123
返回列表 发新帖
楼主: 墨家小子
收起左侧

[可疑文件] File name: 855658.exe Detection ratio: 16 / 61

  [复制链接]
xxl11231220
发表于 2017-6-15 19:03:00 | 显示全部楼层
碧水金江 发表于 2017-6-15 18:57
从这附件下载的,报法和你的不一样

启发杀,是未入库,杀未知病毒。入库后是你这种报法
碧水金江
发表于 2017-6-15 19:50:40 | 显示全部楼层
xxl11231220 发表于 2017-6-15 19:03
启发杀,是未入库,杀未知病毒。入库后是你这种报法

哦哦,谢谢。请问一下,我这提示病毒后,操作栏为什么老是“未决分析”
lyfpp
发表于 2017-6-15 21:21:20 | 显示全部楼层
bdts2017默认防护 20170615最新病毒库 开启勒索防护 扫描杀

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
piouu
发表于 2017-6-15 22:04:45 | 显示全部楼层
360拦截成功
,就一个.
发表于 2017-7-7 02:48:42 | 显示全部楼层
GD还是凶

Suspicious access to your file system has been detected, which suggests an encryption Trojan.

The following processes were therefore interrupted by G DATA for security reasons:
        ----------------------------------------------------------------
        C:\Program Files (x86)\PalmInput\2.7.0.1686\PalmInputService.exe (PID 4620)
        C:\Users\Administrator\AppData\Local\360Chrome\Chrome\Application\360chrome.exe (PID 2240)
        C:\Program Files (x86)\PalmInput\Extensions\Guard\2.6.0.49\PalmInputGuard.exe (PID 7768)
        C:\windows\explorer.exe (PID 7988)
        C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe (PID 4164)
        C:\Program Files (x86)\360\360zip\360zip.exe (PID 3560)
        C:\Program Files (x86)\360\360zip\360zip.exe (PID 1476)
        C:\Program Files (x86)\Thunder Network\Thunder9\Program\SDK\DownloadSDKServer.exe (PID 4996)
        D:\360极速浏览器下载\o0ya9zk30\o0ya9zk30.exe (PID 1864)
        C:\windows\Explorer.EXE (PID 5692)
        C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe (PID 1900)
        C:\Program Files (x86)\PalmInput\Extensions\Guard\2.6.0.49\PalmInputGuard.exe (PID 2100)
        C:\Users\Administrator\AppData\Local\360Chrome\Chrome\Application\360chrome.exe (PID 2884)
        C:\Program Files (x86)\Thunder Network\Thunder9\Program\ThunderNewTask.exe (PID 3056)
        D:\360极速浏览器下载\855658\855658.exe (PID 2308)
        ----------------------------------------------------------------

If blocked, the following programs responsible will be moved to Quarantine:
        ----------------------------------------------------------------
        D:\360极速浏览器下载\o0ya9zk30\o0ya9zk30.exe
        C:\Users\Administrator\Desktop\o0ya9zk30.exe
        D:\360极速浏览器下载\855658\855658.exe
        ----------------------------------------------------------------

