改成普通后,趋势被当场打回原形,果然是云安全软件。。。
扫描:6/23
双击:KILL 7X
Total:13/23=57%
这回日志正常了(蓝色为病毒本体,其余目测是某些样本运行后的衍生物):
2018/7/31 22:25,TSPY_HPLOKI.SMBD,威胁,C:\Users\Administrator\Desktop\PACKAGE 0731\0731(2).exe,已移除,手动扫描,,,,
2018/7/31 22:25,TSPY_HPLOKI.SM1,威胁,C:\Users\Administrator\Desktop\PACKAGE 0731\0731(12).exe,已移除,手动扫描,,,,
2018/7/31 22:25,TSPY_HPLOKI.SMBD,威胁,C:\Users\Administrator\Desktop\PACKAGE 0731\0731(5).exe,已移除,手动扫描,,,,
2018/7/31 22:25,TSPY_HPLOKI.SM1,威胁,C:\Users\Administrator\Desktop\PACKAGE 0731\0731(13).exe,已移除,手动扫描,,,,
2018/7/31 22:25,TSPY_HPLOKI.SM1,威胁,C:\Users\Administrator\Desktop\PACKAGE 0731\0731(8).exe,已移除,手动扫描,,,,
2018/7/31 22:25,TSPY_HPLOKI.SM1,威胁,C:\Users\Administrator\Desktop\PACKAGE 0731\0731(14).exe,已移除,手动扫描,,,,
2018/7/31 22:26,HEU_FALCONTroj.Win32.Gen.XXBM100FF004,威胁,C:\Users\Administrator\Desktop\PACKAGE 0731\0731(1).exe,已移除,实时扫描,,,,
2018/7/31 22:28,HEU_AEGISCS922,威胁,C:\Users\Administrator\Desktop\PACKAGE 0731\0731(6).exe,已移除,实时扫描,,,,
2018/7/31 22:28,HEU_CDPLC016,威胁,C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\window.task.vbs,已移除,关联扫描,,,,
2018/7/31 22:29,HEU_CDPLCEXT,威胁,C:\Users\Administrator\AppData\Roaming\The MONY Group Inc\The MONY Group Inc.exe,已移除,关联扫描,,,,
2018/7/31 22:31,HTTP_LOKI_REQUEST,威胁,C:\users\administrator\desktop\package 0731\0731(11).exe,已移除,网络内容扫描,,,,
2018/7/31 22:31,HEU_AEGISCS010,威胁,C:\Users\Administrator\Desktop\PACKAGE 0731\0731(18).exe,已移除,实时扫描,,,,
2018/7/31 22:31,HEU_AEGISCS010,威胁,c:\windows\win.ini,已移除,实时扫描,,,,
2018/7/31 22:32,HEU_AEGISCS957,威胁,C:\Users\Administrator\Desktop\PACKAGE 0731\0731(19).exe,已移除,实时扫描,,,,
2018/7/31 22:33,HEU_AEGISCS219,威胁,C:\Users\Administrator\Desktop\PACKAGE 0731\0731(22).exe,已移除,实时扫描,,,,
2018/7/31 22:43,HEU_CDPLCEXT,威胁,C:\Users\Administrator\AppData\Roaming\Di Giorgio Corporation\Di Giorgio Corporation.exe,已移除,关联扫描,,,,
2018/7/31 22:43,HEU_CDPLC016,威胁,C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\microsoft.vbs,已移除,关联扫描,,,,
2018/7/31 22:44,HEU_AEGISCS976,威胁,c:\users\administrator\desktop\package 0731\0731(17).exe,已移除,实时扫描,,,,
剩余样本双击结果:除21号样本运行后即停止工作,23号样本改EXE后提示不是有效的win32位应用程序以外,其余均驻留内存。
|