本帖最后由 小飞侠.net 于 2017-11-22 20:55 编辑
Emsisoft Emergency Kit - 版本 2017.10
上次更新: 2017/11/22 19:42:16
用户帐号: TECLAST\Admin
电脑名称: TECLAST
操作系统版本: Windows 10x64
扫描设置:
扫描方式: 自定义扫描
对象: Rootkits, 内存, C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\
检测流氓软件(PUPs): On
扫描压缩包: On
扫描邮件存档: On
ADS数据流: On
文件扩展名过滤: Off
直接磁盘访问: Off
扫描开始于: 2017/11/22 20:34:34
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(13).vir.rtf -> (objdata) 发现病毒: Exploit.RTF-ObfsStrm.Gen (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(18).vir.DOCM -> word/vbaProject.bin 发现病毒: VB:Trojan.VBA.Agent.PR (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(23).vir.rtf -> (objdata) -> (Embedded DocFile g) 发现病毒: Exploit.CVE-2017-11882.Gen (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(23).vir.rtf -> (objdata) -> (Equation.3) 发现病毒: Exploit.CVE-2017-11882.Gen (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(29).vir.DOCX -> word/_rels/document.xml.rels 发现病毒: Trojan.Doc.Downloader.AFO (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(39).vir.EML -> [Subject: avviso di pagamento][Date: Tue, 21 Nov 2017 18:00:10 +0900] -> 65829_[removed].xls 发现病毒: VB:Trojan.VBA.Downloader.HT (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(35).vir.DOCX -> word/_rels/document.xml.rels 发现病毒: Trojan.Doc.Downloader.AFO (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(40).vir.vbs -> [Subject: avviso di pagamento 21/11/2017][Date: Tue, 21 Nov 2017 10:02:29 +0100] -> 46812_[removed].xls 发现病毒: VB:Trojan.VBA.Downloader.HT (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(41).vir.EML -> [Subject: avviso di pagamento 21/11/2017][Date: Tue, 21 Nov 2017 10:27:43 +0100] -> 94134_[removed].xls 发现病毒: VB:Trojan.VBA.Downloader.HT (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(42).vir.vbs -> [Subject: pagamento 21.11.2017][Date: Tue, 21 Nov 2017 14:29:16 +0200] -> [removed]-3499.xls 发现病毒: VB:Trojan.VBA.Downloader.HT (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(8).vir.DOCX -> word/embeddings/oleObject1.bin -> Microsoft Office Opening.exe 发现病毒: Gen:Variant.MSIL.Mensa.8 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(49).vir.DOCX -> word/embeddings/oleObject1.bin -> Wed_Nov_22_2017_00_41_DOCX_.js 发现病毒: Exploit.OLE-JS.Gen.2 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(32).vir.DOCX -> word/embeddings/oleObject1.bin -> Wed_Nov_22_2017_00_41_DOCX_.js 发现病毒: Exploit.OLE-JS.Gen.2 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(11).vir.XLS 发现病毒: VB:Trojan.VBA.Downloader.HT (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(10).vir.exe 发现病毒: Trojan.GenericKD.12599874 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(12).vir.exe 发现病毒: Trojan.GenericKD.12597512 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(15).vir.exe 发现病毒: Gen:Variant.Razy.222987 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(16).vir.exe 发现病毒: Gen:Variant.Kazy.794951 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(22).vir.DOC 发现病毒: Trojan.Agent.CQTP (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(20).vir.exe 发现病毒: Gen:Variant.Jaiko.2649 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(25).vir.exe 发现病毒: Trojan.GenericKD.12602294 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(30).vir.sys 发现病毒: Trojan.Agent (A) [291576]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(3).vir.dll 发现病毒: Trojan.GenericKD.2551982 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(31).vir.exe 发现病毒: Trojan.Agent.CQTQ (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(33).vir.DOC 发现病毒: W97m.Downloader.GNA (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(21).vir.exe 发现病毒: Trojan.GenericKD.12601363 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(36).vir.sys 发现病毒: Trojan.Agent (A) [291576]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(45).vir.XLS 发现病毒: VB:Trojan.VBA.Downloader.HT (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(51).vir.exe 发现病毒: Gen:Variant.Symmi.80408 (B) [krnl.xmd]
已扫描 1776
  [:03:][:03:]发现 29
扫描完成后: 2017/11/22 20:35:08
扫描时间: 0:00:34
ESET Smart Security Premium 64位(高级启发式(Y)+压缩文件(Y)+自解压加壳(Y)+DNY智能签名(Y)++(Windows 10 Creators Update(Redstone 2)....):Found nothing
日志
正在扫描日志
检测引擎的版本: 16448P (20171121)
日期: 2017/11/22 时间: 20:27:20
已扫描的磁盘、文件夹和文件: C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(1).vir.exe - MSIL/CoinMiner.AFI 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(10).vir.exe - Win32/Spy.Zbot.ACZ 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(11).vir.XLS - VBA/TrojanDownloader.Agent.FKY 特洛伊木马 - 已清除