Detected suspicious activities:
        ----------------------------------------------------------------
        Renamed: F:\新建文件夹\费玉清、邓丽君 - 但愿人长久.mp3 -> F:\新建文件夹\bdjJBjF7Fm.b6db
        Renamed: F:\新建文件夹\东方神秘园 - 玛依拉.mp3 -> F:\新建文件夹\1isUhFNR9I.b6db
        Renamed: F:\新建文件夹\哈孜肯 - 掀起你的盖头来.mp3 -> F:\新建文件夹\WECmMaHWKO.b6db
        Renamed: F:\新建文件夹\卓尼、豆格嘉布 - 康定情歌.mp3 -> F:\新建文件夹\B0dCTSh74X.b6db
        Renamed: F:\新建文件夹\徐小凤、邓丽君 - 戏凤.mp3 -> F:\新建文件夹\ScA9V0Q2mK.b6db
        Renamed: F:\新建文件夹\春雷 - 太阳出来喜洋洋.mp3 -> F:\新建文件夹\ck1J5fotn9.b6db
        Renamed: F:\新建文件夹\汤灿 - 龙船调.mp3 -> F:\新建文件夹\xwnuM8RrkY.b6db
        Renamed: F:\新建文件夹\群星 - 杨柳青(扬州民歌).mp3 -> F:\新建文件夹\vPjvG60DHq.b6db
        Renamed: F:\新建文件夹\腾格尔 - 在银色的月光下.mp3 -> F:\新建文件夹\wps4CtZFKf.b6db
        Renamed: F:\新建文件夹\腾格尔 - 父亲和我.mp3 -> F:\新建文件夹\RvmBcNWdLJ.b6db
        Renamed: F:\新建文件夹\腾格尔 - 草原之夜.mp3 -> F:\新建文件夹\Tmg5YSnt-3.b6db
        Created: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\IE\E3JVD815\day_update[1].htm
        Created: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\IE\K2ZQJHON\day_update[1].htm
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000eeb
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000eec
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000eed
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000eee
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000eef
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000ef0
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000ef1
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\33DE.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF1e33cf.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000ef2
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000ef3
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000ef4
        Created: C:\Users\Administrator\AppData\Local\Temp\Age602F.tmp
        Created: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\IE\K2ZQJHON\IPTKIQAE.gif
        Created: C:\Users\Administrator\AppData\Local\Temp\Xunlei\CON6762.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\6F72.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\etilqs_h5atmqgu5zizh5q
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF1e6fa0.TMP
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\Community\welcome.xml
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\Offline\OfflineConfig_9.xml.tmp
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Data\kn_conf.xml.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\XLGameBox-FileCache\data\1499366307385.js.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\XLGameBox-FileCache\data\1499366307766.js.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\XLGameBox-FileCache\data\149936630743.js.tmp
        Created: D:\迅雷下载\forum.php.xltd.cfg
        Created: D:\迅雷下载\forum.php.xltd
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\TaskSpeedInfo\TaskInfo_8303308376.txt
        Created: C:\Users\Administrator\AppData\Local\Temp\Thunder Network\Thunder7.9\JumpIcon\e4af75a7a42b18732bce451d33a3b8848cfd7690.ico
        Created: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\W030PPZQDNBLOG1ZDBKO.temp
        Created: C:\Users\Administrator\AppData\Local\Temp\etilqs_XI9bjDuagkrbWB7
        Created: C:\Users\Administrator\AppData\Local\Temp\ico81A2.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\ico81A2.tmp.ico.tmp
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\AdWords\133285.png.tmp
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\AdWords\134339.png.tmp
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\AdWords\134890.png.tmp
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\AdWords\135143.png.tmp
        Created: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1B4BG7F5OHBUPPS4TLC1.temp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\9C5F.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF1e9c5d.TMP
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Data\AdPlatform\Icons\4176d26646acd82f7947a189dc624992.png.tmp
        Created: D:\360极速浏览器下载\CCA7.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\~DF6EAA2836282E55A2.TMP
        Created: C:\Users\Administrator\AppData\Local\Temp\~DFA8B81045E1F1E009.TMP
        Created: C:\Users\Administrator\AppData\Local\Temp\icoD67A.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\icoD67A.tmp.ico.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\E531.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF1ee5ca.TMP
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\XLBrowserApp\CacheData\Cookies-journal
        Created: C:\Users\Administrator\AppData\Local\Temp\etilqs_REAmd27NTJIxy4Q
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000ef5
        Created: C:\ProgramData\360zip\speedmem2.hg-journal
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\18D5.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF1f18c1.TMP
        Created: D:\360极速浏览器下载\o0ya9zk30\fab922a8-736e-4cb5-a666-4fd849a3049a.txt
        Created: D:\360极速浏览器下载\o0ya9zk30\o0ya9zk30.exe
        Created: C:\Users\Administrator\AppData\Roaming\360zip\con_2039015.ini
