本帖最后由 静影沉璧 于 2018-8-2 20:59 编辑
趋势科技(虚拟机测试,防御等级:普通)手动扫描:0/26
双击:
以下样本被成功防御并清除:
2018/8/2 20:22,TSPY_FAREIT.MIP00000001,威胁,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(4).exe,已移除,实时扫描,,,,
2018/8/2 20:23,TSPY_FAREIT.MIP00000001,威胁,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(8).exe,已移除,实时扫描,,,,
2018/8/2 20:24,HEU_AEGISCS985,威胁,c:\users\administrator\desktop\package 0802\0802(11).exe,已移除,实时扫描,,,,
2018/8/2 20:25,HEU_FALCONTroj.Win32.Gen.XXBM100FF004,威胁,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(15).exe,已移除,实时扫描,,,,
2018/8/2 20:25,HEU_AEGISCS219,威胁,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(14).exe,已移除,实时扫描,,,,
2018/8/2 20:26,TSPY_FAREIT.MIP00000001,威胁,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(18).exe,已移除,实时扫描,,,,
2018/8/2 20:27,HEU_AEGISCS957,威胁,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(23).exe,已移除,实时扫描,,,,
2018/8/2 20:27,HEU_FALCONTroj.Win32.Gen.XXBM100FF004,威胁,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(26).exe,需要重新启动,实时扫描,,,,
2018/8/2 20:35,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(12).exe,未知,,,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(12).exe,已清除
2018/8/2 20:44,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(3).exe,未知,,,C:\Windows\explorer.exe,已清除
以下样本被终止,本体未删除:
2018/8/2 20:19,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(1).exe,未知,,,HKCU\Software\Microsoft\Windows\CurrentVersion\Run\remcos,已终止
2018/8/2 20:21,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(2).exe,Skype Technologies S.A.,8.25.0.5,(c) 2018 Skype and/or Microsoft,ZwWriteVirtualMemory,已终止
2018/8/2 20:23,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(9).exe,未知,,,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(9).exe,已终止
2018/8/2 20:26,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(19).exe,未知,,,ZwWriteVirtualMemory,已终止
2018/8/2 20:26,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(21).exe,未知,,,ZwWriteVirtualMemory,已终止
2018/8/2 20:28,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(25).exe,Heaventools Software,1.99.6.1400,Copyright ? 2000-2009 Heaventools Software,ZwWriteVirtualMemory,已终止
2018/8/2 20:52,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(16).exe,未知,,,C:\Users\Administrator\Desktop\PACKAGE 0802\0802(16).exe,已终止
剩余样本双击情况:
样本10,22成功运行并驻留内存
样本20提示缺少MSVCP100.dll,未运行
样本5,6,13运行一段时间后自退
样本17,24运行后提示停止工作
样本7弹窗后即关闭
Total:10/26=38.5%
|