本帖最后由 墨家小子 于 2015-12-14 18:30 编辑
SHA256: 1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c
File name: 1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe
Detection ratio: 5 / 53
Analysis date: 2015-12-14 10:20:55 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1450088455/
2015/12/14 18:22:10,C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe,53,Allowed ;执行应用程序 ("C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" -C:\Users\AAA\AppData\Roaming\ZyRLXDe\OEXvPQ.exe)
2015/12/14 18:22:14,C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe,53,Allowed ;执行应用程序 ("C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe")
2015/12/14 18:22:16,C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows,Load)
2015/12/14 18:22:20,C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe,53,Allowed ;执行应用程序 ("C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe")
2015/12/14 18:22:22,C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe,53,Allowed ;执行应用程序 ("C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe")
2015/12/14 18:22:26,C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe,47,Allowed ;创建交换数据流 (C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe:Zone.Identifier)
2015/12/14 18:22:28,C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe,20,Blocked ;记录键盘输入
2015/12/14 18:22:30,C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe,24,Blocked ;监视剪贴版变更
2015/12/14 18:22:31,C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/14 18:22:33,C:\Users\AAA\Desktop\W\1f7bc9f1c7299c1d42e0eda2ce530f2c34bb190e5202c8924274444ef0cf6d8c.exe,48,Allowed ;出站网络访问
|