病毒名称 病毒类型 发作次数 客户端名称 客户端IP 病毒来源 查杀结果 查杀方式 文件名 路径/访问染毒文件的进程 发现时间 最后发作时间 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 文件监控 C:\PROGRAM FILES\KINGSOFT\KINGSOFT ANTIVIRUS\UPDATE\KAV\KAV\KSPECIALSCAN.DLL>>BINARYTYPE-151-804 C:\PROGRAM FILES\KINGSOFT\KINGSOFT ANTIVIRUS\KISLIVE.EXE 2013-3-11 00:37:10 2013-3-11 00:37:10 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 文件监控 C:\PROGRAM FILES\KINGSOFT\KINGSOFT ANTIVIRUS\UPDATE\REBOOT_UPDATE\KSPECIALSCAN.DLL>>BINARYTYPE-151-804 C:\PROGRAM FILES\KINGSOFT\KINGSOFT ANTIVIRUS\KISLIVE.EXE 2013-3-11 00:42:32 2013-3-11 00:42:32 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 文件监控 C:\PROGRAM FILES\KINGSOFT\KINGSOFT ANTIVIRUS\KSPECIALSCAN.DLL0>>BINARYTYPE-151-804 C:\PROGRAM FILES\KINGSOFT\KINGSOFT ANTIVIRUS\KISLIVE.EXE 2013-3-11 00:42:37 2013-3-11 00:42:37 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 文件监控 C:\SYSTEM VOLUME INFORMATION\_RESTORE{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP290\SNAPSHOT\MFEX-46.DAT>>BINARYTYPE-151-804 C:\WINDOWS\SYSTEM32\SVCHOST.EXE 2013-3-11 03:20:11 2013-3-11 03:20:11 RootKit.Win32.Agent.GEN Rootkit 1 SJTHZJB01 10.168.188.124 用户忽略 文件监控 C:\PROGRAM FILES\KINGSOFT\KINGSOFT ANTIVIRUS\KSPECIALSCAN.DLL>>BINARYTYPE-151-804 C:\PROGRAM FILES\KINGSOFT\KINGSOFT ANTIVIRUS\KSCAN.EXE 2013-3-11 15:33:13 2013-3-11 15:33:13 RootKit.Win32.Agent.GEN Rootkit 1 SJTHCYXCZC 8.168.188.155 用户忽略 文件监控 C:\PROGRAM FILES\KINGSOFT\KINGSOFT ANTIVIRUS\KSPECIALSCAN.DLL>>BINARYTYPE-151-804 C:\PROGRAM FILES\KINGSOFT\KINGSOFT ANTIVIRUS\UNI0NST.EXE 2013-3-11 16:29:54 2013-3-11 16:29:54 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 文件监控 C:\SYSTEM VOLUME INFORMATION\_RESTORE{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP291\SNAPSHOT\MFEX-46.DAT>>BINARYTYPE-151-804 C:\WINDOWS\SYSTEM32\SVCHOST.EXE 2013-3-12 03:49:13 2013-3-12 03:49:13 RootKit.Win32.Agent.GEN Rootkit 1 SJTHGCYANYU 8.168.188.61 用户忽略 文件监控 C:\PROGRAM FILES\KINGSOFT\KINGSOFT ANTIVIRUS\KSPECIALSCAN.DLL>>BINARYTYPE-151-804 C:\WINDOWS\SYSTEM32\RUNDLL32.EXE 2013-3-12 11:42:54 2013-3-12 11:42:54 RootKit.Win32.Agent.GEN Rootkit 1 SJTHSYCL 8.168.188.100 用户忽略 客户端远程查杀 kspecialscan.dll>>BINARYTYPE-151-804 C:\Program Files\kingsoft\kingsoft antivirus 2013-3-12 12:40:21 2013-3-12 12:40:21 RootKit.Win32.Agent.GEN Rootkit 1 SJTHCWKF02 8.168.188.39 用户忽略 客户端远程查杀 KSpecialScan.dll>>BINARYTYPE-151-804 C:\Program Files\Kingsoft\kingsoft antivirus 2013-3-12 12:42:44 2013-3-12 12:42:44 Macro.Xl4Poppy 感染型病毒 1 SJTHCWKF02 8.168.188.39 用户忽略 客户端远程查杀 Book1>>XL4Poppy C:\Program Files\Microsoft Office\OFFICE11\XLSTART 2013-3-12 12:43:03 2013-3-12 12:43:03 RootKit.Win32.Agent.GEN Rootkit 1 SJTHGCYANYU 8.168.188.61 用户忽略 客户端远程查杀 kspecialscan.dll>>BINARYTYPE-151-804 C:\Program Files\Kingsoft\kingsoft antivirus 2013-3-12 12:47:11 2013-3-12 12:47:11 RootKit.Win32.Agent.GEN Rootkit 1 SJTHSYZCT 8.168.188.77 用户忽略 客户端远程查杀 kspecialscan.dll>>BINARYTYPE-151-804 C:\Program Files\kingsoft\kingsoft antivirus 2013-3-12 12:51:18 2013-3-12 12:51:18 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 kspecialscan.dll>>BINARYTYPE-151-804 C:\Program Files\Kingsoft\kingsoft antivirus 2013-3-12 12:51:54 2013-3-12 12:51:54 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 kspecialscan.dll_del_5803>>BINARYTYPE-151-804 C:\Program Files\Kingsoft\kingsoft antivirus 2013-3-12 12:51:54 2013-3-12 12:51:54 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 A0030513.dll>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP246 2013-3-12 13:00:37 2013-3-12 13:00:37 RootKit.Win32.Agent.GEN Rootkit 1 SJTHSYZCT 8.168.188.77 用户忽略 客户端远程查杀 A0082217.dll>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP196 2013-3-12 13:00:43 2013-3-12 13:00:43 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 A0030675.dll>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP246 2013-3-12 13:00:44 2013-3-12 13:00:44 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-139.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP246\snapshot 2013-3-12 13:00:49 2013-3-12 13:00:49 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-227.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP246\snapshot 2013-3-12 13:00:54 2013-3-12 13:00:54 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-315.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP246\snapshot 2013-3-12 13:00:59 2013-3-12 13:00:59 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-404.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP246\snapshot 2013-3-12 13:01:03 2013-3-12 13:01:03 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-49.