SHA256: 19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10
File name: 19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe
Detection ratio: 3 / 55
Analysis date: 2015-11-28 11:55:05 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1448711705/
2015/11/28 19:55:14,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe" )
2015/11/28 19:55:14,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe" )
2015/11/28 19:55:41,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe")
2015/11/28 19:55:45,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,53,Allowed ;执行应用程序 ("C:\Windows\Microsoft.NET\Framework\v2.0.50727\regasm.exe")
2015/11/28 19:55:47,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,11,Blocked ;记录键盘输入
2015/11/28 19:55:48,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,40,Blocked ;以修改权限打开进程或线程 (TabTip32.exe(pid=4528))
2015/11/28 19:55:51,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,53,Allowed ;执行应用程序 ("C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe")
2015/11/28 19:55:52,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,11,Blocked ;记录键盘输入
2015/11/28 19:55:54,C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe,11,Blocked ;记录键盘输入
2015/11/28 19:55:56,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Adobe)
2015/11/28 19:55:58,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,57,Blocked ;正在以只读方式打开受保护的进程 (explorer.exe(pid=4012))
2015/11/28 19:56:01,C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe,11,Blocked ;记录键盘输入
2015/11/28 19:56:03,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/11/28 19:56:05,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Adobe)
2015/11/28 19:56:07,C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe,50,Blocked ;使用 DNS 解析服务访问网络
2015/11/28 19:56:10,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,48,Blocked ;出站网络访问
2015/11/28 19:56:11,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Adobe)
2015/11/28 19:56:14,C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe,48,Blocked ;出站网络访问
2015/11/28 19:56:16,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Adobe)
2015/11/28 19:56:21,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Adobe)
2015/11/28 19:56:26,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Adobe)
2015/11/28 19:56:32,C:\Users\AAAAA\Desktop\11\19ab20723fb0a59d255a94816db46b9fc9d294468e7344fa41986c2a800d5d10.exe,26,Terminated ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Adobe)
|