本帖最后由 小飞侠.net 于 2017-11-23 22:09 编辑
Emsisoft Emergency Kit - 版本 2017.10
上次更新: 2017/11/23 21:26:24
用户帐号: TECLAST\Admin
电脑名称: TECLAST
操作系统版本: Windows 10x64
扫描设置:
扫描方式: 自定义扫描
对象: Rootkits, 内存, C:\Users\Admin\Desktop\AVtest100\D8034658To1123\
检测流氓软件(PUPs): On
扫描压缩包: On
扫描邮件存档: On
ADS数据流: On
文件扩展名过滤: Off
直接磁盘访问: Off
扫描开始于: 2017/11/23 21:45:01
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(1).vir.rtf -> (objdata) -> (Embedded DocFile g) 发现病毒: Exploit.CVE-2017-11882.Gen (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(1).vir.rtf -> (objdata) -> (Equation.3) 发现病毒: Exploit.CVE-2017-11882.Gen (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(14).vir.DOCX -> word/embeddings/oleObject1.bin -> qhfostpnmrle.jar 发现病毒: Exploit.OLE-JAR.Gen.1 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(19).vir.LNK -> (LNK Command 0) 发现病毒: Gen:Heur.BZC.Pantera.3 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(35).vir.rtf -> (objdata) -> (Embedded DocFile g) 发现病毒: Exploit.CVE-2017-11882.Gen (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(35).vir.rtf -> (objdata) -> (Equation.3) 发现病毒: Exploit.CVE-2017-11882.Gen (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(8).vir.jar -> resultados/capital.class 发现病毒: Java.Trojan.GenericGB.34 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(11).vir.sys 发现病毒: Trojan.GenericKD.6232166 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(13).vir.DOC 发现病毒: VB:Trojan.Valyria.1010 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(16).vir.exe 发现病毒: Trojan-Spy.Ursnif (A) [291617]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(20).vir.sys 发现病毒: Trojan.GenericKD.12605407 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(21).vir.exe 发现病毒: Trojan.GenericKD.12604868 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(17).vir.exe 发现病毒: Gen:Variant.Jacard.81599 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(22).vir.exe 发现病毒: Gen:Variant.Symmi.80408 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(25).vir.exe 发现病毒: Trojan.MSIL.Agent.CZU (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(24).vir.exe 发现病毒: Trojan-Spy.Ursnif (A) [291617]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(28).vir.dll 发现病毒: Application.Agent.AJU (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(32).vir.exe 发现病毒: Trojan.GenericKD.12609200 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(33).vir.exe 发现病毒: Trojan.GenericKD.12604115 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(34).vir.exe 发现病毒: Gen:Variant.MSILPerseus.132255 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(4).vir.exe 发现病毒: Trojan.Agent (A) [291618]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(30).vir.exe 发现病毒: Gen:Variant.Symmi.80384 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(44).vir.exe 发现病毒: Gen:Variant.Graftor.433295 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(42).vir.exe 发现病毒: Gen:Variant.Graftor.433407 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(48).vir.exe 发现病毒: Application.BitCoinMiner.UY (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(49).vir.exe 发现病毒: Gen:Variant.Graftor.432767 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(38).vir.exe 发现病毒: Gen:Variant.Mikey.74907 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(55).vir.exe 发现病毒: Trojan-MSIL.Crypted.Gen.J (A) [290001]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(7).vir.exe 发现病毒: Trojan.Agent.CQUB (B) [krnl.xmd]
已扫描 1732
发 现 29
扫描完成后: 2017/11/23 21:45:23
扫描时间: 0:00:22
ESET Smart Security Premium 64位(高级启发式(Y)+压缩文件(Y)+自解压加壳(Y)+DNY智能签名(Y)++(Windows 10 Creators Update(Redstone 2)....):Found nothing
日志
正在扫描日志
检测引擎的版本: 16458P (20171123)
日期: 2017/11/23 时间: 21:38:26
已扫描的磁盘、文件夹和文件: C:\Users\Admin\Desktop\AVtest100\D8034658To1123
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(10).vir.exe > NSIS > coopery.dll - Win32/Injector.DTTX 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(11).vir.sys - Win32/Kryptik.FZJA 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(12).vir.exe - MSIL/Kryptik.LLL 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(13).vir.DOC - VBA/TrojanDownloader.Agent.FGU 特洛伊木马 - 已清除
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(15).vir.exe - Win32/Injector.DTTW 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(16).vir.exe - Win32/TrojanDownloader.Nymaim.BA 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(17).vir.exe - Win32/Injector.DTSJ 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(18).vir.exe > WINRARSFX > Fhrdbi.exe - MSIL/Injector.QOY 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(19).vir.LNK - LNK/TrojanDownloader.Agent.HP 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(2).vir.vbs - VBS/TrojanDownloader.Agent.PJO 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(20).vir.sys - Generik.EVPUSJP 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(21).vir.exe - Win32/Kryptik.FZIZ 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(22).vir.exe - Win32/Injector.DTTM 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(23).vir.exe - Win32/Kryptik.FZKP 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(24).vir.exe - Win32/Kryptik.FZJE 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(25).vir.exe - MSIL/Kryptik.LST 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(26).vir.exe > EZIRIZ > protected.exe - MSIL/TrojanDropper.Agent.MK 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(27).vir.exe - MSIL/Kryptik.LLL 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(28).vir.dll - Win32/Exploit.CVE-2015-0016.B 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(29).vir.exe - MSIL/GenKryptik.BEWC 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(3).vir.vbs - VBS/TrojanDownloader.Agent.PJO 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(30).vir.exe - Win32/Injector.DRYY 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(31).vir.exe - MSIL/Kryptik.LLT 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(32).vir.exe - Win32/Injector.DTUA 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(33).vir.exe - Win32/Injector.DSLM 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(34).vir.exe - VBS/TrojanDownloader.Small.NGR 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(35).vir.rtf - Win32/Exploit.CVE-2017-11882.B 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(36).vir.vbs - VBS/TrojanDownloader.Agent.PJO 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(37).vir.exe - Win32/Agent.YIJ 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(38).vir.exe - Win32/GenKryptik.BEYD 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(39).vir.DOC - VBA/TrojanDownloader.Agent.FMC 特洛伊木马 - 已清除
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(4).vir.exe - Win32/Kryptik.FZKP 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(40).vir.exe - Win32/GenKryptik.BEZV 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(41).vir.exe - Generik.KLNFPON 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(42).vir.exe - Win32/Injector.DTSJ 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(44).vir.exe - Win32/Kryptik.FZII 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(45).vir.exe - MSIL/Kryptik.LSR 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(49).vir.exe - Win32/Injector.DTTM 