- Malwarebytes
- www.malwarebytes.com
- -Log Details-
- Scan Date: 5/16/19
- Scan Time: 3:16 PM
- Log File: 8cc0caa8-77aa-11e9-9631-985fd3d3c7d2.json
- -Software Information-
- Version: 3.7.1.2839
- Components Version: 1.0.586
- Update Package Version: 1.0.10620
- License: Premium
- -System Information-
- OS: Windows 10 (Build 17763.475)
- CPU: x64
- File System: NTFS
- User: DESKTOP-VPBE70N\zhong
- -Scan Summary-
- Scan Type: Custom Scan
- Scan Initiated By: Manual
- Result: Cancelled
- Objects Scanned: 2015
- Threats Detected: 52
- Threats Quarantined: 0
- Time Elapsed: 2 min, 27 sec
- -Scan Options-
- Memory: Disabled
- Startup: Disabled
- Filesystem: Enabled
- Archives: Enabled
- Rootkits: Disabled
- Heuristics: Enabled
- PUP: Detect
- PUM: Detect
- -Scan Details-
- Process: 0
- (No malicious items detected)
- Module: 0
- (No malicious items detected)
- Registry Key: 2
- Trojan.EquationDrug, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SPOOLSV.EXE, No Action By User, [7289], [390689],1.0.10620
- Trojan.EquationDrug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SPOOLSV.EXE, No Action By User, [7289], [390689],1.0.10620
- Registry Value: 0
- (No malicious items detected)
- Registry Data: 0
- (No malicious items detected)
- Data Stream: 0
- (No malicious items detected)
- Folder: 0
- (No malicious items detected)
- File: 50
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\ADFW.DLL, No Action By User, [7672], [457755],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\CRLI-0.DLL, No Action By User, [7672], [457762],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\CNLI-0.DLL, No Action By User, [7672], [457761],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\ADFW-2.DLL, No Action By User, [7672], [457752],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\ESCO-0.DLL, No Action By User, [7672], [457759],1.0.10620
- HackTool.Equation, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\COLI-0.DLL, No Action By User, [7631], [541134],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\DMGD-1.DLL, No Action By User, [7672], [457749],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\DMGD-4.DLL, No Action By User, [7672], [457756],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\ETCHCORE-0.X86.DLL, No Action By User, [7672], [470788],1.0.10620
- Exploit.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\ETEBCORE-2.X86.DLL, No Action By User, [8211], [447875],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\ETEB-2.DLL, No Action By User, [7672], [470791],1.0.10620
- Exploit.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\ETEBCORE-2.X64.DLL, No Action By User, [8211], [447876],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\ETCHCORE-0.X64.DLL, No Action By User, [7672], [470788],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\EXMA-1.DLL, No Action By User, [7672], [400065],1.0.10620
- Worm.EternalRocks, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\EXMA.DLL, No Action By User, [8527], [400051],1.0.10620
- HackTool.Agent, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\LIBCURL.DLL, No Action By User, [3948], [400077],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\ICONV.DLL, No Action By User, [7672], [457754],1.0.10620
- Backdoor.Vools, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\OUT.DLL, No Action By User, [8147], [656605],1.0.10620
- HackTool.Equation, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\PCRE-0.DLL, No Action By User, [7631], [541090],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\CNLI-1.DLL, No Action By User, [7672], [457757],1.0.10620
- HackTool.Equation, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\PCLA-0.DLL, No Action By User, [7631], [541093],1.0.10620
- Trojan.EquationDrug, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\ETCH-0.DLL, No Action By User, [7289], [390255],1.0.10620
- Exploit.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\SSLEAY32.DLL, No Action By User, [8211], [447877],1.0.10620
- HackTool.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\LIBICONV-2.DLL, No Action By User, [8693], [457747],1.0.10620
- HackTool.Equation, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\TRCH-0.DLL, No Action By User, [7631], [541095],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\LIBXML2.DLL, No Action By User, [7672], [400070],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\PCREPOSIX-0.DLL, No Action By User, [7672], [457751],1.0.10620
- HackTool.Equation, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\TUCL-1.DLL, No Action By User, [7631], [646048],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\POSH.DLL, No Action By User, [7672], [457758],1.0.10620
- HackTool.Equation, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\RIAR-2.DLL, No Action By User, [7631], [541094],1.0.10620
- HackTool.Equation, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\ZIBE.DLL, No Action By User, [7631], [541096],1.0.10620
- Trojan.EquationDrug, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\SPOOLSV.EXE, No Action By User, [7289], [390689],1.0.10620
- HackTool.Equation, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\TRCH.DLL, No Action By User, [7631], [541091],1.0.10620
- Exploit.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\LIBEAY32.DLL, No Action By User, [8211], [447878],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\PCRECPP-0.DLL, No Action By User, [7672], [457748],1.0.10620
- HackTool.Equation, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\TIBE.DLL, No Action By User, [7631], [541099],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\TIBE-2.DLL, No Action By User, [7672], [400078],1.0.10620
- HackTool.Equation, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\TRFO.DLL, No Action By User, [7631], [541098],1.0.10620
- Worm.EternalRocks, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\UCL.DLL, No Action By User, [8527], [400027],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\XDVL-0.DLL, No Action By User, [7672], [510832],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\_PYTRCH.PYD, No Action By User, [7672], [457750],1.0.10620
- Exploit.Agent.NS, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\SVCHOST.EXE, No Action By User, [7858], [390583],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\TRFO-2.DLL, No Action By User, [7672], [400079],1.0.10620
- Trojan.ShadowBrokers, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\RIAR.DLL, No Action By User, [7672], [457760],1.0.10620
- Worm.EternalRocks, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\TRCH-1.DLL, No Action By User, [8527], [400050],1.0.10620
- HackTool.Equation, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\TIBE-1.DLL, No Action By User, [7631], [541092],1.0.10620
- Worm.EternalRocks, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\TRFO-0.DLL, No Action By User, [8527], [400030],1.0.10620
- Trojan.Downloader, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\X86.DLL, No Action By User, [520], [622846],1.0.10620
- Worm.EternalRocks, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\TUCL.DLL, No Action By User, [8527], [400024],1.0.10620
- HackTool.Agent, C:\USERS\ZHONG\DOWNLOADS\COMPRESSED\卡饭\APPDIAGNOSTICS\APPDIAGNOSTICS\ZLIB1.DLL, No Action By User, [3948], [400073],1.0.10620
- Physical Sector: 0
- (No malicious items detected)
- WMI: 0
- (No malicious items detected)
- (end)
复制代码 |