本帖最后由 静影沉璧 于 2018-8-3 21:33 编辑
趋势科技 20:50 虚拟机:
手动扫描:2/22
双击:7/22
日志:
以下样本被清除:
2018/8/3 20:50,TSPY_HPLOKI.SMBD,威胁,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(9).exe,已移除,手动扫描,,,,
2018/8/3 20:50,Mal_Swizzor,病毒,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(11).exe,已移除,手动扫描,,,,
2018/8/3 20:56,HTTP_LOKI_REQUEST,威胁,C:\users\administrator\desktop\package 0803\0803(2).exe,已移除,网络内容扫描,,,,
2018/8/3 20:58,HEU_AEGISCS219,威胁,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(5).exe,已移除,实时扫描,,,,
2018/8/3 20:59,HEU_AEGISCS957,威胁,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(6).exe,已移除,实时扫描,,,,
2018/8/3 21:08,HEU_AEGISCS957,威胁,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(14).exe,已移除,实时扫描,,,,
2018/8/3 21:10,HEU_AEGISCS957,威胁,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(15).exe,已移除,实时扫描,,,,
2018/8/3 21:12,HEU_AEGISCS219,威胁,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(17).exe,已移除,实时扫描,,,,
2018/8/3 21:15,TSPY_FAREIT.MIP00000001,威胁,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(18).exe,已移除,实时扫描,,,,
以下样本被阻止,不删除本体:
2018/8/3 21:09,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(8).exe,未知,,? Microsoft Corporation. All rights reserved.,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(8).exe,已终止
2018/8/3 21:16,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(16).exe,texaS instrumeNTS incorpoRATED,2.00,Nce fee, Vne,C:\Users\Administrator\AppData\Roaming\pidloc.txt,已终止
2018/8/3 21:16,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(19).exe,未知,,,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(19).exe,已终止
2018/8/3 21:17,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(20).exe,未知,,,ZwWriteVirtualMemory,已终止
2018/8/3 21:17,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(21).exe,texas instrumenTS incorporATED,2.00,NCe Fee, VNe,C:\Program Files\WPA Monitor\wpamon.exe,已终止
2018/8/3 21:17,C:\Users\Administrator\Desktop\PACKAGE 0803\0803(22).exe,未知,2.1.0.0,Copyright 2018 Private Version,ZwWriteVirtualMemory,已终止
Total:9/22=41%
剩余样本双击结果:
1,13号样本驻留内存
3,4,7,12样本运行后自退
10号样本只杀衍生物
|