查看: 2747|回复: 18
收起左侧

[病毒样本] S5+M5(.doc|emotet)(18.06.14)

[复制链接]
petr0vic
发表于 2018-6-14 16:23:27 | 显示全部楼层 |阅读模式

评分

参与人数 1人气 +1 收起 理由
Jerry.Lin + 1 版区有你更精彩: )

查看全部评分

StarlitFuture
发表于 2018-6-14 16:31:36 | 显示全部楼层
360杀毒  06 14 16:29

Samples(5/5) + M(5/5) = Total(10/10)  100%
  1. 360杀毒扫描日志

  2. 病毒库版本:
  3. 扫描时间:2018-06-14 16:28:13
  4. 扫描用时:00:00:01
  5. 扫描类型:右键扫描
  6. 扫描文件总数:5
  7. 项目总数:5
  8. 清除项目数:5

  9. 扫描选项
  10. ----------------------
  11. 扫描所有文件:是
  12. 扫描压缩包:是
  13. 发现病毒处理方式:由360杀毒自动处理
  14. 扫描磁盘引导区:是
  15. 扫描 Rootkit:是
  16. 使用云查杀引擎:是
  17. 使用QVM人工智能引擎:是
  18. 扫描建议修复项:是
  19. 常规引擎设置:未使用

  20. 扫描内容
  21. ----------------------
  22. C:\Users\Home\Downloads\Vir\1.doc
  23. C:\Users\Home\Downloads\Vir\2.doc
  24. C:\Users\Home\Downloads\Vir\3.doc
  25. C:\Users\Home\Downloads\Vir\4.doc
  26. C:\Users\Home\Downloads\Vir\5.doc


  27. 白名单设置
  28. ----------------------


  29. 扫描结果
  30. ======================
  31. 高危风险项
  32. ----------------------
  33. C:\Users\Home\Downloads\Vir\1.doc        virus.office.qexvmc.1085        已修复
  34. C:\Users\Home\Downloads\Vir\2.doc        virus.office.qexvmc.1085        已修复
  35. C:\Users\Home\Downloads\Vir\5.doc        virus.office.obfuscated.4        已修复
  36. C:\Users\Home\Downloads\Vir\4.doc        virus.office.obfuscated.4        已修复
  37. C:\Users\Home\Downloads\Vir\3.doc        virus.office.obfuscated.4        已修复
复制代码
  1. 360杀毒扫描日志

  2. 病毒库版本:
  3. 扫描时间:2018-06-14 16:28:24
  4. 扫描用时:00:00:01
  5. 扫描类型:右键扫描
  6. 扫描文件总数:5
  7. 项目总数:5
  8. 清除项目数:5

  9. 扫描选项
  10. ----------------------
  11. 扫描所有文件:是
  12. 扫描压缩包:是
  13. 发现病毒处理方式:由360杀毒自动处理
  14. 扫描磁盘引导区:是
  15. 扫描 Rootkit:是
  16. 使用云查杀引擎:是
  17. 使用QVM人工智能引擎:是
  18. 扫描建议修复项:是
  19. 常规引擎设置:未使用

  20. 扫描内容
  21. ----------------------
  22. C:\Users\Home\Downloads\Vir\M


  23. 白名单设置
  24. ----------------------


  25. 扫描结果
  26. ======================
  27. 高危风险项
  28. ----------------------
  29. C:\Users\Home\Downloads\Vir\M\1.doc        virus.office.qexvmc.1085        已修复
  30. C:\Users\Home\Downloads\Vir\M\2.doc        virus.office.qexvmc.1085        已修复
  31. C:\Users\Home\Downloads\Vir\M\5.doc        virus.office.obfuscated.4        已修复
  32. C:\Users\Home\Downloads\Vir\M\4.doc        virus.office.obfuscated.4        已修复
  33. C:\Users\Home\Downloads\Vir\M\3.doc        virus.office.obfuscated.4        已修复