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(12).vir.exe - Win32/Injector.DTSL 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(13).vir.rtf - Win32/Exploit.Agent.NWB 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(15).vir.exe - Win32/Kryptik.FZIE 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(16).vir.exe - MSIL/Injector.NIK 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(18).vir.DOCM > ZIP > word/vbaProject.bin - PowerShell/TrojanDownloader.Agent.Q 特洛伊木马 - 扫描完成后再选择处理方式
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(19).vir.exe - MSIL/Kryptik.LOA 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(20).vir.exe - Win32/Injector.DTRM 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(28).vir.exe - MSIL/Kryptik.KBN 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(3).vir.dll - Win32/Spy.Ursnif.BA 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(30).vir.sys - Suspicious Object - 扫描完成后再选择处理方式
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(31).vir.exe - Win32/Kryptik.FZIE 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(36).vir.sys - Suspicious Object - 扫描完成后再选择处理方式
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(37).vir.exe - MSIL/Kryptik.KBN 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(45).vir.XLS - VBA/TrojanDownloader.Agent.FKY 特洛伊木马 - 已清除
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(46).vir.DOC - VBA/TrojanDownloader.Agent.FGU 特洛伊木马 - 已清除
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(47).vir.exe - Win32/GenKryptik.BEVC 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(5).vir.exe - MSIL/Kryptik.LLL 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(51).vir.exe - Win32/Injector.DTSO 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(52).vir.exe - Win32/Injector.DTSJ 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(6).vir.exe - Win32/Kryptik.FZHX 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(8).vir.DOCX > ZIP > word/embeddings/oleObject1.bin > OLEDATA > Microsoft Office Opening.exe - MSIL/Kryptik.JKY 特洛伊木马 的变种 - 扫描完成后再选择处理方式
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(9).vir.DOC - VBA/Kryptik.T 特洛伊木马 - 已清除
已扫描的对象数: 240
发现的威胁数: 25
已清除对象数: 21
完成时间: 20:28:58 总扫描时间: 98 秒 (00:01:38)
备注:
[1] 由于对象中仅包含病毒主体,因此已被删除。
文件名称: C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122.rar
文件大小: 10.3 MB (10,808,627 字节)
修改时间: 2017年11月22日,20:02:44
MD5: 39482582C37798AE8F1EC3B3D8A28DDC
SHA1: 81E66AA0B86F2F27ABBDD8B3E85408D7CC7396DF
SHA256: 30C533EEF4DC6A44C954B36B2FF1A3556DB995D677CC03E06D4FA3C36FB5EFA2
SHA512: B85C12FD046574310C0489DA2E2BD6B2F105483364AB5DA9DA3707B45EFCCD295489D8D3E498C3C185616041CC38E73E0577B2DCF56AE82847FBE7DDD5A6C788
CRC32: 42F0AC52
计算时间: 0.28s
火绒安全---( Windows 7 Ultimate with SP1 简体中文旗舰版....):部分未知文件已发送到seclab@huorong.cn,等处理中。。。
病毒库:2017/11/22 15:57
开始时间:2017/11/22 20:15
总计用时:00:00:29
扫描对象:1485个
扫描文件:52个
发现风险:12个
已处理风险:0个
发现系统修复项:0个
处理系统修复项:0个
病毒详情
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122\Virus(1).vir.exe, 病毒名:Trojan/MSIL.CoinMiner.g, 病毒ID:[eb2caecf7224c927], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122\Virus(11).vir.XLS, 病毒名:OMacro/Downloader.vl, 病毒ID:[aa6756e5fac323a5], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122\Virus(18).vir.DOCM >> word\vbaProject.bin, 病毒名:OMacro/Downloader.vj, 病毒ID:[f0f4e889de82f34d], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122\Virus(39).vir.EML, 病毒名:OMacro/Downloader.vl, 病毒ID:[aa6756e5fac323a5], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122\Virus(40).vir.vbs, 病毒名:OMacro/Downloader.vl, 病毒ID:[aa6756e5fac323a5], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122\Virus(41).vir.EML, 病毒名:OMacro/Downloader.vl, 病毒ID:[aa6756e5fac323a5], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122\Virus(42).vir.vbs, 病毒名:OMacro/Downloader.vl, 病毒ID:[aa6756e5fac323a5], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122\Virus(45).vir.XLS, 病毒名:OMacro/Downloader.vl, 病毒ID:[aa6756e5fac323a5], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122\Virus(46).vir.DOC, 病毒名:OMacro/Downloader.vm, 病毒ID:[473d1835839b1d4e], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122\Virus(47).vir.exe, 病毒名:HEUR:VirTool/Obfuscator.gen!C, 病毒ID:[9f7c74f7afee22c], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122\Virus(6).vir.exe, 病毒名:HEUR:VirTool/Obfuscator.gen!C, 病毒ID:[9f7c74f7afee22c], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus52x 1122\Virus(9).vir.DOC, 病毒名:HEUR:OMacro/Obfuscated.c, 病毒ID:[7e6f1720bf6936fa], 处理结果:已忽略
瑞星---(Windows 10 Creators Update(Redstone 2)....):云引擎(开)RDM+(开)
瑞星反恶软引擎命令行扫描器(社区交流版)
编译于:Sep 22 2017 15:07:50
提示:
- 本工具供社区交流使用,请勿用于其他用途
- 本工具没有恶意软件删除、清除、隔离功能
- 本工具包含开发中的新特性,结果仅供参考
* 命令行中的选项开关:-output-json -log=C:\瑞星RDM+引擎\ScanLog_171122204707.log
* 获取恶软签名库最新版本 ...
