查看: 2713|回复: 19
收起左侧

[病毒样本] #PACKAGE 0621

[复制链接]
Jerry.Lin
发表于 2018-6-21 21:14:06 | 显示全部楼层 |阅读模式
本帖最后由 191196846 于 2018-6-21 21:26 编辑

蓝奏



Total : 26

========================================
These products were tested before package released:

Products                        Pre-execute    Advanced block     Miss         Status

Windows Defender               8                           4                     14           Infected
Qihoo 360 SD                       19                          1                      6           Infected


Note: Pre-execute includes On-Access scan or exeute scan before malware is running on memory.
          Advanced block includes behavior block or other techiques that successufully terminate running malware.
          Miss includes situations: no any Alert or warning from AV software.
          Status means if there are any malicious items, including processes, images, drivers, autoruns, regs etc., on the current system, the system is infected; otherwise it is clean.

========================================


#勿传VT
#在样本有效期内(24小时),建议无需手动上报样本至厂商,便于其他人测试行为拦截,响应速度等
#样本序号以收集时间顺序排序,越大代表越接近现在时间


回帖格式建议

杀软名称 + 时间
查杀数量+查杀率


例如:
XXX 20:39
Samples(5/10) 50%



评分

参与人数 4人气 +4 收起 理由
wangkaka + 1 版区有你更精彩: )
B100D1E55 + 1
Dust-;羅錠 + 1 根据版规,加1分以示鼓励
petr0vic + 1 版区有你更精彩: )

查看全部评分

ynghaos
发表于 2018-6-21 22:23:08 | 显示全部楼层
bd+ns kill 20;双击,atd kill 2, sonar kill4,
ATP_synthase
发表于 2018-6-22 11:34:13 | 显示全部楼层
本帖最后由 wusiyuanjh 于 2018-6-22 11:35 编辑

卡巴 目前扫描加双击只剩25号不杀,6、20、24为双击主防击杀,25/26

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
UBitch
发表于 2018-6-22 12:47:42 | 显示全部楼层
本帖最后由 UBitch 于 2018-6-22 12:50 编辑

McAfee 12:46
右键Kill 17,双击Kill 4,共Kill 21
查杀率77.8%


Dust-;羅錠
发表于 2018-6-21 21:24:10 | 显示全部楼层
ESET
21/26=80.7%

C:\Users\yilan\Downloads\PACKAGE 06212\(1).exe - a variant of MSIL/Kryptik.OIM trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(10).exe - a variant of MSIL/Kryptik.OMU trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(11).exe - a variant of MSIL/Kryptik.NUV trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(12).exe » NSIS » aside.dll - Win32/Injector.DYTX trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(14).exe - a variant of MSIL/Kryptik.NBN trojan

C:\Users\yilan\Downloads\PACKAGE 06212\(16).exe - a variant of MSIL/Kryptik.IGL trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(17).exe - Win32/PSW.Fareit.L trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(18).exe - a variant of Win32/Formbook.AA trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(19).exe - a variant of Win32/Injector.DYUJ trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(2).exe - a variant of MSIL/Injector.SWC trojan

C:\Users\yilan\Downloads\PACKAGE 06212\(21).exe - a variant of Win32/Injector.DYUJ trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(22).exe - a variant of MSIL/Kryptik.ONB trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(23).exe - a variant of Win32/GenKryptik.CDDL trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(24).exe » INNO » {tmp}\data.dll - a variant of Win32/Kryptik.GFYW trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(26).exe - a variant of Win32/Injector.DXSR trojan

C:\Users\yilan\Downloads\PACKAGE 06212\(3).exe - a variant of Win32/Kryptik.GHZP trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(4).exe - MSIL/NanoCore.E trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(5).exe - a variant of MSIL/Kryptik.OIM trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(7).exe - a variant of Win32/TrojanDownloader.Banload.YEZ trojan
C:\Users\yilan\Downloads\PACKAGE 06212\(8).exe - a variant of MSIL/Kryptik.DTZ trojan

