本帖最后由 欧阳宣 于 2018-9-10 23:52 编辑
avira
测试环境:win10 x64 1809
测试产品:Avira antivirus pro
病毒库版本:8.15.6.36
测试项目:扫描
测试配置:启发调高
结果:扫描 11/17
日志:
- 09/10/2018,10-31-03 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\卡饭病毒样本包 20180910\kafan_sample_0c2480b3aebde4a4a5ceaa2be4a31704c075674e81bf341e4a7ed43a394fbca6.exe'
- 09/10/2018,10-31-03 [INFO] Successful Cloud SDK initialization and license check.
- 09/10/2018,10-31-03 [INFO] The file 'e:\samples\卡饭病毒样本包 20180910\kafan_sample_0c2480b3aebde4a4a5ceaa2be4a31704c075674e81bf341e4a7ed43a394fbca6.exe' was scanned with the Protection Cloud. SHA256 = 0C2480B3AEBDE4A4A5CEAA2BE4A31704C075674E81BF341E4A7ED43A394FBCA6
- 09/10/2018,10-31-03 [INFO] e:\samples\卡饭病毒样本包 20180910\kafan_sample_0c2480b3aebde4a4a5ceaa2be4a31704c075674e81bf341e4a7ed43a394fbca6.exe
- 09/10/2018,10-31-03 [INFO] [DETECTION] file contains 'HEUR/APC'
- 09/10/2018,10-31-04 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\卡饭病毒样本包 20180910\kafan_sample_265e84247b6a5b434b3d2fd2152aff4265ae75f22fb67d0f905c5134b365213e.exe'
- 09/10/2018,10-31-04 [INFO] e:\samples\卡饭病毒样本包 20180910\kafan_sample_265e84247b6a5b434b3d2fd2152aff4265ae75f22fb67d0f905c5134b365213e.exe
- 09/10/2018,10-31-04 [INFO] [DETECTION] file contains 'HEUR/AGEN.1033129'
- 09/10/2018,10-31-04 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\卡饭病毒样本包 20180910\kafan_sample_b324d2c5a763cf1c1bcd87201e9573fea463f0e2b2dd13342690792517a9003f.exe'
- 09/10/2018,10-31-04 [INFO] e:\samples\卡饭病毒样本包 20180910\kafan_sample_b324d2c5a763cf1c1bcd87201e9573fea463f0e2b2dd13342690792517a9003f.exe
- 09/10/2018,10-31-04 [INFO] [DETECTION] file contains 'HEUR/AGEN.1014551'
- 09/10/2018,10-31-04 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\卡饭病毒样本包 20180910\kafan_sample_d7ad34aa329a9fbc4af3b07c19435fa8ab64a2d1710b0da150f82f06e6b6b841.exe'
- 09/10/2018,10-31-04 [INFO] The file 'e:\samples\卡饭病毒样本包 20180910\kafan_sample_d7ad34aa329a9fbc4af3b07c19435fa8ab64a2d1710b0da150f82f06e6b6b841.exe' was scanned with the Protection Cloud. SHA256 = D7AD34AA329A9FBC4AF3B07C19435FA8AB64A2D1710B0DA150F82F06E6B6B841
- 09/10/2018,10-31-04 [INFO] e:\samples\卡饭病毒样本包 20180910\kafan_sample_d7ad34aa329a9fbc4af3b07c19435fa8ab64a2d1710b0da150f82f06e6b6b841.exe
- 09/10/2018,10-31-04 [INFO] [DETECTION] file contains 'DR/Delphi.d7ad34'
- 09/10/2018,10-31-05 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\卡饭病毒样本包 20180910\kafan_sample_d9ec3fece87a0926fc7569e7654a15eab11215ef96137d365c1a12c4b252e6b8.exe'
- 09/10/2018,10-31-05 [INFO] The file 'e:\samples\卡饭病毒样本包 20180910\kafan_sample_d9ec3fece87a0926fc7569e7654a15eab11215ef96137d365c1a12c4b252e6b8.exe' was scanned with the Protection Cloud. SHA256 = D9EC3FECE87A0926FC7569E7654A15EAB11215EF96137D365C1A12C4B252E6B8
- 09/10/2018,10-31-05 [INFO] e:\samples\卡饭病毒样本包 20180910\kafan_sample_d9ec3fece87a0926fc7569e7654a15eab11215ef96137d365c1a12c4b252e6b8.exe
- 09/10/2018,10-31-05 [INFO] [DETECTION] file contains 'DR/Delphi.d9ec3f'
- 09/10/2018,10-31-06 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\卡饭病毒样本包 20180910\kafan_sample_debf8693ca46cebad5a54f6824fb52d36ee24c90ccf53bf0abdea51a6e45b68d.exe'
- 09/10/2018,10-31-06 [INFO] The file 'e:\samples\卡饭病毒样本包 20180910\kafan_sample_debf8693ca46cebad5a54f6824fb52d36ee24c90ccf53bf0abdea51a6e45b68d.exe' was scanned with the Protection Cloud. SHA256 = DEBF8693CA46CEBAD5A54F6824FB52D36EE24C90CCF53BF0ABDEA51A6E45B68D
- 09/10/2018,10-31-06 [INFO] e:\samples\卡饭病毒样本包 20180910\kafan_sample_debf8693ca46cebad5a54f6824fb52d36ee24c90ccf53bf0abdea51a6e45b68d.exe
- 09/10/2018,10-31-06 [INFO] [DETECTION] file contains 'HEUR/APC'
- 09/10/2018,10-31-07 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\卡饭病毒样本包 20180910\kafan_sample_df7b41cd9a4e0e4c729be3bdbac21f7841031e026d1e3c8528495c402c2294bb.exe'
- 09/10/2018,10-31-07 [INFO] e:\samples\卡饭病毒样本包 20180910\kafan_sample_df7b41cd9a4e0e4c729be3bdbac21f7841031e026d1e3c8528495c402c2294bb.exe
- 09/10/2018,10-31-07 [INFO] [DETECTION] file contains 'HEUR/AGEN.1001615'
- 09/10/2018,10-31-07 [INFO] FP reports status 'NO False Positive' for file 'e:\samples\卡饭病毒样本包 20180910\kafan_sample_e7f1eb00d16c1c4f2c64eb4c786b217d2c3b56b6f59ae89b18c76d22606c48e1.exe'