* 下载恶软签名库配置文件 ...
* 创建恶软签名库升级组件 ...
* 计算并下载增量文件 ...
* 升级恶软签名库 ...
* 恶软签名库升级成功
* 扫描目标 : (1) C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52
* 加载恶软签名库: C:\瑞星RDM+引擎/malware.rmd
* 恶软签名库加载成功,发布序号为 3211
* 读取恶软签名库配置 ...
* 云辅助扫描组件初始化失败.
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
扫描开始: Wed Nov 22 20:47:21 2017
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(11).vir.XLS","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(14).vir.rtf","infect":{"engine":"classic","threat":"Exploit.CVE-2017-11882.Gen!1.AED3"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(1).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrkPk81PDdWmQ6im104t7HOdzU6yQ","threat":"Trojan.CoinMiner!8.30A"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(19).vir.exe","infect":{"engine":"sha1","signature":"c2hhMToYLZM35NdFSK7brwu6Hd98Sspa4A","threat":"Backdoor.Androm!8.113"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(15).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTq5HOR08mCeku/YHLy6o79fdiTVOQ","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(17).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrSicrodvfl3HisCaT2qGom6gF8cw","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(10).vir.exe","infect":{"engine":"sha1","signature":"c2hhMToPnPuWVgyKhaJUGwmmEocHQhN9Iw","threat":"Spyware.Zbot!8.16B"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(21).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrl5OD+bIRmzkZspOAzRCVpZmQgZQ","threat":"Trojan.Injector!8.C4"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(2).vir.DOC","infect":{"engine":"classic","threat":"Downloader.VBA/Agent!1.AEC1"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(16).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTpclIVnGNn1lhYAF4vRc0I+vkKlKw","threat":"Trojan.Injector!8.C4"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(12).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTp3E8upKPyDOxNKcPZil0n2Q1ci6w","threat":"Trojan.Injector!1.AE48"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(23).vir.rtf","infect":{"engine":"classic","threat":"Exploit.CVE-2017-11882.Gen!1.AED3"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(20).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrU/B0ZymKnS5ExEhNmZ646Di0EFQ","threat":"Trojan.Injector!8.C4"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(18).vir.DOCM","infect":{"engine":"sha1","signature":"c2hhMTqn0+ygyjfP30xSuNHF3+ZsLB8ARA","threat":"Downloader.Agent!8.B23"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(22).vir.DOC","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(24).vir.DOC","infect":{"engine":"classic","threat":"Downloader.VBA/Agent!1.AEC1"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(25).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrO64DPUP5JI1LJiK1rYwjur7vnKg","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(28).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrHXtgiYmPyy52Pffm+dDxSbvNwOg","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(13).vir.rtf","infect":{"engine":"sha1","signature":"c2hhMTqN4kL/CQTtJ1CJ3NFMHtojbseR+g","threat":"Exploit.CVE-2015-1641!1.A3AF"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(26).vir.rtf","infect":{"engine":"classic","threat":"Exploit.CVE-2017-11882.Gen!1.AED3"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(29).vir.DOCX","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(27).vir.DOC","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(30).vir.sys","infect":{"engine":"sha1","signature":"c2hhMTomLIsPj9jqrFeJTm9XsSUe6bD4Kw","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(31).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTqUNFBw9dggBrzScBl8a0awgh5pQA","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(34).vir.js","infect":{"engine":"sha1","signature":"c2hhMTqt8sT90Kmi2b17nM/gaZKqnbU8aQ","threat":"Downloader.Agent!8.B23"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(39).vir.EML","infect":{"engine":"sha1","signature":"c2hhMToQ66Cl6bcukX1h+k5065TavWNV2A","threat":"Downloader.Agent!8.B23"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(36).vir.sys","infect":{"engine":"sha1","signature":"c2hhMTr0MfatAQNZrxERGDYAdjhCRYXMaQ","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(38).vir.EML","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(37).