SHA256 cb65bdba8b18cef2d4afe4835ba509f572b7ee2652da2af804038efa97c64f82
File name: uwctyrru.exe
Detection ratio: 4 / 55
Analysis date: 2015-11-27 23:57:58 UTC ( 1 hour, 25 minutes ago )
2015/11/28 9:24:12,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\OOOOO\Desktop
\1111\cb65bdba8b18cef2d4afe4835ba509f572b7ee2652da2af804038efa97c64f82.exe" )
2015/11/28 9:24:14,C:\Users\OOOOO\Desktop
\1111\cb65bdba8b18cef2d4afe4835ba509f572b7ee2652da2af804038efa97c64f82.exe,47,Allowed ;创建
交换数据流 (C:\Users\OOOOO\AppData\Local\Temp\hsckcecr.exe:Zone.Identifier)
2015/11/28 9:24:16,C:\Users\OOOOO\Desktop
\1111\cb65bdba8b18cef2d4afe4835ba509f572b7ee2652da2af804038efa97c64f82.exe,53,Allowed ;执行
应用程序 (C:\Users\OOOOO\AppData\Local\Temp\hsckcecr.exe)
2015/11/28 9:24:21,C:\Users\OOOOO\AppData\Local\Temp\hsckcecr.exe,53,Allowed ;执行应用程序
(C:\windows\system32\svchost.exe)
2015/11/28 9:24:23,C:\Users\OOOOO\AppData\Local\Temp\hsckcecr.exe,40,Blocked ;以修改权限打开
进程或线程 (svchost.exe(pid=5264))
2015/11/28 9:24:25,C:\Users\OOOOO\AppData\Local\Temp\hsckcecr.exe,53,Allowed ;执行应用程序
(C:\windows\system32\svchost.exe)
============================================
2015/11/28 9:24:31,C:\Windows\SysWOW64\svchost.exe,41,Blocked ;修改受保护的文件 (C:\Users
\OOOOO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xwkfrrvo.exe)
介个是怎么回事儿???SSF你说,你说,你说
============================================
2015/11/28 9:24:37,C:\Users\OOOOO\AppData\Local\Temp\hsckcecr.exe,53,Blocked ;执行应用程序
("C:\windows\system32\sdbinst.exe" /q "C:\Users\OOOOO\AppData\Local\Temp\\..\..\LocalLow
\com.f.sdb")
2015/11/28 9:24:42,C:\Windows\SysWOW64\svchost.exe,26,Blocked ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows\CurrentVersion\Run,XwkFrrvo)
2015/11/28 9:24:45,C:\Windows\SysWOW64\svchost.exe,50,Blocked ;使用 DNS 解析服务访问网络
2015/11/28 9:24:47,C:\Windows\SysWOW64\svchost.exe,26,Blocked ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows\CurrentVersion\Run,XwkFrrvo)
2015/11/28 9:24:51,C:\Users\OOOOO\AppData\Local\Temp\hsckcecr.exe,53,Blocked ;执行应用程序
("C:\windows\system32\sdbinst.exe" /q /u "C:\Users\OOOOO\AppData\Local\Temp\\..\..\LocalLow
\com.f.sdb")
2015/11/28 9:24:54,C:\Windows\SysWOW64\svchost.exe,48,Blocked ;出站网络访问
2015/11/28 9:24:56,C:\Windows\SysWOW64\svchost.exe,26,Blocked ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows\CurrentVersion\Run,XwkFrrvo)
2015/11/28 9:25:01,C:\Windows\SysWOW64\svchost.exe,26,Blocked ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows\CurrentVersion\Run,XwkFrrvo)
2015/11/28 9:25:05,C:\Users\OOOOO\AppData\Local\Temp\hsckcecr.exe,53,Allowed ;执行应用程序
("C:\windows\SysWOW64\cmd.exe" /C ""C:\Users\OOOOO\AppData\Local\Temp\oyjawytm.exe"")
2015/11/28 9:25:08,C:\Windows\SysWOW64\svchost.exe,26,Blocked ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows\CurrentVersion\Run,XwkFrrvo)
2015/11/28 9:26:05,C:\Windows\SysWOW64\cmd.exe,53,Blocked ;执行应用程序 ("C:\Users\OOOOO
\AppData\Local\Temp\oyjawytm.exe")
2015/11/28 9:26:08,C:\Windows\SysWOW64\svchost.exe,26,Blocked ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows\CurrentVersion\Run,XwkFrrvo)
2015/11/28 9:26:31,C:\Windows\SysWOW64\svchost.exe,26,Terminated ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows\CurrentVersion\Run,XwkFrrvo)
|