本帖最后由 stupid1man 于 2018-8-12 19:54 编辑  
 
紅傘  19:42 
實時防護+右鍵掃描:12/13(92.3%) 
 
剩下檔案:(7) 
 
————————掃描部份————————  
Start of the scan: 2018-08-12 19:42:08 
08/12/2018,19-42-09        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\shane siu\desktop\package 0812\0812(1).exe' 
08/12/2018,19-42-09        [INFO]        c:\users\shane siu\desktop\package 0812\0812(1).exe 
08/12/2018,19-42-09        [INFO]        [DETECTION] file contains 'TR/AD.BrowserPassview.ayzfu' 
08/12/2018,19-42-09        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\shane siu\desktop\package 0812\0812(10).exe' 
08/12/2018,19-42-09        [INFO]        c:\users\shane siu\desktop\package 0812\0812(10).exe 
08/12/2018,19-42-09        [INFO]        [DETECTION] file contains 'TR/Dropper.MSIL.Gen7' 
08/12/2018,19-42-09        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\shane siu\desktop\package 0812\0812(11).exe' 
08/12/2018,19-42-09        [INFO]        c:\users\shane siu\desktop\package 0812\0812(11).exe 
08/12/2018,19-42-09        [INFO]        [DETECTION] file contains 'TR/Crypt.TPM.Gen' 
08/12/2018,19-42-12        [INFO]        [CLOUD] File 'c:\users\shane siu\desktop\package 0812\0812(12).exe' needs to be uploaded to cloud. User confirmation is needed. 
08/12/2018,19-42-12        [INFO]        Successful Cloud SDK initialization and license check. 
08/12/2018,19-42-12        [INFO]        The file 'c:\users\shane siu\desktop\package 0812\0812(12).exe' was scanned with the Protection Cloud. SHA256 = 0E987A5515E795C1C9B7876E962FF83039B22F271CBEA8E355A2B001C791843F 
08/12/2018,19-42-13        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\shane siu\desktop\package 0812\0812(13).exe' 
08/12/2018,19-42-13        [INFO]        c:\users\shane siu\desktop\package 0812\0812(13).exe 
08/12/2018,19-42-13        [INFO]        [DETECTION] file contains 'TR/Dropper.Gen' 
08/12/2018,19-42-13        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\shane siu\desktop\package 0812\0812(2).exe' 
08/12/2018,19-42-13        [INFO]        c:\users\shane siu\desktop\package 0812\0812(2).exe 
08/12/2018,19-42-13        [INFO]        [DETECTION] file contains 'TR/Dropper.Gen7' 
08/12/2018,19-42-14        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\shane siu\desktop\package 0812\0812(6).exe' 
08/12/2018,19-42-14        [INFO]        c:\users\shane siu\desktop\package 0812\0812(6).exe 
08/12/2018,19-42-14        [INFO]        [DETECTION] file contains 'TR/Crypt.ZPACK.Gen' 
08/12/2018,19-42-14        [INFO]        [CLOUD] File 'c:\users\shane siu\desktop\package 0812\0812(9).exe' needs to be uploaded to cloud. User confirmation is needed. 
08/12/2018,19-42-14        [INFO]        The file 'c:\users\shane siu\desktop\package 0812\0812(9).exe' was scanned with the Protection Cloud. SHA256 = ADCCD5C5D0FC5864C4834E90DC1CB58F16214279F168FBF0535D1EB87F7F3782 
08/12/2018,19-42-36        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\shane siu\desktop\package 0812\0812(12).exe' 
08/12/2018,19-42-36        [INFO]        The file 'c:\users\shane siu\desktop\package 0812\0812(12).exe' has been uploaded to the Protection Cloud and analyzed. SHA256 = 0E987A5515E795C1C9B7876E962FF83039B22F271CBEA8E355A2B001C791843F 
08/12/2018,19-42-36        [INFO]        c:\users\shane siu\desktop\package 0812\0812(12).exe 
08/12/2018,19-42-36        [INFO]        [DETECTION] file contains 'TR/Dropper.MSIL.0e987a' 
08/12/2018,19-42-50        [INFO]        FP reports status 'NO False Positive' for file 'c:\users\shane siu\desktop\package 0812\0812(9).exe' 
08/12/2018,19-42-50        [INFO]        The file 'c:\users\shane siu\desktop\package 0812\0812(9).exe' has been uploaded to the Protection Cloud and analyzed. SHA256 = ADCCD5C5D0FC5864C4834E90DC1CB58F16214279F168FBF0535D1EB87F7F3782 
08/12/2018,19-42-50        [INFO]        c:\users\shane siu\desktop\package 0812\0812(9).exe 
08/12/2018,19-42-50        [INFO]        [DETECTION] file contains 'TR/Crypt.XPACK.adccd5' 
08/12/2018,19-43-00        [INFO]        repair.rdf loaded (version: 1.0.44.0)  
 
 |