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrRh+IfYfCEN225La1Oy0vnLNakkA","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(33).vir.DOC","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(3).vir.dll","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(42).vir.vbs","infect":{"engine":"sha1","signature":"c2hhMTplNJbkghYUz/dJZM+3VcHV5E3d3A","threat":"Downloader.Agent!8.B23"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(45).vir.XLS","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(35).vir.DOCX","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(43).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTqNJpuvflA31J8R5/EC7hCqw9IoMg","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(46).vir.DOC","infect":{"engine":"topis","signature":"JznujS5DV3S","threat":"Downloader.Agent!8.B23"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(40).vir.vbs","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(44).vir.rtf","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(41).vir.EML","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(48).vir.exe","infect":{"engine":"rdmk","signature":"cmRtazrRT4ooMF9+Fq+/e5yx0Y7g","threat":"Malware.Heuristic!ET#100%"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(5).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTplZHnlo0r6qFccGMjYLvQjypnJ+w","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(50).vir.rtf","infect":{"engine":"sha1","signature":"c2hhMToulW9AbcVGzvrNIcFvuVQE0MoRYA","threat":"Exploit.CVE-2017-11882!8.EFC7"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(51).vir.exe","infect":{"engine":"sha1","signature":"c2hhMToyWRE0OM4H+1rOP2ICRiDBMECtjw","threat":"Trojan.Injector!8.C4"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(47).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTo5Hf7N3SxTzf1d2udF+z5w3rlY2Q","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(6).vir.exe","infect":{"engine":"tfe","signature":"dGZlOgITMqOn00xkSg","threat":"Trojan.Kovter!8.152"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(7).vir.rtf","infect":{"engine":"sha1","signature":"c2hhMTqiqNkbzzo+s1m1wyDkoFuG78aJ2Q","threat":"Exploit.CVE-2017-0199.Gen!1.AECA"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(52).vir.exe","infect":{"engine":"classic","threat":"Trojan.Injector!1.AE36"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(9).vir.DOC","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(32).vir.DOCX","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(8).vir.DOCX","infect":{"engine":"sha1","signature":"c2hhMTrAMTP1RUVCWR7ElLmxNfGM43OiEA","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(4).vir.pptx","infect":{"engine":"classic","threat":"Exploit.CVE-2017-8759.Gen!1.AEC4"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\1122To42F0AC52\\Virus52x 1122\\Virus(49).vir.DOCX","type":"scan"}
扫描结束: Wed Nov 22 20:47:27 2017
总扫描耗时: 0:6:176(m:s:ms)
总扫描对象: 384
总扫描文件: 52
总恶意文件: 37
有效 检 [:01:]出率: 71.15%
X-Sec Antivirus ---(Windows 10 Creators Update(Redstone 2)....):
Start Time: Wed Nov 22 20:50:55 2017
Scan Type: Custom Scan
Scan Target: C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52
Heuristic Engine: Enabled
Cloud Engine: Enabled
Resolve Threats: Scan only
Database Version: 2017.11.20.01
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(10).vir.exe -> Cloud:Trojan.Win32.Injector
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(11).vir.XLS -> Cloud:Macro.MSExcel.Downloader
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(15).vir.exe -> Cloud:Trojan.Win32.Emotet
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(17).vir.exe -> Cloud:Trojan.Win32.Hancitor
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(19).vir.exe -> Trojan.Win32.Generic.Ec
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(30).vir.sys -> Cloud:Trojan.Win32.Emotet
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(31).vir.exe -> Cloud:Trojan.Win32.Emotet
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(33).vir.DOC -> Cloud:Macro.MSWord.Downloader
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(36).vir.sys -> Cloud:Trojan.Win32.Emotet
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(45).vir.XLS -> Cloud:Macro.MSExcel.Downloader
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(48).vir.exe -> Cloud:Trojan.Win32.Injector
C:\Users\Admin\Desktop\AVtest100\1122To42F0AC52\Virus52x 1122\Virus(9).vir.DOC -> Cloud:Macro.MSWord.Downloader
Elapsed Time: 00:00:53
Total File: 52
Skipped File: 5
Infected File: 12
|