C:\Users\yilan\Downloads\PACKAGE 06212\(9).exe - a variant of MSIL/Autorun.Spy.Agent.CM worm

YU2711
发表于 2018-6-21 21:33:40 | 显示全部楼层
本帖最后由 YU2711 于 2018-6-21 21:37 编辑

KASPERSKY  SCAN   17/26



2018/6/21 下午 09:17:09    检测到恶意对象    WinRAR 壓縮工具    User\   已检测: UDS:DangerousObject.Multi.Generic    D:\(1).exe/data0023.res    云分析   
2018/6/21 下午 09:19:30    检测到恶意对象    WinRAR 壓縮工具    User\    已检测: HEUR:Backdoor.MSIL.Agent.gen    D:\(1).exe    机器学习   
2018/6/21 下午 09:19:31    检测到恶意对象    WinRAR 壓縮工具    User\    已检测: HEUR:Trojan.Win32.Generic    D:\(9).exe    专家分析   
2018/6/21 下午 09:19:32    检测到恶意对象    WinRAR 壓縮工具    User\    已检测: HEUR:Trojan.Win32.Generic    D:\(9).exe    专家分析   
2018/6/21 下午 09:19:34    检测到恶意对象    WinRAR 壓縮工具    User\    已检测: HEUR:Trojan-Downloader.Win32.Agent.gen    D:\(7).exe    机器学习   
2018/6/21 下午 09:19:34    检测到恶意对象    Windows Explorer    User\  已检测: HEUR:Trojan-Spy.Win32.Agent.gen    D:\(2).exe    机器学习   
2018/6/21 下午 09:19:35    检测到恶意对象    Windows Explorer    User\    已检测: HEUR:Trojan.Win32.Agent.gen    D:\(19).exe    机器学习   
2018/6/21 下午 09:19:36    检测到恶意对象    Windows Explorer    User\    已检测: HEUR:Trojan.MSIL.Generic    D:\(11).exe    机器学习   
2018/6/21 下午 09:19:36    检测到恶意对象    Windows Explorer    User\   已检测: UDS:DangerousObject.Multi.Generic    D:\(10).exe/data0008.res    云分析   
2018/6/21 下午 09:19:37    检测到恶意对象    Windows Explorer    User\    已检测: HEUR:Backdoor.Win32.Agent.gen    D:\(10).exe    机器学习   
2018/6/21 下午 09:19:37    检测到恶意对象    Windows Explorer    User\    已检测: Backdoor.Win32.Androm.qaxl    D:\(17).exe    自动分析   
2018/6/21 下午 09:19:38    检测到恶意对象    Windows Explorer    User\    已检测: HEUR:Trojan-Downloader.Win32.Agent.gen    D:\(14).exe    机器学习   
2018/6/21 下午 09:19:39    检测到恶意对象    Windows Explorer    User\    已检测: UDS:DangerousObject.Multi.Generic    D:\(12).exe/aside.dll    云分析   
2018/6/21 下午 09:19:40    检测到恶意对象    Windows Explorer    User\    已检测: HEUR:Trojan-Ransom.Win32.Agent.gen    D:\(12).exe    机器学习   
2018/6/21 下午 09:19:41    检测到恶意对象    Windows Explorer    User\    已检测: HEUR:Trojan.MSIL.Agent.gen    D:\(22).exe    机器学习   
2018/6/21 下午 09:19:42    检测到恶意对象    Windows Explorer    User\    已检测: HEUR:Trojan-Dropper.Win32.Generic    D:\(15).exe    机器学习   
2018/6/21 下午 09:19:43    检测到恶意对象    Windows Explorer    User\    已检测: HEUR:Trojan.Win32.Agent.gen    D:\(21).exe    机器学习   
2018/6/21 下午 09:19:44    检测到恶意对象    Windows Explorer    User\    已检测: HEUR:Trojan.MSIL.Generic    D:\(16).exe    机器学习   
2018/6/21 下午 09:19:45    检测到恶意对象    Windows Explorer    User\    已检测: HEUR:Trojan.Win32.Generic    D:\(18).exe    专家分析   

