infected File
c:\users\win7\desktop\2016.9.6\03.vir.exe - Restart Required
1 Browser Cache
Heur.AdvML.B
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 Infected File
c:\users\win7\desktop\2016.9.6\28.vir.exe - Deleted
1 Browser Cache
JS.Nemucod
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 Infected File
c:\users\win7\desktop\2016.9.6\15.vir.html - Deleted
1 Browser Cache
Trojan.Swifi
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 Infected File
c:\users\win7\desktop\2016.9.6\19.vir.swf - Deleted
1 Browser Cache
Ransom.Locky
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 Infected File
c:\users\win7\desktop\2016.9.6\31.vir.dll - Deleted
1 Browser Cache
Trojan.Gen.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 Infected File
c:\users\win7\desktop\2016.9.6\11.vir.dll - Deleted
1 Browser Cache
Ransom.HiddenTear
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 Infected File
c:\users\win7\desktop\2016.9.6\49.vir.exe - Deleted
1 Browser Cache
Unresolved Threats:
No unresolved risks[/mw_shl_code] |