本帖最后由 静影沉璧 于 2018-8-1 20:23 编辑
趋势科技(虚拟机测试,防护级别为普通)扫描:KILL 2X
双击:KILL 5X(13,15号样本只阻止操作,未删除本体)
Total:7/17=41%
日志(蓝色为病毒本体,黑色是某些病毒运行后的衍生物):
2018/8/1 19:43,TSPY_HPLOKI.SMBD,威胁,C:\Users\Administrator\Desktop\PACKAGE 0801\0801(12).exe,已移除,手动扫描,,,,
2018/8/1 19:44,TSPY_HPLOKI.SMBD,威胁,C:\Users\Administrator\Desktop\PACKAGE 0801\0801(17).exe,已移除,手动扫描,,,,
2018/8/1 19:45,HTTP_HANCITOR_REQUEST,威胁,C:\users\administrator\desktop\package 0801\0801(1).exe,已移除,网络内容扫描,,,,
2018/8/1 19:47,TSPY_FAREIT.MIP00000001,威胁,C:\Users\Administrator\Desktop\PACKAGE 0801\0801(5).exe,已移除,实时扫描,,,,
2018/8/1 19:48,TSPY_FAREIT.MIP00000001,威胁,C:\Users\Administrator\Desktop\PACKAGE 0801\0801(6).exe,已移除,实时扫描,,,,
2018/8/1 19:51,HEU_AEGISCS936,威胁,C:\Users\Administrator\AppData\Local\Temp\regserv31.exe,已移除,实时扫描,,,,
2018/8/1 19:51,HEU_AEGISCS936,威胁,C:\Users\Administrator\AppData\Local\Temp\regserv32.exe,已移除,实时扫描,,,,
2018/8/1 19:53,HEU_AEGIS1478T,威胁,C:\Users\Administrator\Desktop\PACKAGE 0801\0801(14).exe,已移除,实时扫描,,,,
2018/8/1 19:56,HEU_AEGISCS010,威胁,C:\Users\Administrator\Desktop\PACKAGE 0801\0801(16).exe,已移除,实时扫描,,,,
2018/8/1 19:56,HEU_AEGISCS010,威胁,c:\windows\win.ini,已移除,实时扫描,,,,
2018/8/1 19:56,C:\Users\Administrator\Desktop\PACKAGE 0801\0801(13).exe,Al Rashid LLC,1.0.0.0,Copyright © 2008 - 2018. All rights reserved.,ZwWriteVirtualMemory,已终止
2018/8/1 19:57,C:\Users\Administrator\Desktop\PACKAGE 0801\0801(15).exe,未知,,,ZwWriteVirtualMemory,已终止
|