本帖最后由 小飞侠.net 于 2018-8-7 02:58 编辑
,,, ,,,
瑞星---(Windows 10 Creators Update(Redstone 4)....1803):云引擎(开)RDM+引擎(开)
瑞星反恶软引擎命令行扫描器(社区交流版)
编译于:Sep 22 2017 15:07:50
提示:
- 本工具供社区交流使用,请勿用于其他用途
- 本工具没有恶意软件删除、清除、隔离功能
- 本工具包含开发中的新特性,结果仅供参考
* 命令行中的选项开关:-output-json -log=C:\瑞星RDM+引擎\ScanLog_180807025428.log
* 获取恶软签名库最新版本 ...
* 下载恶软签名库配置文件 ...
* 创建恶软签名库升级组件 ...
* 计算并下载增量文件 ...
* 升级恶软签名库 ...
* 恶软签名库升级成功
* 扫描目标 : (1) C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210
* 加载恶软签名库: C:\瑞星RDM+引擎/malware.rmd
* 恶软签名库加载成功,发布序号为 4719
* 读取恶软签名库配置 ...
* 云辅助扫描组件初始化失败.
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
* 初始化引擎环境 ...
扫描开始: Tue Aug 07 02:54:49 2018
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(11).exe","infect":{"engine":"md5","signature":"bWQ1Ot+FzknxPaKcIqxtc3IIUP8","threat":"Spyware.KeyLogger!8.12F"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(14).exe","infect":{"engine":"rdmk","signature":"cmRtazqSTyWVkJREYY3sBAY8vvSp","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(15).exe","infect":{"engine":"rdmk","signature":"cmRtazo8kMNIIMyXQ+ZgJGGt5eOt","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(13).exe","infect":{"engine":"md5","signature":"bWQ1Oi0jb2ZRiH5IM5+WHtcF2Eo","threat":"Dropper.Generic!8.35E"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(1).exe","infect":{"engine":"md5","signature":"bWQ1OqxTYJjGGfsAZLjUb9Ycvs4","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(12).exe","infect":{"engine":"rdmk","signature":"cmRtazq9CsblwvzZm9CWwQuLQAYD","threat":"Trojan.Injector!1.AFE3"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(16).exe","infect":{"engine":"md5","signature":"bWQ1OvsZQ0/BMoWDz4agZEKWD9Q","threat":"Backdoor.Noancooe!8.176"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(10).exe","infect":{"engine":"rdmk","signature":"cmRtazq2Vc3rdhu11PoPCLCgF0tH","threat":"Trojan.Injector!1.AFE3"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(19).exe","infect":{"engine":"md5","signature":"bWQ1OrfDk9VuxZK9ttvrgF7wogI","threat":"Trojan.Fuery!8.EAFB"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(22).exe","infect":{"engine":"rdmk","signature":"cmRtazqWu7yYQgRZQgkYYvAIZd76","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(20).exe","infect":{"engine":"rdmk","signature":"cmRtazoi6yNfBDbsyIn7dvuw3GdO","threat":"Trojan.Injector!8.C4"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(2).exe","infect":{"engine":"rdmk","signature":"cmRtazofp54/6oWmdF5r3vAOK0P6","threat":"Trojan.Injector!1.AFE3"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(21).exe","infect":{"engine":"md5","signature":"bWQ1OlS8cbxIAktYx5cExumnPo0","threat":"Trojan.Agent!8.B1E"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(23).exe","infect":{"engine":"md5","signature":"bWQ1OkhiMQCJVpTH8rrO1NscwG0","threat":"Ransom.Agent!8.6B7"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(17).exe","infect":{"engine":"md5","signature":"bWQ1OsuGaId5AQurUZz/t0xlZj4","threat":"Trojan.Spatet!8.22F"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(24).exe","infect":{"engine":"md5","signature":"bWQ1OrvJpsxui5zG3/KGZ+DqYIc","threat":"Dropper.Generic!8.35E"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(3).exe","infect":{"engine":"md5","signature":"bWQ1OshWASxWTf6kJ38nwFnnAgc","threat":"Dropper.Generic!8.35E"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(27).exe","infect":{"engine":"rdmk","signature":"cmRtazrsh+J3d7YDVEtSi+XFHGbz","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(26).exe","infect":{"engine":"rdmk","signature":"cmRtazpfuXq5dH9XXxvDGTUQwphY","threat":"Malware.Heuristic!ET#89%"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(25).exe","infect":{"engine":"rdmk","signature":"cmRtazpfuXq5dH9XXxvDGTUQwphY","threat":"Malware.Heuristic!ET#89%"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(28).exe","infect":{"engine":"rdmk","signature":"cmRtazoKfwUK8VMT9ieVAJGWj7NO","threat":"Trojan.GenKryptik!8.AA55"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(7).exe","infect":{"engine":"rdmk","signature":"cmRtazplrPA8k2/bQMyV68Bdbu6V","threat":"Malware.Heuristic!ET#91%"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(6).exe","infect":{"engine":"rdmk","signature":"cmRtazo4BVlHBD89usOcy5rOv58B","threat":"Trojan.Azden!8.F0E3"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(8).exe","infect":{"engine":"rdmk","signature":"cmRtazqCTlK6Qdued6AHIg8aZ4OQ","threat":"Trojan.Injector!1.AFE3"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(9).exe","infect":{"engine":"rdmk","signature":"cmRtazo5hf4vb96ki9qzYAqxuD/m","threat":"Trojan.Injector!1.AFE3"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(4).exe","infect":{"engine":"rdmk","signature":"cmRtazpx/hfo/5qKCBwTnzKgCeIQ","threat":"Malware.Heuristic!ET#82%"},"type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(5).exe","type":"scan"}