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP246\snapshot 2013-3-12 13:01:06 2013-3-12 13:01:06 RootKit.Win32.Agent.GEN Rootkit 1 SJTHCW005 8.168.188.31 用户忽略 客户端远程查杀 kspecialscan.dll>>BINARYTYPE-151-804 C:\Program Files\Kingsoft\kingsoft antivirus 2013-3-12 13:01:14 2013-3-12 13:01:14 RootKit.Win32.Agent.GEN Rootkit 1 SJTHCWTT 10.168.188.32 用户忽略 客户端远程查杀 A0044041.dll>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP182 2013-3-12 13:01:59 2013-3-12 13:01:59 RootKit.Win32.Agent.GEN Rootkit 1 SJTHCWTT 10.168.188.32 用户忽略 客户端远程查杀 A0044331.dll>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP187 2013-3-12 13:02:09 2013-3-12 13:02:09 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 A0032100.dll>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP264 2013-3-12 13:02:26 2013-3-12 13:02:26 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 A0032172.dll>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP264 2013-3-12 13:02:31 2013-3-12 13:02:31 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-10.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP264\snapshot 2013-3-12 13:02:32 2013-3-12 13:02:32 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 A0032244.dll>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP265 2013-3-12 13:02:35 2013-3-12 13:02:35 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-10.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP265\snapshot 2013-3-12 13:02:36 2013-3-12 13:02:36 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-36.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP265\snapshot 2013-3-12 13:02:38 2013-3-12 13:02:38 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-62.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP265\snapshot 2013-3-12 13:02:40 2013-3-12 13:02:40 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-88.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP265\snapshot 2013-3-12 13:02:41 2013-3-12 13:02:41 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-10.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP266\snapshot 2013-3-12 13:02:43 2013-3-12 13:02:43 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-114.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP266\snapshot 2013-3-12 13:02:44 2013-3-12 13:02:44 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-140.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP266\snapshot 2013-3-12 13:02:46 2013-3-12 13:02:46 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-36.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP266\snapshot 2013-3-12 13:02:48 2013-3-12 13:02:48 RootKit.Win32.Agent.GEN Rootkit 1 SJTHCWTT 10.168.188.32 用户忽略 客户端远程查杀 A0052279.dll>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP198 2013-3-12 13:02:48 2013-3-12 13:02:48 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-62.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP266\snapshot 2013-3-12 13:02:50 2013-3-12 13:02:50 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-88.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP266\snapshot 2013-3-12 13:02:52 2013-3-12 13:02:52 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-10.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP267\snapshot 2013-3-12 13:02:54 2013-3-12 13:02:54 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-114.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP267\snapshot 2013-3-12 13:02:55 2013-3-12 13:02:55 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-140.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP267\snapshot 2013-3-12 13:02:57 2013-3-12 13:02:57 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-166.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP267\snapshot 2013-3-12 13:02:58 2013-3-12 13:02:58 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-192.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP267\snapshot 2013-3-12 13:03:00 2013-3-12 13:03:00 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-218.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP267\snapshot 2013-3-12 13:03:02 2013-3-12 13:03:02 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-244.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP267\snapshot 2013-3-12 13:03:04 2013-3-12 13:03:04 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-36.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP267\snapshot 2013-3-12 13:03:05 2013-3-12 13:03:05 RootKit.Win32.Agent.GEN Rootkit 1 SJTHQT005 10.168.188.108 用户忽略 客户端远程查杀 MFEX-62.DAT>>BINARYTYPE-151-804 C:\System Volume Information\_restore{2F5417B6-CFF8-4E42-AA6B-F7CB910CC827}\RP267\snapshot