        Created: C:\Users\Administrator\AppData\Local\Temp\etilqs_5az3QMeawe8D4UR
        Created: C:\Users\Administrator\AppData\Local\Microsoft\Windows\ActionCenterCache\windows-systemtoast-securityandmaintenance_127_0.png
        Created: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\IE\G16TPU62\guard_day_update[1].htm
        Created: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\IE\R8TC6SKE\guard_day_update[1].htm
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85C9.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85CA.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85CB.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85CC.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85CD.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85CE.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85CF.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85DF.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85F0.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85F1.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85F2.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85F3.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85F4.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\85F5.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\94EA.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF1f9515.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000ef6
        Created: C:\Users\Administrator\AppData\Local\Temp\b1e69b21\4edc.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\b1e69b21\3b83.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\BC69.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF1fbcf0.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000ef7
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000ef8
        Created: E:\KuGou\_R_E_A_D___T_H_I_S___ZT0E_.hta
        Created: E:\KuGou\_R_E_A_D___T_H_I_S___SQ9BCOCN_.txt
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000ef9
        Created: E:\KuGou\Temp\_R_E_A_D___T_H_I_S___6ZV4NLCM_.hta
        Created: E:\KuGou\Temp\_R_E_A_D___T_H_I_S___6U6KNH_.txt
        Created: C:\Users\Administrator\AppData\Local\Temp\etilqs_p7JNAGFMbJUbzKt
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000efa
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\B6.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF2008be.TMP
        Created: C:\Users\Administrator\AppData\Local\Temp\cvp358B.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\65CA.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Local State~RF206ab4.TMP
        Renamed: E:\KuGou\周杰伦、蔡依林 - 给我一首歌的时间 - 2010超时代世界巡回演唱会.mp3 -> E:\KuGou\iPQdd1YxOW.b6db
        Renamed: E:\KuGou\周柏豪 - 传闻.mp3 -> E:\KuGou\xprreoCQgQ.b6db
        Renamed: E:\KuGou\周柏豪 - 你还怕大雨吗.mp3 -> E:\KuGou\AZS797dKQ5.b6db
        Renamed: E:\KuGou\安又琪 - 你好,周杰伦.mp3 -> E:\KuGou\0wEi70AQQZ.b6db
        Renamed: E:\KuGou\张智霖 - 天生爱情狂.mp3 -> E:\KuGou\qz6oXQByhH.b6db
        Renamed: E:\KuGou\张智霖 - 未婚妻.mp3 -> E:\KuGou\l4KT4LFynD.b6db
        Renamed: E:\KuGou\徐佳莹、林俊杰 - 不为谁而作的歌.mp3 -> E:\KuGou\efKmhON34V.b6db
        Renamed: E:\KuGou\李荣浩 - 老街.mp3 -> E:\KuGou\dJZO8LEPf3.b6db
        Created: C:\Users\Administrator\Desktop\o0ya9zk30.exe
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\C645.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF21cf84.TMP
        Renamed: E:\KuGou\田馥甄 - 魔鬼中的天使 - 2012白色时尚音乐节.mp3 -> E:\KuGou\AZt5GgBdnW.b6db
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\67C.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF220b55.TMP
        Renamed: E:\KuGou\薛之谦 - 你还要我怎样.mp3 -> E:\KuGou\zQcoJx3cmt.b6db
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000efb
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000efc
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000efd
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\7479.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF2278a5.TMP
        Renamed: E:\KuGou\钟嘉欣 - 明争暗斗.mp3 -> E:\KuGou\cR2teSREWH.b6db
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cookies-journal
        Created: C:\Users\Administrator\AppData\Local\Temp\etilqs_nmtQuZpfecd71xA
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Sync360_V8.sqlite3-journal
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\5D49.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\360mobilefav.dat~RF235d67.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Extension State\LOG.old~RF235e42.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Extension State\LOCK
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\360sefav.dat-journal
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\673D.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Bookmarks~RF2367e7.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\778A.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Local State~RF237797.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\77BA.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\77DA.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF2377e5.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Network Persistent State~RF2377f4.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\7B75.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\TransportSecurity~RF237b7f.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\9AC6.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\9AC7.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\9AC8.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\9AC9.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\9ACA.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\9ACB.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\9ACC.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\9ADC.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\9ADD.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\9ADE.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\1416.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Local State~RF241425.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Session Storage\LOG.old~RF244aa6.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Session Storage\LOCK
        Created: C:\Users\Administrator\AppData\Local\Temp\etilqs_gRC62g4BuPLK2MM
        Created: C:\Users\Administrator\AppData\Local\Microsoft\Windows\ActionCenterCache\windows-systemtoast-securityandmaintenance_128_0.png
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\EAE0.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF24eaed.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5BE.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5BF.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5C0.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5C1.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5C2.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5C3.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5C4.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5D5.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5D6.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5D7.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5D8.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5E8.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5E9.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\JumpListIcons\F5EA.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000eff
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Favicons-journal
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000f00
        Created: C:\Users\Administrator\AppData\Local\Temp\etilqs_Ft7VJrq2BOXqzoN
        Created: C:\Users\Administrator\AppData\Local\Temp\AgeBF4.tmp
        Created: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\IE\K2ZQJHON\UCGWX6L3.gif
        Created: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCookies\W3ODTFUF.cookie
        Created: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCookies\E6FCMH77.cookie
        Created: C:\Users\Administrator\AppData\Local\Temp\Xunlei\CON11ED.tmp
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\Community\welcome.xml
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\Offline\OfflineConfig_9.xml.tmp
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\xlaccount\LuaXLAccount.ini.tmp
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\xlaccount\XLAccount.ini.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\XLGameBox-FileCache\data\1499366742215.js.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\XLGameBox-FileCache\data\1499366742862.js.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\XLGameBox-FileCache\data\1499366742769.js.tmp
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Data\kn_conf.xml.tmp
        Created: D:\360极速浏览器下载\1914.tmp
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\XLBrowserApp\xl9browser_kernel_urls.xml.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\ico2269.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\ico2269.tmp.ico.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\23F3.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF2523fe.TMP
        Created: C:\Users\Administrator\AppData\Local\Temp\~DFF7A89084749A34E3.TMP
        Created: C:\Users\Administrator\AppData\Local\Temp\~DFB4F2FBF3023546DC.TMP
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000f01
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\4D26.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF254d22.TMP
        Created: C:\ProgramData\360zip\speedmem2.hg-journal
        Created: D:\360极速浏览器下载\855658\fab922a8-736e-4cb5-a666-4fd849a3049a.txt
        Created: D:\360极速浏览器下载\855658\855658.exe
        Created: C:\Users\Administrator\AppData\Roaming\360zip\con_2450281.ini
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\789C.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF2578a6.TMP
        Created: C:\Users\Administrator\AppData\Local\Temp\ico8069.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\ico8069.tmp.ico.tmp
        Created: C:\Users\Administrator\AppData\Local\Temp\etilqs_49K5DqEXX5tBXff
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000f02
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Cache\f_000f03
        Created: C:\Program Files (x86)\Thunder Network\Thunder9\Profiles\XLBrowserApp\CacheData\Cookies-journal