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(5).vir.exe - MSIL/Kryptik.LLL 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(53).vir.exe > NSIS > pancreatitis.dll - Win32/Injector.DTTX 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(54).vir.html - JS/Agent.NWK 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(55).vir.exe - MSIL/Kryptik.KPP 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(6).vir.exe - Win32/Kryptik.FZKT 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(7).vir.exe - Win32/Injector.DTTR 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(8).vir.jar > ZIP > resultados/capital.class - Java/TrojanDownloader.Banload.DA 特洛伊木马 的变种 - 通过删除清除 [1]
已扫描的对象数: 102
发现的 威胁数: 45
已清除对象数: 45
完成时间: 21:39:27 总扫描时间: 61 秒 (00:01:01)
备注:
[1] 由于对象中仅包含病毒主体,因此已被删除。
火绒安全---( Windows 7 Ultimate with SP1 简体中文旗舰版....):部分未知文件已发送到seclab@huorong.cn,等处理中。。。
病毒库:2017/11/23 17:21
开始时间:2017/11/23 21:26
总计用时:00:00:23
扫描对象:425个
扫描文件:55个
发现风险:13个
已处理风险:0个
发现系统修复项:0个
处理系统修复项:0个
文件名称: C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123.rar
文件大小: 10.7 MB (11,228,906 字节)
修改时间: 2017年11月23日,21:21:23
MD5: C84BC765D2EA09E1363F3258739101F2
SHA1: CECA92C9A2F7C6240E2EDC7064C43BC5BC007D1D
SHA256: 2333ECF5FF254C2F2E763D81F1BEF33FCD42B2659F95C84CF1DFB267713EEB7C
SHA512: 0AF39AEF2CBD46CAE68DABB7A3CA161374C058509D060F4E962384DA5D06D1C53325C62F88343C58317087896CEAFB28B2F5735FA9318EC37BCF0FCB56539365
CRC32: D8034658
计算时间: 0.28s
病毒详情
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(13).vir.DOC, 病毒名:OMacro/Downloader.vm, 病毒ID:[473d1835839b1d4e], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(10).vir.exe, 病毒名:HVM:Trojan/Injector.gen!A, 病毒ID:[cc4a875f53a5d678], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(21).vir.exe, 病毒名:HEUR:VirTool/Obfuscator.gen!J, 病毒ID:[ddf8356203605f03], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(16).vir.exe, 病毒名:HEUR:VirTool/Obfuscator.gen!C, 病毒ID:[9f7c74f7afee22c], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(37).vir.exe, 病毒名:HEUR:VirTool/Obfuscator.gen!B, 病毒ID:[2d18551aef762f90], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(24).vir.exe, 病毒名:HEUR:VirTool/Obfuscator.gen!C, 病毒ID:[9f7c74f7afee22c], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(38).vir.exe, 病毒名:HVM:VirTool/Obfuscator.gen!A, 病毒ID:[b27d4294cde6a1ec], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(41).vir.exe, 病毒名:HEUR:VirTool/Obfuscator.gen!C, 病毒ID:[9f7c74f7afee22c], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(48).vir.exe, 病毒名:Trojan/Generic!2706BB3FE12EB807, 病毒ID:[2706bb3fe12eb807], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(49).vir.exe, 病毒名:Trojan/Injector.kb, 病毒ID:[d0643d17d8dc1564], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(54).vir.html, 病毒名:SVM:TrojanDownloader/JS.MalBehav.gen!D, 病毒ID:[e27d0b2a9482fa98], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(53).vir.exe, 病毒名:HVM:Trojan/Injector.gen!A, 病毒ID:[cc4a875f53a5d678], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\刘1\艾2\61647309\85014225\孙3\Windows Defender\AVTestZipX\Virus55x 1123\Virus(6).vir.exe, 病毒名:HVM:Trojan/Injector.gen!A, 病毒ID:[cc4a875f53a5d678], 处理结果:已忽略
瑞星---(Windows 10 Creators Update(Redstone 2)....):云引擎(开)RDM+(开)
瑞星反恶软引擎命令行扫描器(社区交流版)
编译于:Sep 22 2017 15:07:50
提示:
- 本工具供社区交流使用,请勿用于其他用途
- 本工具没有恶意软件删除、清除、隔离功能
- 本工具包含开发中的新特性,结果仅供参考
* 命令行中的选项开关:-output-json -log=C:\瑞星RDM+引擎\ScanLog_171123214854.log
* 获取恶软签名库最新版本 ...
* 下载恶软签名库配置文件 ...
* 创建恶软签名库升级组件 ...
* 计算并下载增量文件 ...
* 升级恶软签名库 ...
* 恶软签名库升级成功
* 扫描目标 : (1) C:\Users\Admin\Desktop\AVtest100\D8034658To1123
* 加载恶软签名库: C:\瑞星RDM+引擎/malware.rmd
* 恶软签名库加载成功,发布序号为 3217
* 读取恶软签名库配置 ...
* 云辅助扫描组件初始化失败.