<Scan_Objects$1722>: 完成时间: 11 分钟以前   (事件: 22, 对象: 130, 威胁: 2, 时间: 00:01:14)   
2018/6/21 下午 09:18:48    检测到恶意对象    D:\(4).exe    已检测: HEUR:Trojan.MSIL.Generic    机器学习    User\
2018/6/21 下午 09:19:30    检测到恶意对象    D:\(5).exe/data0013.res    已检测: UDS:DangerousObject.Multi.Generic    云分析    User\   
2018/6/21 下午 09:19:31    检测到恶意对象    D:\(5).exe    已检测: HEUR:Backdoor.MSIL.Agent.gen    机器学习    User\   


Jirehlov1234
发表于 2018-6-21 21:36:08 来自手机 | 显示全部楼层
YU2711 发表于 2018-6-21 21:33
KASPERSKY  SCAN   17/26



“专家分析”和“自动分析”是啥。。。。。@pal家族
Dust-;羅錠
发表于 2018-6-21 21:37:16 | 显示全部楼层
Jirehlov1234 发表于 2018-6-21 21:36
“专家分析”和“自动分析”是啥。。。。。@pal家族

User\我是真天才 又是啥?
Jerry.Lin
 楼主| 发表于 2018-6-21 21:38:08 | 显示全部楼层
  21:36

(26/26) 100%

  1. 2018/6/21, 21:36:16 [Real-Time Protection] Malware found
  2.         The pattern of 'DR/Delphi.b264c7 (Cloud) [DR/Delphi.b264c7]'
  3.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(26).exe'.
  4.         Action performed: Delete file
  5.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  6. 2018/6/21, 21:34:45 [Real-Time Protection] Malware found
  7.         The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
  8.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(25).exe'.
  9.         Action performed: Delete file
  10.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  11. 2018/6/21, 21:34:28 [Real-Time Protection] Malware found
  12.         The pattern of 'ADWARE/MultiPlug.Gen4 (Cloud) [ADWARE/MultiPlug.Gen4]'
  13.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(24).exe'.
  14.         Action performed: Delete file
  15.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  16. 2018/6/21, 21:33:49 [Real-Time Protection] Malware found
  17.         The pattern of 'TR/Dropper.Gen [trojan]'
  18.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(22).exe'.
  19.         Action performed: Delete file
  20.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  21. 2018/6/21, 21:33:42 [Real-Time Protection] Malware found
  22.         The pattern of 'DR/Delphi.fa115f (Cloud) [DR/Delphi.fa115f]'
  23.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(21).exe'.
  24.         Action performed: Delete file
  25.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  26. 2018/6/21, 21:33:20 [Real-Time Protection] Malware found
  27.         The pattern of 'HEUR/APC (Cloud) [HEUR/APC]'
  28.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(20).exe'.
  29.         Action performed: Delete file
  30.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  31. 2018/6/21, 21:32:55 [Real-Time Protection] Malware found
  32.         The pattern of 'DR/Delphi.5b037f (Cloud) [DR/Delphi.5b037f]'
  33.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(19).exe'.
  34.         Action performed: Delete file
  35.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  36. 2018/6/21, 21:32:29 [Real-Time Protection] Malware found
  37.         The pattern of 'TR/Crypt.ZPACK.Gen [trojan]'
  38.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(18).exe'.
  39.         Action performed: Delete file
  40.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  41. 2018/6/21, 21:32:23 [Real-Time Protection] Malware found