{"filename":"C:\\Users\\Admin\\Desktop\\AVtest100\\PACKAGE 0806VBInject0210\\PACKAGE 0806VBInject0210\\0806(18).exe","type":"scan"}
扫描结束: Tue Aug 07 02:54:51 2018
总扫描耗时: 0:2:254(m:s:ms)
总扫描对象: 29
总扫描文件: 28
总恶意文件: 26
有效检出率: 92.86%---VirusTotal?没人上传就不会超过50%
Emsisoft Emergency Kit - 版本 2018.6
上次更新: 2018-08-06 22:59:16
用户帐号: TECLAST\Admin
电脑名称: TECLAST
操作系统版本: Windows 10 x64
Emsisoft Emergency Kit 绿色免费版
(已开启)加入 Emsisoft 云、更新源:测试版
Bitdefender(B)+Emsisoft(A) 双引擎
扫描设置:
扫描方式: 自定义扫描
对象: Rootkits, 恶意残留, C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\
检测流氓软件(PUPs): On
扫描压缩包: On
扫描邮件存档: Off
ADS数据流: On
文件扩展名过滤: Off
直接磁盘访问: Off
扫描开始于: 2018-08-07 2:46:31
C:\Users\Admin\AppData\Roaming\baidu 发现风险: Application.AppInstall (A) [224507]
C:\Users\Admin\AppData\Local\baidu 发现风险: Application.AppInstall (A) [226898]
C:\Users\Admin\AppData\Local\sysassistbyhotwheel 发现风险: Application.Toolbar (A) [230313]
Key: HKEY_USERS\S-1-5-21-1320124207-2627790254-4257915705-1001\SOFTWARE\PPSTREAM 发现风险: Application.Toolbar (A) [281127]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(1).exe 发现风险: Trojan.GenericKD.40371387 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(12).exe 发现风险: Trojan.GenericKD.40371770 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(10).exe 发现风险: Trojan.Agent.DCQE (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(11).exe 发现风险: Gen:Variant.Zusy.160900 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(14).exe 发现风险: Gen:Variant.Graftor.507704 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(13).exe 发现风险: Gen:Variant.Barys.15557 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(15).exe 发现风险: Gen:Variant.Ursu.5156 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(18).exe 发现风险: Trojan.GenericKD.40371863 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(20).exe 发现风险: Gen:Variant.Razy.373960 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(2).exe 发现风险: Trojan.Agent.DCQE (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(21).exe 发现风险: Gen:Variant.Razy.373344 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(23).exe 发现风险: Gen:Variant.MSILPerseus.41172 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(25).exe 发现风险: Gen:Trojan.Heur.VP2.pn3@amUnMzni (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(27).exe 发现风险: Trojan.GenericKD.40372236 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(26).exe 发现风险: Gen:Trojan.Heur.VP2.nn3@amUnMzni (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(28).exe 发现风险: Gen:Variant.Razy.373960 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(5).exe 发现风险: Trojan.Generic.23023437 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(3).exe 发现风险: Gen:Variant.Johnnie.120617 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(7).exe 发现风险: Gen:Variant.Ransom.Xorist.79 (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(9).exe 发现风险: Trojan.Agent.DCQE (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(8).exe 发现风险: Trojan.Agent.DCQE (B) [krnl.xmd]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(16).exe 发现风险: Trojan.Lethic.Gen.7 (B) [krnl.xmd]
已扫描 61715
发现 26---VirusTotal?没人上传就不会超过50%
扫描完成后: 2018-08-07 2:46:52
扫描时间: 0:00:21
ESET Endpoint Security 64位(高级启发式(Y)+压缩文件(Y)+自解压加壳(Y)+DNA智能签名(Y)++(Windows 10 Creators Update(Redstone 4)....1803):
日志
正在扫描日志
检测引擎的版本: 17838P (20180806)
日期: 2018-08-07 时间: 2:37:53
