Skip to content

Instantly share code, notes, and snippets.

@tomoconnor
Created March 11, 2017 22:19
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save tomoconnor/f76ba94ece7c3d761cc88df4bcc68deb to your computer and use it in GitHub Desktop.
Save tomoconnor/f76ba94ece7c3d761cc88df4bcc68deb to your computer and use it in GitHub Desktop.
C:\Documents and Settings/All Users/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(100)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Documents and Settings/All Users/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Documents and Settings/All Users/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Documents and Settings/All Users/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Documents and Settings/All Users/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Documents and Settings/All Users/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Documents and Settings/All Users/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Documents and Settings/All Users/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Documents and Settings/All Users/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
C:\Documents and Settings/All Users/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi!MSCAB:C2RCDLL!...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Documents and Settings/Gill/Desktop/798_abroad.exe: Win.Trojan.Clicker-3867 FOUND
C:\Program Files/McAfee.com/Agent/mcagen+.exe: Win.Trojan.Clicker-3867 FOUND
C:\Program Files/McAfee.com/Agent/mcagen+.exe!(9): Win.Trojan.Clicker-3867 FOUND
C:\Documents and Settings/Gill/Desktop/798_abroad.exe!(2): Win.Trojan.Clicker-3867 FOUND
C:\Program Files (x86)/Adobe/Reader 9.0/Reader/AcroRd32Info.exe: Win.Trojan.Agent-1373809 FOUND
C:\Program Files (x86)/Adobe/Reader 9.0/Reader/AcroRd32Info.exe!(0): Win.Trojan.Agent-1373809 FOUND
C:\Program Files (x86)/Adobe/Reader 9.0/Reader/AcroTextExtractor.exe: Win.Trojan.Vilsel-1675 FOUND
C:\Program Files (x86)/Adobe/Reader 9.0/Reader/AcroTextExtractor.exe!(0): Win.Trojan.Vilsel-1675 FOUND
C:\Program Files (x86)/Common Files/microsoft shared/Virtualization Handler/VirtualSearchHost.exe: Win.Worm.Chir-2576 FOUND
C:\Program Files (x86)/Common Files/microsoft shared/Virtualization Handler/VirtualSearchHost.exe!(0): Win.Worm.Chir-2576 FOUND
C:\ProgramData/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(143)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\ProgramData/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\ProgramData/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\ProgramData/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\ProgramData/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\ProgramData/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\ProgramData/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\ProgramData/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
C:\ProgramData/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi!...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\ProgramData/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
C:\ProgramData/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi!MSCAB:C2RCDLL!...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\ProgramData/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
C:\ProgramData/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi!MSCAB:C2RCDLL!MSCAB:C2RICONS.EXE!...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\SwSetup/CyberDVD/Stage1/P2Go/Power2Go.msi: Win.Worm.Palevo-39167 FOUND
C:\SwSetup/CyberDVD/Stage1/P2Go/Power2Go.msi!(34): Win.Worm.Palevo-39167 FOUND
C:\Users/All Users/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Users/All Users/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Users/All Users/Application Data/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Users/All Users/Application Data/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Users/All Users/Application Data/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Users/All Users/Application Data/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Users/All Users/Application Data/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Users/All Users/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
C:\Users/All Users/Application Data/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi!MSCAB:C2RCDLL!...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Users/All Users/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi: Win.Worm.Chir-2576 FOUND
C:\Users/All Users/Microsoft/OEMOffice14/OStarter/en-us/click2run.msi!MSCAB:C2RCDLL!...!(277)MSCAB:VIRTUALSEARCHPROTOCOLHOSTPS.DLL: Win.Worm.Chir-2576 FOUND
C:\Users/Gill/Desktop/798_abroad.exe: Win.Trojan.Clicker-3867 FOUND
C:\Users/Gill/Desktop/798_abroad.exe!(8): Win.Trojan.Clicker-3867 FOUND
C:\Windows/Installer/4de8ca.msi: Win.Worm.Palevo-39167 FOUND
C:\Windows/Installer/4de8ca.msi!(77): Win.Worm.Palevo-39167 FOUND
C:\Windows/SoftwareDistribution/Download/a743cb1c702e8c4fdc85fa5f04552d80/amd64_microsoft-windows-blb-events-main_31bf3856ad364e35_6.1.7601.17514_none_590326050266f2c7: Win.Trojan.Clicker-3867 FOUND
C:\Windows/SoftwareDistribution/Download/a743cb1c702e8c4fdc85fa5f04552d80/amd64_microsoft-windows-blb-events-main_31bf3856ad364e35_6.1.7601.17514_none_590326050266f2c7!(8): Win.Trojan.Clicker-3867 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 5991137
Engine version: 0.99.2
Scanned directories: 120878
Scanned files: 437046
Infected files: 36
Data scanned: 27052.88 MB
Data read: 170722.90 MB (ratio 0.16:1)
Time: 4844.570 sec (80 m 44 s)
@tomoconnor
Copy link
Author

$ cut -d':' -f 2 < gilly.log | grep FOUND | sort | uniq -c
   2  Win.Trojan.Agent-1373809 FOUND
   8  Win.Trojan.Clicker-3867 FOUND
   2  Win.Trojan.Vilsel-1675 FOUND
  30  Win.Worm.Chir-2576 FOUND
   4  Win.Worm.Palevo-39167 FOUND

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment