本帖最后由 墨家小子 于 2016-1-12 09:51 编辑
SHA256: 148458f5b9b2eb4f514faf03abce621f804ab60e2fe642870823a32456ed5482
File name: 148458f5b9b2eb4f514faf03abce621f804ab60e2fe642870823a32456ed5482.scr
Detection ratio: 27 / 54
Analysis date: 2016-01-12 01:35:09 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1452562509/
http://1000eb.com/1iivm
认怂就开着监控玩~~好吧?走到底才拦截加密的才是好东西,是不?看看人家HMPA指名道姓的说不服,Mitigation CryptoGuard
[mw_shl_code=css,true]Mitigation CryptoGuard
Platform 6.3.9600/x64 06_3d
PID 8132
Application C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe
Filename C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe
C:\UserGuidePDF\pdf\ar-SA.pdf
C:\UserGuidePDF\pdf\ar-SA-LLW.pdf
C:\UserGuidePDF\pdf\ar-SA-GEL.pdf
[/mw_shl_code]
[mw_shl_code=css,true]2016/1/12 9:39:16,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\1\148458f5b9b2eb4f514faf03abce621f804ab60e2fe642870823a32456ed5482.scr" /S)
2016/1/12 9:39:25,C:\Users\AA\Desktop\1\148458f5b9b2eb4f514faf03abce621f804ab60e2fe642870823a32456ed5482.scr,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Local\Temp\RarSFX0\chrome.exe" i)
2016/1/12 9:39:32,C:\Users\AA\AppData\Local\Temp\RarSFX0\chrome.exe,54,Allowed ;接受入站网络数据包
2016/1/12 9:39:33,C:\Users\AA\AppData\Local\Temp\RarSFX0\chrome.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Local\Temp\RarSFX0\chrome.exe" --type=gpu-process --channel="1516.0.404252580\1366995049" --no-sandbox --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x8086 --gpu-device-id=0x161e --gpu-driver-vendor="Intel)
2016/1/12 9:39:35,C:\Users\AA\AppData\Local\Temp\RarSFX0\chrome.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Local\Temp\RarSFX0\chrome.exe" --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=zh-CN --extension-process --nodejs --working-directory="C:\Users\AA\AppData\Local\Temp\nw1516_779" --enable-pinch --device-scale-factor=2.5 )
2016/1/12 9:39:36,C:\Users\AA\AppData\Local\Temp\RarSFX0\chrome.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Local\Temp\RarSFX0\chrome.exe" --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=zh-CN --extension-process --nodejs --working-directory="C:\Users\AA\AppData\Local\Temp\nw1516_779" --enable-pinch --device-scale-factor=2.5 )
2016/1/12 9:39:39,C:\Users\AA\AppData\Local\Temp\RarSFX0\chrome.exe,53,Allowed ;执行应用程序 (s.exe "/F:C:\Users\AA\Start Menu\Startup\ChromeService.lnk" /A:C "/T:C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe" "/W:C:\Users\AA\AppData\Roaming\Chrome Browser" /P:l "/D:Chrome Apps Service")
2016/1/12 9:39:40,C:\Users\AA\AppData\Local\Temp\RarSFX0\chrome.exe,53,Allowed ;执行应用程序 (s.exe "/F:C:\Users\AA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ChromeService.lnk" /A:C "/T:C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe" "/W:C:\Users\AA\AppData\Roaming\Chrome Browser" /P:l "/D:Chrome Apps Service")
2016/1/12 9:39:44,C:\Users\AA\AppData\Local\Temp\RarSFX0\s.exe,41,Blocked ;修改受保护的文件 (C:\Users\AA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ChromeService.lnk)
2016/1/12 9:39:47,C:\Users\AA\AppData\Local\Temp\RarSFX0\chrome.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe" l)
2016/1/12 9:39:52,C:\Windows\System32\svchost.exe,53,Allowed ;执行应用程序 (C:\windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5})
2016/1/12 9:39:52,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\windows\system32\CompMgmtLauncher.exe" )
2016/1/12 9:40:04,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,54,Allowed ;接受入站网络数据包
2016/1/12 9:40:06,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe" --type=gpu-process --channel="4196.0.422957202\1562824583" --no-sandbox --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x8086 --gpu-device-id=0x161e --gpu-driver-vendor="I)
2016/1/12 9:40:07,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe" --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=zh-CN --extension-process --nodejs --working-directory="C:\Users\AA\AppData\Local\Temp\nw4196_12010" --enable-pinch --device-scale-facto)
2016/1/12 9:40:09,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe" --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=zh-CN --extension-process --nodejs --working-directory="C:\Users\AA\AppData\Local\Temp\nw4196_12010" --enable-pinch --device-scale-facto)
2016/1/12 9:40:10,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe" q 8132)
2016/1/12 9:40:11,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Chrome Browser\rundll32.exe" -f chrome)
2016/1/12 9:40:11,C:\Users\AA\AppData\Roaming\Chrome Browser\rundll32.exe,53,Allowed ;执行应用程序 (\??\C:\windows\system32\conhost.exe 0xffffffff)
2016/1/12 9:40:11,C:\Windows\System32\conhost.exe,40,Allowed ;以修改权限打开进程或线程 (rundll32.exe(pid=6272))
2016/1/12 9:40:12,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,54,Allowed ;接受入站网络数据包
2016/1/12 9:40:14,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe" --type=gpu-process --channel="7984.0.45293334\1142421651" --no-sandbox --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x8086 --gpu-device-id=0x161e --gpu-driver-vendor="In)
2016/1/12 9:40:17,C:\Users\AA\AppData\Roaming\Chrome Browser\rundll32.exe,54,Allowed ;接受入站网络数据包
2016/1/12 9:40:19,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe" --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=zh-CN --extension-process --nodejs --working-directory="C:\Users\AA\AppData\Local\Temp\nw7984_4847" --enable-pinch --device-scale-factor)
2016/1/12 9:40:21,C:\Users\AA\AppData\Roaming\Chrome Browser\rundll32.exe,48,Allowed ;出站网络访问
2016/1/12 9:40:22,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe" --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=zh-CN --extension-process --nodejs --working-directory="C:\Users\AA\AppData\Local\Temp\nw7984_4847" --enable-pinch --device-scale-factor)
2016/1/12 9:40:34,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,48,Allowed ;出站网络访问
2016/1/12 9:40:43,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,53,Allowed ;执行应用程序 (cmd)
2016/1/12 9:41:03,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,48,Allowed ;出站网络访问
2016/1/12 9:41:06,C:\Users\AA\AppData\Roaming\Chrome Browser\chrome.exe,48,Allowed ;出站网络访问
[/mw_shl_code] |