已扫描的磁盘、文件夹和文件: C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(1).exe - Win32/GenKryptik.CFHT 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(10).exe - Win32/Injector.DZPV 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(11).exe - MSIL/Spy.Keylogger.AWS 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(12).exe - Win32/Injector.DZPV 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(13).exe - MSIL/GenKryptik.CHEX 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(14).exe - Win32/Kryptik.GJOF 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(15).exe - Win32/Injector.DZQH 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(16).exe - Win32/Injector.DZPZ 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(17).exe - Win32/Spatet.T 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(18).exe - Win32/Injector.DZPZ 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(19).exe - Win32/GenKryptik.CHIW 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(2).exe - MSIL/NanoCore.E 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(20).exe - Win32/Injector.DZQF 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(21).exe - MSIL/Agent.SSK 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(22).exe - Win32/Injector.DZQF 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(23).exe > DOTNETREACTOR - MSIL/Filecoder.JobCrypter.C 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(24).exe - Win32/Injector.DZQO 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(25).exe - Win32/Injector.DZQH 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(26).exe - Win32/Injector.DZQH 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(27).exe - Win32/Injector.DZQF 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(28).exe - Win32/Injector.DZQF 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(3).exe - MSIL/GenKryptik.CHEX 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(4).exe > INNO > {tmp}\nklaprok.dll - Win32/Tinukebot.K 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(6).exe - Win32/Spy.Ursnif.BW 特洛伊木马 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(7).exe - MSIL/Kryptik.PBW 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(8).exe - Win32/Injector.DZPV 特洛伊木马 的变种 - 通过删除清除 [1]
C:\Users\Admin\Desktop\AVtest100\PACKAGE 0806VBInject0210\PACKAGE 0806VBInject0210\0806(9).exe - Win32/Injector.DZPV 特洛伊木马 的变种 - 通过删除清除 [1]
已扫描的对象数: 92
发现的威胁数: 27
已清除对象数: 27---VirusTotal?没人上传就不会超过50%
完成时间: 2:38:46 总扫描时间: 53 秒 (00:00:53)
备注:
[1] 由于对象中仅包含病毒主体,因此已被删除。
火绒安全---( Windows 7 Ultimate with SP1 简体中文旗舰版....):部分未知文件已发送到seclab@huorong.cn,等处理中。。。
病毒库:2018-08-06 16:47
开始时间:2018-08-07 02:06
总计用时:00:00:30
扫描对象:447个
扫描文件:28个
发现风险:9个
已处理风险:0个
发现系统修复项:0个
处理系统修复项:0个
病毒详情
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806\0806(1).exe, 病毒名:HVM:VirTool/Obfuscator.gen!A, 病毒ID:[b27d4294cde6a1ec], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806\0806(11).exe, 病毒名:TrojanSpy/KeyLogger.s, 病毒ID:[7775e7defe5e3928], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806\0806(19).exe, 病毒名:Trojan/VBInject.b, 病毒ID:[e4beee39ea2e9885], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806\0806(20).exe, 病毒名:HEUR:VirTool/VB.Obfuscator.gen!A, 病毒ID:[636e99dfed83873b], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806\0806(23).exe, 病毒名:Ransom/MSIL.JobCrypter.a, 病毒ID:[42056f958e55cfb8], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806\0806(22).exe, 病毒名:HEUR:VirTool/VB.Obfuscator.gen!A, 病毒ID:[636e99dfed83873b], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806\0806(27).exe, 病毒名:HEUR:VirTool/VB.Obfuscator.gen!A, 病毒ID:[636e99dfed83873b], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806\0806(28).exe, 病毒名:HEUR:VirTool/VB.Obfuscator.gen!A, 病毒ID:[636e99dfed83873b], 处理结果:已忽略
风险路径:C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806\0806(6).exe, 病毒名:HVM:VirTool/Obfuscator.gen!A, 病毒ID:[b27d4294cde6a1ec], 处理结果:已忽略
文件名称: C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806.zip
文件大小: 14.1 MB (14,787,297 字节)
修改时间: 2018年08月07日,02:05:35
MD5: 22B964B4B84FC4B88E9F7395F0DFDDA5
SHA1: 1D3F0CCD62E264AE5E0B872AFDC7B34B17A5347F
SHA256: B0B93630CED8A5B1EE4346B061168D72095F4ED241C5F6D821BFA037900CC0B1
CRC32: 10BF7B91
计算时间: 1.48s (9.98 MB/s)
Dr.Web CureIt! 简体中文绿色免费版---( Windows 7 Ultimate with SP1 简体中文旗舰版....):
-----------------------------------------------------------------------------
Start scanning
-----------------------------------------------------------------------------
Command line used:-rpcep:\pipe\8F433B9A6 -rpcpr:np
Limit the use of the computer resources to 100%
Instances used for this session: 10
Object(s) to scan:
- C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(10).exe - infected with Trojan.PWS.Stealer.21154