- 09/10/2018,10-31-07 [INFO] e:\samples\卡饭病毒样本包 20180910\kafan_sample_e7f1eb00d16c1c4f2c64eb4c786b217d2c3b56b6f59ae89b18c76d22606c48e1.exe
- 09/10/2018,10-31-07 [INFO] [DETECTION] file contains 'HEUR/AGEN.1034997'
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/RedCap.vjxfd Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe
- [INFO] The file will be copied to quarantine!
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe'
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/RedCap.vjxfd Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
- [INFO] The file will be copied to quarantine!
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe'
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/RedCap.vjxfd Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe
- 2018/9/10,10:30:07 [DETECTION] Is the TR/RedCap.vjxfd Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
- 2018/9/10,10:30:07 [DETECTION] Is the TR/RedCap.vjxfd Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe'
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/RedCap.vjxfd Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe
- 2018/9/10,10:30:07 [DETECTION] Is the TR/RedCap.vjxfd Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe'
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/RedCap.vjxfd Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/RedCap.vjxfd Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/RedCap.vjxfd Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe'
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/RedCap.vjxfd Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_bdc6d148006292c393a48f790e67544f9619e05daf487433cf7ed8408f089e4c.exe
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
- [INFO] The file will be copied to quarantine!
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_22db03c1eb144fc103f383f446a30ebe04509b41c41766219f2991ed85d7c6fb.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/Drop.DanaBot.nlpjj Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_22db03c1eb144fc103f383f446a30ebe04509b41c41766219f2991ed85d7c6fb.exe
- [INFO] The file will be copied to quarantine!
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_22db03c1eb144fc103f383f446a30ebe04509b41c41766219f2991ed85d7c6fb.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/Drop.DanaBot.nlpjj Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_22db03c1eb144fc103f383f446a30ebe04509b41c41766219f2991ed85d7c6fb.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_22db03c1eb144fc103f383f446a30ebe04509b41c41766219f2991ed85d7c6fb.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/Drop.DanaBot.nlpjj Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_22db03c1eb144fc103f383f446a30ebe04509b41c41766219f2991ed85d7c6fb.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_22db03c1eb144fc103f383f446a30ebe04509b41c41766219f2991ed85d7c6fb.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
- 2018/9/10,10:30:07 [DETECTION] Is the TR/Drop.DanaBot.nlpjj Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_22db03c1eb144fc103f383f446a30ebe04509b41c41766219f2991ed85d7c6fb.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_22db03c1eb144fc103f383f446a30ebe04509b41c41766219f2991ed85d7c6fb.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/Drop.DanaBot.nlpjj Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_22db03c1eb144fc103f383f446a30ebe04509b41c41766219f2991ed85d7c6fb.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_22db03c1eb144fc103f383f446a30ebe04509b41c41766219f2991ed85d7c6fb.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/Drop.DanaBot.nlpjj Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_22db03c1eb144fc103f383f446a30ebe04509b41c41766219f2991ed85d7c6fb.exe
- 2018/9/10,10:30:07 [INFO] FP reports status 'NO False Positive' for file 'E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe'
- 2018/9/10,10:30:07 [DETECTION] Is the TR/AD.MalwareCrypter.rawsq Trojan!
- E:\Samples\卡饭病毒样本包 20180910\Kafan_Sample_6f492d9bf91e289eb9e9953c36df63b9943a5fdf8e52a67a620746125ecb5606.exe
复制代码
|