本帖最后由 YU2711 于 2019-1-28 17:18 编辑
Avira 5x
- 01/28/2019,16-12-44 [INFO] FP reports status 'NO False Positive' for file 'c:\idm\idm\downloads\compressed\exe样本_11\Samp(1).vir'
- 01/28/2019,16-12-44 [INFO] c:\idm\idm\downloads\compressed\exe样本_11\Samp(1).vir
- 01/28/2019,16-12-44 [INFO] [DETECTION] file contains 'TR/Dropper.Gen7'
- 01/28/2019,16-12-44 [INFO] FP reports status 'NO False Positive' for file 'c:\idm\idm\downloads\compressed\exe样本_11\Samp(2).vir'
- 01/28/2019,16-12-44 [INFO] c:\idm\idm\downloads\compressed\exe样本_11\Samp(2).vir
- 01/28/2019,16-12-44 [INFO] [DETECTION] file contains 'TR/Ransom.wevaf'
- 01/28/2019,16-12-45 [INFO] FP reports status 'NO False Positive' for file 'c:\idm\idm\downloads\compressed\exe样本_11\Samp(3).vir'
- 01/28/2019,16-12-45 [INFO] c:\idm\idm\downloads\compressed\exe样本_11\Samp(3).vir
- 01/28/2019,16-12-45 [INFO] [DETECTION] file contains 'TR/Crypt.ASPM.Gen'
- 01/28/2019,16-12-48 [INFO] FP reports status 'NO False Positive' for file 'c:\idm\idm\downloads\compressed\exe样本_11\Samp(4).vir'
- 01/28/2019,16-12-48 [INFO] The file 'c:\idm\idm\downloads\compressed\exe样本_11\Samp(4).vir' was scanned with the Protection Cloud. SHA256 = F845BEEE412C55DC458893DDDF453E7A60E6E0A0CE184A9D93DA197ECC204222
- 01/28/2019,16-12-48 [INFO] c:\idm\idm\downloads\compressed\exe样本_11\Samp(4).vir
- 01/28/2019,16-12-48 [INFO] [DETECTION] file contains 'TR/Emotet.f845be'
- 01/28/2019,16-12-49 [INFO] FP reports status 'NO False Positive' for file 'c:\idm\idm\downloads\compressed\exe样本_11\Samp(5).vir'
- 01/28/2019,16-12-49 [INFO] c:\idm\idm\downloads\compressed\exe样本_11\Samp(5).vir
- 01/28/2019,16-12-49 [INFO] [DETECTION] file contains 'TR/Ransom.gzscs'
复制代码 Trend Micro Scan 2x- 2019/1/28 16:41,Ransom.MSIL.BLACKWORM.SMTHAA,安全威脅,C:\Users\TEST-3\Downloads\EXE样本_11\Samp(1).vir,已移除,手動掃瞄
- 2019/1/28 16:41,Ransom_RAMSIL.SM,安全威脅,C:\Users\TEST-3\Downloads\EXE样本_11\Samp(2).vir,已移除,手動掃瞄
复制代码 Run Miss Samp(3) Samp(5)勒索克星阻止(预设路径图片及文档) 桌面图片损毁
17:06
在试了下Samp(5)阻止并回滚文件(刚刚可能网不好)
|