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(10).exe - infected
>C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(11).exe is BINARYRES container
>>C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(11).exe\data003 is NET container
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(11).exe - container
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(15).exe - Ok
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(18).exe - infected with Trojan.PWS.Stealer.18836
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(18).exe - infected
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(12).exe - infected with Trojan.PWS.Stealer.21154
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(12).exe - infected
>C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(17).exe is BINARYRES container
>>C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(17).exe\data001 is NET container
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(20).exe - infected with Trojan.DownLoader25.11684
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(14).exe - infected with Trojan.Encoder.24384
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(14).exe - infected
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(20).exe - infected
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(17).exe - container
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(19).exe - Ok
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(16).exe - Ok
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(2).exe - infected with Trojan.PWS.Stealer.21154
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(2).exe - infected
>C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(1).exe is ZLIB container
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(24).exe - infected with Trojan.PWS.Stealer.1932
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(24).exe - infected
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(1).exe - container
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(23).exe - infected with Trojan.MulDrop8.34069
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(23).exe - infected
>C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(3).exe is BINARYRES container
>>C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(3).exe\data001 is NET container
>>C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(3).exe\data002 - packed by XOREXE
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(3).exe - container
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(21).exe - Ok
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(27).exe - infected with Trojan.PWS.Stealer.13052
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(27).exe - infected
>C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(5).exe - packed by BINARYRES
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(5).exe - Ok
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(6).exe - Ok
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(7).exe - infected with Trojan.Nanocore.24
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(7).exe - infected
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(28).exe - Ok
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(25).exe - Ok
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(22).exe - Ok
>C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(13).exe is NET container
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(13).exe - container
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(9).exe - infected with Trojan.PWS.Stealer.21154
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(9).exe - infected
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(8).exe - infected with Trojan.PWS.Stealer.21154
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(8).exe - infected
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(26).exe - Ok
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(4).exe - infected with Trojan.TinyNuke.30
C:\Users\xfxnet2000\Desktop\MX Player Pro\175418360\145802370\479704092\AVTest100\PACKAGE 0806VBInject0210\0806(4).exe - infected
Total 22494975 bytes in 28 files scanned (39 objects)
Total 15 files (26 objects) are clean
Total 13 files are infected---VirusTotal?没人上传就不会超过50%
Scan time is 00:00:04.797
|