https://www.virustotal.com/en/fi ... nalysis/1449106353/
SHA256: 6fb74bfd8bea6e98acc01f70997505a074660873cfd228d909cc8818b6cf952d
File name: 31ad1da7cdcccaa7103ded6cb5426984.exe
Detection ratio: 2 / 54
Analysis date: 2015-12-03 01:32:33 UTC ( 0 minutes ago )
2015/12/3 9:36:50,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAAA\Desktop\3333\31ad1da7cdcccaa7103ded6cb5426984.exe" )
2015/12/3 9:37:02,C:\Users\AAAAA\Desktop\3333\31ad1da7cdcccaa7103ded6cb5426984.exe,48,Allowed ;出站网络访问
2015/12/3 9:37:34,C:\Users\AAAAA\Desktop\3333\31ad1da7cdcccaa7103ded6cb5426984.exe,53,Allowed ;执行应用程序 (cmd.exe /K "C:\PROGRA~3\TSTheme_86.dll")
2015/12/3 9:37:37,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 (C:\PROGRA~3\TSTheme_86.dll)
2015/12/3 9:37:49,C:\PROGRA~3\TSTheme_86.dll,48,Allowed ;出站网络访问
2015/12/3 9:38:24,C:\PROGRA~3\TSTheme_86.dll,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,SearchUI_86)
2015/12/3 9:38:53,C:\PROGRA~3\TSTheme_86.dll,53,Allowed ;执行应用程序 ("C:\Windows\System32\cmd.exe" /K "C:\Users\AAAAA\AppData\LocalLow\appserverai_86.exe")
2015/12/3 9:38:56,C:\Windows\System32\cmd.exe,53,Allowed ;执行应用程序 (C:\Users\AAAAA\AppData\LocalLow\appserverai_86.exe)
2015/12/3 9:39:08,C:\Users\AAAAA\AppData\LocalLow\appserverai_86.exe,48,Allowed ;出站网络访问
2015/12/3 9:39:48,C:\Users\AAAAA\AppData\LocalLow\appserverai_86.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Run,MSchedExe_86)
2015/12/3 9:39:51,C:\Users\AAAAA\AppData\LocalLow\appserverai_86.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,MSchedExe_86)
2015/12/3 9:40:08,C:\Users\AAAAA\AppData\LocalLow\appserverai_86.exe,53,Allowed ;执行应用程序 ("C:\Windows\System32\cmd.exe" /K "C:\Users\AAAAA\AppData\LocalLow\openssl_86.exe")
2015/12/3 9:40:10,C:\Windows\System32\cmd.exe,53,Allowed ;执行应用程序 (C:\Users\AAAAA\AppData\LocalLow\openssl_86.exe)
2015/12/3 9:40:22,C:\Users\AAAAA\AppData\LocalLow\openssl_86.exe,48,Allowed ;出站网络访问
2015/12/3 9:40:57,C:\Users\AAAAA\AppData\LocalLow\openssl_86.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Run,ovftool_86)
2015/12/3 9:41:00,C:\Users\AAAAA\AppData\LocalLow\openssl_86.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,ovftool_86)
2015/12/3 9:41:18,C:\Users\AAAAA\AppData\LocalLow\openssl_86.exe,53,Allowed ;执行应用程序 ("C:\Windows\System32\cmd.exe" /K "C:\Users\AAAAA\AppData\LocalLow\aspnet_wp_86.exe")
2015/12/3 9:41:20,C:\Windows\System32\cmd.exe,53,Allowed ;执行应用程序 (C:\Users\AAAAA\AppData\LocalLow\aspnet_wp_86.exe)
2015/12/3 9:41:31,C:\Users\AAAAA\AppData\LocalLow\aspnet_wp_86.exe,48,Allowed ;出站网络访问
|