本帖最后由 欧阳宣 于 2016-12-19 09:43 编辑
MES占位,久违了
检测17,修复4个。
[mw_shl_code=css,true]12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\03.vir\_VBA_PROJECT. The Trojan named W97M/Downloader.bni was detected and deleted.
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\07.vir\00000042.js. The Trojan named JS/Nemucod.qh was detected and deleted.
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\06.vir\__substg1.0_37010102\IMPORTANT-zip-9219.zip\IMPORTANT-9219.js. The Trojan named JS/Nemucod.jp was detected and deleted.
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
12/18/2016 8:38:48 PM mfetp(4352.4900) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\08.vir\WordDocument. The Trojan named W97M/Downloader.brn was detected and deleted.
12/18/2016 8:38:48 PM mfetp(4352.4900) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:48 PM mfetp(4352.4900) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:48 PM mfetp(4352.4900) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:48 PM mfetp(4352.4900) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\14.vir\00000042.js. The Trojan named JS/Nemucod.qh was detected and deleted.
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\12.vir\WordDocument. The Trojan named X97M/Downloader.ax was detected and deleted.
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:48 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\24.vir\00000042.js. The Trojan named JS/Nemucod.qh was detected and deleted.
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\19.vir. The Trojan named JS/Nemucod.qj was detected and deleted.
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\30.vir\word/vbaProject.bin\_VBA_PROJECT. The Trojan named W97M/Downloader.bni was detected and deleted.
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\32.vir. The Trojan named JS/Nemucod.oa was detected and deleted.
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:49 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\33.vir. The Trojan named JS/Nemucod.px was detected and deleted.
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\35.vir\00000042.js. The Trojan named JS/Nemucod.qh was detected and deleted.
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1025
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\40.vir. The Trojan named JS/Nemucod.oa was detected and deleted.
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:50 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\36.vir. The Trojan named BackDoor-NJRat was detected and deleted.
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\18.vir. The Trojan named PWSZbot-FAWZ!2AFE617EDB33 was detected and deleted.
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\38.vir\10.nsis. The Trojan named NSIS/ObfusRansom.f was detected and deleted.
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:51 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1027
12/18/2016 8:38:55 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: JEFF-XPS13\jeff6 ran C:\Program Files\WinRAR\WinRAR.exe, which attempted to access C:\Virus\2016.12.19\28.vir\001098.pdf.exe. The Virus named Artemis!76D624EA723A was detected and deleted.
12/18/2016 8:38:55 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Additional information:
12/18/2016 8:38:55 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Primary Action: Clean
12/18/2016 8:38:55 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Secondary Action: Delete
12/18/2016 8:38:55 PM mfetp(4352.4904) <SYSTEM> oasbl.OAS.Activity: Event ID: 1280[/mw_shl_code] |