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
扫描开始: Thu Nov 23 21:49:09 2017
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(13).vir.DOC","infect":{"engine":"topis","signature":"9T9g2My92HP","threat":"Downloader.Agent!8.B23"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(16).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTqC1S0fh89rsOt8nzQoBziLmHRp1Q","threat":"Downloader.Nymaim!8.781"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(11).vir.sys","infect":{"engine":"sha1","signature":"c2hhMTrEo53SZlhUtKXwVo3CNzDEg0HrCw","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(19).vir.LNK","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(15).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTq2steS+1kbR2UQUiu9bjLfS6NVcg","threat":"Trojan.Injector!8.C4"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(1).vir.rtf","infect":{"engine":"classic","threat":"Exploit.CVE-2017-11882.Gen!1.AED3"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(12).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrTPo1qPawFsUdcLo74BTSgvX62wA","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(10).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTreaGimOUswhtMF4gmkXpIK8USQ1Q","threat":"Ransom.Blocker!8.12A"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(17).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrHUnJzvYZCnC9FKYtk31NT2ZQ2WQ","threat":"Trojan.Injector!1.AE36"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(14).vir.DOCX","infect":{"engine":"sha1","signature":"c2hhMTovDstlbT5+tsCBtb3yqqxQH4Q8vA","threat":"Trojan.Agent!8.B1E"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(2).vir.vbs","infect":{"engine":"classic","threat":"Downloader.VBS/Agent!1.AEC5"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(22).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTr7Q/srQqIxMpOrd1b8zzgXl070Mw","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(23).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTqtbziRMYLo1JXkX3CwmarYnnBnwg","threat":"Malware.Undefined!8.C"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(18).vir.exe","infect":{"engine":"c64","signature":"YzY0Os4KptfdjfdI","threat":"Dropper.Generic!8.35E"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(24).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrZAFNS/ZEdfRVemergMWazbEtA1A","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(28).vir.dll","infect":{"engine":"sha1","signature":"c2hhMTq5YfZH+gHBaKc/pie30RfzLPR1tA","threat":"Exploit.CVE-2015-0016!8.4D0C"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(27).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrXa/mumOVCz0nDTo2rNsNct2IctA","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(29).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTp4uLNekVaugVq+aQiAa3Qy50W+Rg","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(3).vir.vbs","infect":{"engine":"classic","threat":"Downloader.VBS/Agent!1.AEC5"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(21).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTpsPphIC3+u4T8gqjprkLv31RHy/g","threat":"Malware.Undefined!8.C"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(20).vir.sys","infect":{"engine":"sha1","signature":"c2hhMTrN74QyBSO9YOZrGprketqBz9E4rA","threat":"Trojan.Dovs!8.EB4C"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(32).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTqFHtG+WgYWiD/rf6uTITRTBW9WKA","threat":"Trojan.Injector!8.C4"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(34).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrvk2KIPnbupXtkHOj0zbTiY0J5XQ","threat":"Downloader.Small!8.B41"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(35).vir.rtf","infect":{"engine":"classic","threat":"Exploit.CVE-2017-11882.Gen!1.AED3"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(33).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTqwgdSMvwlSA2FdjbcHN8LPndexaw","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(30).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrvRzaxwyNK54wzLvd3pAemEri/qA","threat":"Backdoor.Fynloski!8.1FD"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(26).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTr3+FIZNiCC66U3QTh4wlq3U7FLHQ","threat":"Dropper.Agent!8.2F"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(25).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTr1oTUBfVqC93o66/TUVr/uRn03Yg","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(31).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTo5nmRdCm922Tt+ht4MguuRJ0UxlQ","threat":"Dropper.Generic!8.35E"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(39).vir.DOC","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(43).vir.html","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(38).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTq02l9+pOVntmmDbcibF4+2LIup4Q","threat":"Malware.Undefined!8.C"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(41).vir.exe","infect":{"engine":"sha1","signature":"c2hhMToHG56Gx9L7NGCZbe7b4kDfx6vv7w","threat":"Malware.Undefined!8.C"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(4).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTolS3nqALxua/QB3vkVazS+PxHiYg","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(40).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTpc8WrM0MWYlyD2W2cBOgXiOqi7LA","threat":"Malware.Undefined!8.C"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(37).