  42.         The pattern of 'TR/Dropper.VB.77e16c (Cloud) [TR/Dropper.VB.77e16c]'
  43.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(17).exe'.
  44.         Action performed: Delete file
  45.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  46. 2018/6/21, 21:32:08 [Real-Time Protection] Malware found
  47.         The pattern of 'TR/Dropper.Gen [trojan]'
  48.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(16).exe'.
  49.         Action performed: Delete file
  50.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  51. 2018/6/21, 21:32:04 [Real-Time Protection] Malware found
  52.         The pattern of 'TR/ATRAPS.Gen [trojan]'
  53.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(13).exe'.
  54.         Action performed: Delete file
  55.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  56. 2018/6/21, 21:31:53 [Real-Time Protection] Malware found
  57.         The pattern of 'TR/Crypt.XPACK.0ec99b (Cloud) [TR/Crypt.XPACK.0ec99b]'
  58.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(12).exe'.
  59.         Action performed: Delete file
  60.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  61. 2018/6/21, 21:31:33 [Real-Time Protection] Malware found
  62.         The pattern of 'TR/Dropper.MSIL.0903ae (Cloud) [TR/Dropper.MSIL.0903ae]'
  63.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(11).exe'.
  64.         Action performed: Delete file
  65.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  66. 2018/6/21, 21:31:11 [Real-Time Protection] Malware found
  67.         The pattern of 'TR/Dropper.MSIL.e3abe0 (Cloud) [TR/Dropper.MSIL.e3abe0]'
  68.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(10).exe'.
  69.         Action performed: Delete file
  70.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  71. 2018/6/21, 21:30:51 [Real-Time Protection] Malware found
  72.         The pattern of 'TR/Dropper.Gen [trojan]'
  73.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(9).exe'.
  74.         Action performed: Delete file
  75.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  76. 2018/6/21, 21:30:47 [Real-Time Protection] Malware found
  77.         The pattern of 'HEUR/AGEN.1008943 [heuristic]'
  78.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(8).exe'.
  79.         Action performed: Delete file
  80.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  81. 2018/6/21, 21:30:42 [Real-Time Protection] Malware found
  82.         The pattern of 'TR/Dldr.Delphi.a56f20 (Cloud) [TR/Dldr.Delphi.a56f20]'
  83.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(7).exe'.
  84.         Action performed: Delete file
  85.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  86. 2018/6/21, 21:30:04 [Real-Time Protection] Malware found
  87.         The pattern of 'HEUR/AGEN.1025504 [heuristic]'
  88.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(6).exe'.
  89.         Action performed: Delete file
  90.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  91. 2018/6/21, 21:29:22 [FireWall] Service activated
  92.         The service has been activated.

