Scan Stats:
Scan Time: 110 seconds
Scan Options:
Scan Targets: D:\Virus\Dudu26
Counts:
Total items scanned: 8
- Files & Directories: 8
- Registry Entries: 0
- Processes & Start-up Items: 0
- Network & Browser Items: 0
- Other: 0
- Trusted Files: 0
- Skipped Files: 0
Total security risks detected: 5
Total items resolved: 5
Total items that require attention: 0
Resolved Threats:
VBS.Runauto
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\virus\dudu26\dudu\'.vbs - Deleted
VBS.Runauto.B
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
2 Files
d:\virus\dudu26\dudu\.vbs - Deleted
d:\virus\dudu26\dudu\2.vbs - Deleted
W32.SillyFDC
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Restart Required
-----------
54 Registry Entries
[Restricted item (permission required)] - N/A
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer->NoDriveTypeAutoRun:149 - Repaired
[Restricted item (permission required)] - N/A
[Restricted item (permission required)] - N/A
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce - Repaired
[Restricted item (permission required)] - N/A
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce - Repaired
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->HideFileExt:0 - Repaired
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Repaired
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Repaired
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule->ImagePath:%SystemRoot%\System32\svchost.exe -k netsvcs - Repaired
HKEY_CLASSES_ROOT\MSCFile\Shell\Open\Command - Repaired
HKEY_CLASSES_ROOT\regfile\shell\open\command - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system->DisableStatusMessages:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL->CheckedValue:1 - Repaired
[Restricted item (permission required)] - N/A
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Control Panel\Desktop->AutoEndTasks:... - Repaired
[Restricted item (permission required)] - N/A
HKEY_USERS\.DEFAULT\Control Panel\Desktop->AutoEndTasks:... - Repaired
[Restricted item (permission required)] - N/A
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Control Panel\Desktop->ScreenSaveTimeOut:600 - Repaired
[Restricted item (permission required)] - N/A
HKEY_USERS\.DEFAULT\Control Panel\Desktop->ScreenSaveTimeOut:600 - Repaired
HKEY_CLASSES_ROOT\comfile\shell\open\command - Repaired
HKEY_CLASSES_ROOT\txtfile\shell\open\command\ - Repaired
HKEY_CLASSES_ROOT\exefile - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt->UncheckedValue:0 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden->UncheckedValue:1 - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideFileExt->CheckedValue:0 - Repaired
HKEY_CLASSES_ROOT\batfile\shell\edit\command\ - Repaired
HKEY_CLASSES_ROOT\comfile\ - Repaired
HKEY_CLASSES_ROOT\inifile\shell\open\command\ - Repaired
HKEY_CLASSES_ROOT\piffile\shell\open\command\ - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\->Shell:Explorer.exe - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\->Userinit:C:\Windows\system32\userinit.exe, - Repaired
[Restricted item (permission required)] - N/A
HKEY_USERS\S-1-5-21-1350214121-284562733-1199252589-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableRegistryTools:0 - Repaired
[Restricted item (permission required)] - N/A
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\->AlternateShell:cmd.exe - Repaired
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\SystemRestore\->DisableConfig:0 - Repaired
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\SystemRestore\->DisableSR:0 - Repaired
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer\->LimitSystemRestoreCheckpointing:0 - Repaired
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer\->DisableMSI:0 - Repaired
HKEY_LOCAL_MACHINE\Software\Classes\exefile\ - Repaired
[Restricted item (permission required)] - N/A
[Restricted item (permission required)] - N/A
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->HideFileExt:0 - Repaired
[Restricted item (permission required)] - N/A
[Restricted item (permission required)] - N/A
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Repaired
[Restricted item (permission required)] - N/A
[Restricted item (permission required)] - N/A
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Repaired
10 Files
d:\virus\dudu26\dudu\delautorun.bat - Deleted
c:\users\无尽藏海\appdata\local\temp\~df1921.tmp - Deleted
c:\users\无尽藏海\appdata\local\temp\~df4e35.tmp - Deleted
c:\users\无尽藏海\appdata\local\temp\~df5df2.tmp - Deleted
c:\users\无尽藏海\appdata\local\temp\~df7dc8.tmp - Deleted
c:\users\无尽藏海\appdata\local\temp\~df84ea.tmp - Deleted
c:\users\无尽藏海\appdata\local\temp\~dfa4ad.tmp - Deleted
c:\users\无尽藏海\appdata\local\temp\~dfb71c.tmp - Restart Required
c:\windows\setup\state - Restart Required
C:\Windows\setup - Restart Required
W32.Rajump
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 Registry Entry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL->CheckedValue:1 - Repaired
1 File
d:\virus\dudu26\dudu\ravmon.exe - Deleted
Trojan Horse
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\virus\dudu26\dudu\recycled.exe - Deleted |