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTox13Rs0iLytSXdTCDRb3N/J4yD9w","threat":"Trojan.Agent!8.B1E"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(44).vir.exe","infect":{"engine":"rdmk","signature":"cmRtazpt7vbTmnAlcqWhfeYiUd71","threat":"Malware.Heuristic!ET#97%"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(45).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTqpQd2+ERNcPkoJAy1Y9nFElbyycA","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(42).vir.exe","infect":{"engine":"classic","threat":"Trojan.Injector!1.AE36"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(46).vir.exe","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(47).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTq6sjQXsojiUyV/7CxQyptQBVuzig","threat":"Malware.Undefined!8.C"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(5).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTotBGBPR0u6/LoVO9jsaXA3hcskuA","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(52).vir.vbs","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(50).vir.JS","infect":{"engine":"classic","threat":"Trojan.ObfusJS/Heur!1.A4CA"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(53).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTql/Lp5iXW1vzJEiSrO/npKGxvzmQ","threat":"Trojan.Injector!8.C4"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(6).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTpv5XzzJvwkNMk8zAEGt7ZOwDAN1w","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(54).vir.html","infect":{"engine":"sha1","signature":"c2hhMTrzlSE3Sv7e0c8wkAT8AcebHS/x3Q","threat":"Downloader.Generic!8.141"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(49).vir.exe","infect":{"engine":"sha1","signature":"c2hhMToW4GAYqasCOSpDnONbG+lFypy4hA","threat":"Trojan.Injector!8.C4"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(8).vir.jar","infect":{"engine":"classic","threat":"Trojan.Java.Banload!1.AE05"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(51).vir.vbs","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(55).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrC8/X19cB7Z/ggOMofduEwQJvTVw","threat":"Trojan.Kryptik!8.8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(9).vir.DOC","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(7).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTrg1Le5Lu/MdPKtcxWzRKRmx1e6oQ","threat":"Trojan.Injector!8.C4"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(48).vir.exe","infect":{"engine":"sha1","signature":"c2hhMTr+gbgozB1D3RwTJ5nd6DPtw0TTKg","threat":"Trojan.CoinMiner!1.ADB8"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\D8034658To1123\\Virus55x 1123\\Virus(36).vir.vbs","infect":{"engine":"classic","threat":"Downloader.VBS/Agent!1.AEC5"},"type":"scan"}
扫描结束: Thu Nov 23 21:49:12 2017
总扫描耗时: 0:3:119(m:s:ms)
总扫描对象: 84
总扫描文件: 55
总恶意文件: 48
有效检 出率: 87.27%
X-Sec Antivirus ---(Windows 10 Creators Update(Redstone 2)....):
Start Time: Thu Nov 23 21:56:18 2017
Scan Type: Custom Scan
Scan Target: C:\Users\Admin\Desktop\AVtest100\D8034658To1123
Heuristic Engine: Enabled
Cloud Engine: Enabled
Resolve Threats: Scan only
Database Version: 2017.11.22.01
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(1).vir.rtf -> Cloud:Exploit.MSOffice.CVE-2017-11882
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(13).vir.DOC -> Cloud:Macro.MSWord.Downloader
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(14).vir.DOCX -> Cloud:Malware.MSOffice.Dropper
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(16).vir.exe -> Cloud:Trojan.Win32.Injector
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(2).vir.vbs -> Cloud:Trojan.Script.Downloader
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(27).vir.exe -> Cloud:Backdoor.Win32.Generic
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(3).vir.vbs -> Cloud:Trojan.Script.Downloader
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(31).vir.exe -> Trojan.Win32.Generic.Ec
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(35).vir.rtf -> Cloud:Exploit.MSOffice.CVE-2017-11882
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(36).vir.vbs -> Cloud:Trojan.Script.Downloader
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(38).vir.exe -> Cloud:Trojan.Win32.Injector
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(39).vir.DOC -> Cloud:Macro.MSWord.Downloader
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(40).vir.exe -> Cloud:Trojan.Win32.Injector
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(41).vir.exe -> Cloud:Trojan.Win32.Injector
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(43).vir.html -> Cloud:Trojan.Script.Downloader
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(48).vir.exe -> Trojan.Win32.CoinMiner.Aa
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(49).vir.exe -> Cloud:Trojan.Win32.Generic
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(5).vir.exe -> Cloud:Backdoor.Win32.Generic
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(50).vir.JS -> Cloud:Trojan.Script.Downloader
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(6).vir.exe -> Cloud:Trojan.Win32.Injector
C:\Users\Admin\Desktop\AVtest100\D8034658To1123\Virus55x 1123\Virus(9).vir.DOC -> Cloud:Macro.MSWord.Downloader
Elapsed Time: 00:01:18
Total File: 55
Skipped File: 1
Infected File: 21
|