  93. 2018/6/21, 21:29:22 [Real-Time Protection] Service started
  94.         Service started.
  95.         Version of service:        15.0.36.198

  96. 2018/6/21, 21:29:19 [Helper Service] Service started
  97.         Service started.
  98.         Version of service:        15.0.36.198
  99.         Version of Engine:        8.3.52.4
  100.         Version of VDF:        8.14.59.228

  101. 2018/6/21, 21:28:43 [Real-Time Protection] Malware found
  102.         The pattern of 'TR/Dropper.MSIL.Gen7 [trojan]'
  103.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(4).exe'.
  104.         Action performed: Delete file
  105.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  106. 2018/6/21, 21:28:31 [Real-Time Protection] Malware found
  107.         The pattern of 'HEUR/AGEN.1002647 [heuristic]'
  108.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(2).exe'.
  109.         Action performed: Delete file
  110.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  111. 2018/6/21, 21:28:21 [Real-Time Protection] Malware found
  112.         The pattern of 'TR/Drop.Agent.smnny [trojan]'
  113.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(15).exe'.
  114.         Action performed: Delete file
  115.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  116. 2018/6/21, 21:28:20 [Real-Time Protection] Malware found
  117.         The pattern of 'TR/AD.Emotet.tixkp [trojan]'
  118.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(3).exe'.
  119.         Action performed: Delete file
  120.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  121. 2018/6/21, 21:28:19 [Real-Time Protection] Malware found
  122.         The pattern of 'TR/Kryptik.orddu [trojan]'
  123.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(14).exe'.
  124.         Action performed: Delete file
  125.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  126. 2018/6/21, 21:28:18 [Real-Time Protection] Malware found
  127.         The pattern of 'TR/AD.Emotet.tixkp [trojan]'
  128.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(3).exe'.
  129.         Action performed: Delete file
  130.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  131. 2018/6/21, 21:28:18 [Real-Time Protection] Malware found
  132.         The pattern of 'TR/Drop.Agent.smnny [trojan]'
  133.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(15).exe'.
  134.         Action performed: Delete file
  135.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  136. 2018/6/21, 21:28:17 [Real-Time Protection] Malware found
  137.         The pattern of 'TR/Drop.Agent.smnny [trojan]'
  138.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(15).exe'.
  139.         Action performed: Delete file
  140.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  141. 2018/6/21, 21:28:17 [Real-Time Protection] Malware found
  142.         The pattern of 'TR/Drop.Agent.smnny [trojan]'
  143.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(15).exe'.
  144.         Action performed: Delete file
  145.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  146. 2018/6/21, 21:28:17 [Real-Time Protection] Malware found
  147.         The pattern of 'TR/Kryptik.orddu [trojan]'
  148.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(14).exe'.
  149.         Action performed: Delete file
  150.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  151. 2018/6/21, 21:28:16 [Real-Time Protection] Malware found
  152.         The pattern of 'TR/AD.njLogger.bcmgm [trojan]'
  153.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(1).exe'.
  154.         Action performed: Delete file
  155.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  156. 2018/6/21, 21:28:15 [Real-Time Protection] Malware found
  157.         The pattern of 'TR/AD.njLogger.bcmgm [trojan]'
  158.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(1).exe'.
  159.         Action performed: Delete file
  160.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  161. 2018/6/21, 21:28:15 [Real-Time Protection] Malware found
  162.         The pattern of 'TR/Kryptik.pdgsn [trojan]'
  163.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(23).exe'.
  164.         Action performed: Delete file
  165.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

  166. 2018/6/21, 21:28:15 [Real-Time Protection] Malware found
  167.         The pattern of 'TR/Kryptik.othhi [trojan]'
  168.         detected in file 'C:\Users\zhong\Downloads\Compressed\VIRUS TEST\PACKAGE 06212\(5).exe'.
  169.         Action performed: Delete file
  170.         User SID: S-1-5-21-3774652721-2607747548-2788097174-1001

复制代码



本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
petr0vic
发表于 2018-6-21 21:39:57 | 显示全部楼层
瑞星ML社区版
14/26


瑞星RDM+社区版
23/26




本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
pal家族
发表于 2018-6-21 21:41:47 | 显示全部楼层
Jirehlov1234 发表于 2018-6-21 21:36
“专家分析”和“自动分析”是啥。。。。。@pal家族

kind of detection mechanism, isn't it?
心醉咖啡
发表于 2018-6-21 22:01:27 | 显示全部楼层
  1. 360杀毒扫描日志

  2. 病毒库版本:
  3. 扫描时间:2018-06-21 22:00:33
  4. 扫描用时:00:00:02
  5. 扫描类型:右键扫描
  6. 扫描文件总数:26
  7. 项目总数:19
  8. 清除项目数:19

  9. 扫描选项
  10. ----------------------
  11. 扫描所有文件:是
  12. 扫描压缩包:是
  13. 发现病毒处理方式:由用户选择处理
  14. 扫描磁盘引导区:是
  15. 扫描 Rootkit:是
  16. 使用云查杀引擎:是
  17. 使用QVM人工智能引擎:是
  18. 扫描建议修复项:是
  19. 常规引擎设置:未使用