  34. 可疑文件上传结果
  35. ----------------------
  36. c:\users\home\downloads\vir\m\1.doc        上传成功
  37. c:\users\home\downloads\vir\m\4.doc        上传成功
  38. c:\users\home\downloads\vir\m\5.doc        上传成功
复制代码
761773275
发表于 2018-6-14 16:32:23 | 显示全部楼层
本帖最后由 761773275 于 2018-6-14 16:35 编辑

Baidu Antivirus
Samples(0/5) + M(0/5) = Total(0/10)



Nocria
发表于 2018-6-14 16:37:20 | 显示全部楼层
本帖最后由 humanlwj52 于 2018-6-14 16:38 编辑

G DATA has no detection.
YU2711
发表于 2018-6-14 16:39:01 | 显示全部楼层
Symantec  Endpoint Protection
Samples(5/5) + M(5/5) = Total(10/10)
ISB.Downloader!gen80ISB.Downloader!gen80
ATP_synthase
发表于 2018-6-14 17:05:48 | 显示全部楼层
卡巴全灭
540923555
发表于 2018-6-14 17:07:03 | 显示全部楼层
WD清空
ATP_synthase
发表于 2018-6-14 17:07:05 | 显示全部楼层
StarlitFuture 发表于 2018-6-14 16:31
360杀毒  06 14 16:29

Samples(5/5) + M(5/5) = Total(10/10)  100%

360修复文件了吗,没删除
Jerry.Lin
发表于 2018-6-14 17:22:38 | 显示全部楼层

  1. Antivirus Pro
  2. Report file date: 2018-06-14 17:17:54


  3. The program is running as an unrestricted full version.



  4. Configuration settings for the scan:
  5. AutoActionOnDetection: on
  6. Network scanning enabled: on
  7. Upload to cloud enabled: on
  8. Upload to cloud confirmation needed: off
  9. DetectionUnpackedGen: off
  10. DetectionDamagedGen: off
  11. Maximum number of clients: 10
  12. Heuristic macro: 1
  13. Heuristic files: 3
  14. Scan archives: on
  15. Smart extensions: on
  16. Archive scan types:
  17. Limit recursion depth: on
  18. Recursion depth: 20
  19. Maximum unpack size: 1073741824
  20. Unpack ratio: 250
  21. Excluded files:
  22. C:\Users\zhong\Downloads\Compressed\Corel VideoStudio\Keygen.exe