  20. 扫描内容
  21. ----------------------
  22. F:\浏览器下载\PACKAGE 06212


  23. 白名单设置
  24. ----------------------


  25. 扫描结果
  26. ======================
  27. 高危风险项
  28. ----------------------
  29. F:\浏览器下载\PACKAGE 06212\(13).exe        HEUR/QVM20.1.FE3B.Malware.Gen        已删除
  30. F:\浏览器下载\PACKAGE 06212\(16).exe        感染型病毒(Win32/Trojan.7c5)        已删除
  31. F:\浏览器下载\PACKAGE 06212\(22).exe        感染型病毒(Win32/Trojan.289)        已删除
  32. F:\浏览器下载\PACKAGE 06212\(23).exe        感染型病毒(Win32/Trojan.23d)        已删除
  33. F:\浏览器下载\PACKAGE 06212\(1).exe        HEUR/QVM03.0.FE73.Malware.Gen        已删除
  34. F:\浏览器下载\PACKAGE 06212\(12).exe        HEUR/QVM42.1.FE73.Malware.Gen        已删除
  35. F:\浏览器下载\PACKAGE 06212\(11).exe        HEUR/QVM03.0.FE73.Malware.Gen        已删除
  36. F:\浏览器下载\PACKAGE 06212\(10).exe        HEUR/QVM03.0.FE73.Malware.Gen        已删除
  37. F:\浏览器下载\PACKAGE 06212\(25).exe        HEUR/QVM20.1.FE3B.Malware.Gen        已删除
  38. F:\浏览器下载\PACKAGE 06212\(17).exe        HEUR/QVM03.0.FE73.Malware.Gen        已删除
  39. F:\浏览器下载\PACKAGE 06212\(2).exe        HEUR/QVM03.0.FE73.Malware.Gen        已删除
  40. F:\浏览器下载\PACKAGE 06212\(19).exe        HEUR/QVM05.1.FE73.Malware.Gen        已删除
  41. F:\浏览器下载\PACKAGE 06212\(18).exe        HEUR/QVM20.1.FE73.Malware.Gen        已删除
  42. F:\浏览器下载\PACKAGE 06212\(21).exe        HEUR/QVM05.1.FE73.Malware.Gen        已删除
  43. F:\浏览器下载\PACKAGE 06212\(3).exe        HEUR/QVM19.1.FE73.Malware.Gen        已删除
  44. F:\浏览器下载\PACKAGE 06212\(4).exe        HEUR/QVM03.0.FE73.Malware.Gen        已删除
  45. F:\浏览器下载\PACKAGE 06212\(5).exe        HEUR/QVM03.0.FE73.Malware.Gen        已删除
  46. F:\浏览器下载\PACKAGE 06212\(7).exe        HEUR/QVM05.1.FE73.Malware.Gen        已删除
  47. F:\浏览器下载\PACKAGE 06212\(9).exe        HEUR/QVM03.0.FE73.Malware.Gen        已删除



  48. 可疑文件上传结果
  49. ----------------------
  50. f:\浏览器下载\package 06212\(1).exe        上传成功
  51. f:\浏览器下载\package 06212\(10).exe        上传成功
  52. f:\浏览器下载\package 06212\(11).exe        上传成功
  53. f:\浏览器下载\package 06212\(12).exe        上传成功
  54. f:\浏览器下载\package 06212\(17).exe        上传成功
  55. f:\浏览器下载\package 06212\(18).exe        上传成功
  56. f:\浏览器下载\package 06212\(19).exe        上传成功
  57. f:\浏览器下载\package 06212\(2).exe        上传成功
  58. f:\浏览器下载\package 06212\(21).exe        上传成功
  59. f:\浏览器下载\package 06212\(3).exe        上传成功
  60. f:\浏览器下载\package 06212\(4).exe        上传成功
  61. f:\浏览器下载\package 06212\(5).exe        上传成功
  62. f:\浏览器下载\package 06212\(7).exe        上传成功
  63. f:\浏览器下载\package 06212\(9).exe        上传成功
复制代码
Jirehlov1234
发表于 2018-6-21 22:05:48 | 显示全部楼层
pal家族 发表于 2018-6-21 21:41
kind of detection mechanism, isn't it?

没用过KES,以前没听过这俩词汇。是本地的启发吗?我好像见过有个词叫“启发分析”来着。。。有啥区别?
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-1 07:33 , Processed in 0.133855 second(s), 21 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表