  23. Start of the scan: 2018-06-14 17:17:54
  24. 06/14/2018,17-17-54        [INFO]        c:\users\zhong\downloads\compressed\virus test\llqnop\vir\m\3.doc
  25. 06/14/2018,17-17-54        [INFO]        [DETECTION] file contains 'W97M/Agent.8308720'
  26. 06/14/2018,17-17-54        [INFO]        c:\users\zhong\downloads\compressed\virus test\llqnop\vir\m\4.doc
  27. 06/14/2018,17-17-54        [INFO]        [DETECTION] file contains 'W97M/Agent.8308720'
  28. 06/14/2018,17-17-55        [INFO]        c:\users\zhong\downloads\compressed\virus test\llqnop\vir\m\5.doc
  29. 06/14/2018,17-17-55        [INFO]        [DETECTION] file contains 'W97M/Agent.8308721'
  30. 06/14/2018,17-17-55        [INFO]        c:\users\zhong\downloads\compressed\virus test\llqnop\vir\3.doc
  31. 06/14/2018,17-17-55        [INFO]        [DETECTION] file contains 'W97M/Agent.8308720'
  32. 06/14/2018,17-17-55        [INFO]        c:\users\zhong\downloads\compressed\virus test\llqnop\vir\4.doc
  33. 06/14/2018,17-17-55        [INFO]        [DETECTION] file contains 'W97M/Agent.8308720'
  34. 06/14/2018,17-17-55        [INFO]        c:\users\zhong\downloads\compressed\virus test\llqnop\vir\5.doc
  35. 06/14/2018,17-17-55        [INFO]        [DETECTION] file contains 'W97M/Agent.8308720'
  36. 06/14/2018,17-17-55        [INFO]        repair.rdf loaded (version: 1.0.42.4)
  37. 06/14/2018,17-17-55        [INFO]        Repair of Generic started.
  38. 06/14/2018,17-17-57        [INFO]        Repair of Generic finished successfully.
  39. 06/14/2018,17-17-57        [INFO]        Repair of W97M/Agent.8308720 started.
  40. 06/14/2018,17-17-59        [INFO]        Repair of W97M/Agent.8308720 finished successfully.
  41. 06/14/2018,17-18-00        [INFO]        c:\users\zhong\downloads\compressed\virus test\llqnop\vir\m\3.doc
  42. 06/14/2018,17-18-00        [INFO]        [ACTION] Clean
  43. 06/14/2018,17-18-00        [WARN]        The file could not be repaired by Engine: c:\users\zhong\downloads\compressed\virus test\llqnop\vir\m\3.doc. Virus: W97M/Agent.8308720. Category: virus. Error Code: 0
  44. 06/14/2018,17-18-00        [INFO]        Repair of W97M/Agent.8308720 started.
  45. 06/14/2018,17-18-00        [INFO]        Repair of W97M/Agent.8308720 finished successfully.
  46. 06/14/2018,17-18-01        [INFO]        c:\users\zhong\downloads\compressed\virus test\llqnop\vir\m\4.doc
  47. 06/14/2018,17-18-01        [INFO]        [ACTION] Clean
  48. 06/14/2018,17-18-01        [INFO]        Repair of W97M/Agent.8308721 started.
  49. 06/14/2018,17-18-01        [INFO]        Repair of W97M/Agent.8308721 finished successfully.
  50. 06/14/2018,17-18-01        [INFO]        c:\users\zhong\downloads\compressed\virus test\llqnop\vir\m\5.doc
  51. 06/14/2018,17-18-01        [INFO]        [ACTION] Clean
  52. 06/14/2018,17-18-01        [INFO]        Repair of W97M/Agent.8308720 started.
  53. 06/14/2018,17-18-01        [INFO]        Repair of W97M/Agent.8308720 finished successfully.
  54. 06/14/2018,17-18-02        [INFO]        c:\users\zhong\downloads\compressed\virus test\llqnop\vir\3.doc
  55. 06/14/2018,17-18-02        [INFO]        [ACTION] Clean
  56. 06/14/2018,17-18-02        [INFO]        Repair of W97M/Agent.8308720 started.
  57. 06/14/2018,17-18-02        [INFO]        Repair of W97M/Agent.8308720 finished successfully.
  58. 06/14/2018,17-18-02        [INFO]        c:\users\zhong\downloads\compressed\virus test\llqnop\vir\4.doc
  59. 06/14/2018,17-18-02        [INFO]        [ACTION] Clean
  60. 06/14/2018,17-18-02        [INFO]        Repair of W97M/Agent.8308720 started.
  61. 06/14/2018,17-18-02        [INFO]        Repair of W97M/Agent.8308720 finished successfully.
  62. 06/14/2018,17-18-03        [INFO]        c:\users\zhong\downloads\compressed\virus test\llqnop\vir\5.doc
  63. 06/14/2018,17-18-03        [INFO]        [ACTION] Clean

  64. ---------------------------------------------------------

  65. End of scan : 2018-06-14 17:18:03
  66. Duration : 00m:08s:818ms

  67. The scan has been done completely.

  68.       2 Scanned directories
  69.       0 Scanned archives
  70.      10 Scanned files
  71.       0 Skipped files
  72.       0 Ignored files
  73.       6 Detected files
  74.       5 Infected files cleaned
  75.       1 Warnings

  76. ---------------------------------------------------------
复制代码
Dust-;羅錠
发表于 2018-6-14 17:25:59 | 显示全部楼层

我今天试用了一下Avira antivirus pro business edition,结果把我的启动项全删得干干净净,只剩下红伞自己,我也是醉了。这还是business edition?
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-20 12:25 , Processed in 0.133668 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表