        Created: C:\Users\Administrator\AppData\Local\Temp\etilqs_fI7WsaAyNTNWPi9
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\A451.tmp
        Created: C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\360UID38663595_V8\Preferences~RF25a44a.TMP
        Created: F:\MV\_R_E_A_D___T_H_I_S___YA34SF_.hta
        Created: F:\MV\_R_E_A_D___T_H_I_S___S591OS_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\access.zh-cn\_R_E_A_D___T_H_I_S___KOD8_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\access.zh-cn\_R_E_A_D___T_H_I_S___7LXKEU_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\_R_E_A_D___T_H_I_S___821CWF88_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\_R_E_A_D___T_H_I_S___37PLM5HZ_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\de-de\_R_E_A_D___T_H_I_S___4193I1_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\de-de\_R_E_A_D___T_H_I_S___C08T_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\en-us\_R_E_A_D___T_H_I_S___F86LSJN_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\en-us\_R_E_A_D___T_H_I_S___G577A_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\es-es\_R_E_A_D___T_H_I_S___7YH4_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\es-es\_R_E_A_D___T_H_I_S___MPJY_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\fr-fr\_R_E_A_D___T_H_I_S___ACLE_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\fr-fr\_R_E_A_D___T_H_I_S___H1M4_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\it-it\_R_E_A_D___T_H_I_S___V6VPVP1_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\it-it\_R_E_A_D___T_H_I_S___KNR5_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\ja-jp\_R_E_A_D___T_H_I_S___LC0QBEPO_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\ja-jp\_R_E_A_D___T_H_I_S___1YAVM0_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\ko-kr\_R_E_A_D___T_H_I_S___RNDY_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\ko-kr\_R_E_A_D___T_H_I_S___S37GWBB_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\pt-br\_R_E_A_D___T_H_I_S___ELXNHE_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\pt-br\_R_E_A_D___T_H_I_S___NLUBW2AE_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\ru-ru\_R_E_A_D___T_H_I_S___823ABW5Z_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\ru-ru\_R_E_A_D___T_H_I_S___WPJVADUU_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\zh-cn\_R_E_A_D___T_H_I_S___93ZRI_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\zh-cn\_R_E_A_D___T_H_I_S___REFD_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\zh-tw\_R_E_A_D___T_H_I_S___YVK0LU1A_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\admin\zh-tw\_R_E_A_D___T_H_I_S___DVED_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\catalog\_R_E_A_D___T_H_I_S___XRP11OY_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\catalog\_R_E_A_D___T_H_I_S___XXMTXG0S_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\excel.zh-cn\_R_E_A_D___T_H_I_S___SOD6V_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\dcf.zh-cn\_R_E_A_D___T_H_I_S___4Q5U_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\excel.zh-cn\_R_E_A_D___T_H_I_S___IDMM_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\groove.zh-cn\_R_E_A_D___T_H_I_S___CD9Z_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\dcf.zh-cn\_R_E_A_D___T_H_I_S___CUU1_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\groove.zh-cn\_R_E_A_D___T_H_I_S___T7G5GO_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\office.zh-cn\_R_E_A_D___T_H_I_S___YBHTFZ_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\office.zh-cn\_R_E_A_D___T_H_I_S___X7RJ7_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\lync.zh-cn\_R_E_A_D___T_H_I_S___XPW3M_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\lync.zh-cn\_R_E_A_D___T_H_I_S___MXYKKE_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\infopath.zh-cn\_R_E_A_D___T_H_I_S___AIN192L_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\infopath.zh-cn\_R_E_A_D___T_H_I_S___FBYW_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\OFFICE2013\_R_E_A_D___T_H_I_S___DFXMIL_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\OFFICE2013\_R_E_A_D___T_H_I_S___KVHQET_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\office32.zh-cn\_R_E_A_D___T_H_I_S___62H5_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\office32.zh-cn\_R_E_A_D___T_H_I_S___MUTTV_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\onenote.zh-cn\_R_E_A_D___T_H_I_S___O5RLMR_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\onenote.zh-cn\_R_E_A_D___T_H_I_S___N33P_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\osm.zh-cn\_R_E_A_D___T_H_I_S___YCVH3X_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\osm.zh-cn\_R_E_A_D___T_H_I_S___R8OIM9B_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\osmux.zh-cn\_R_E_A_D___T_H_I_S___7UOF_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\osmux.zh-cn\_R_E_A_D___T_H_I_S___ZDL54Y_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\outlook.zh-cn\_R_E_A_D___T_H_I_S___P24VLO_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\outlook.zh-cn\_R_E_A_D___T_H_I_S___FO61N5DU_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\powerpoint.zh-cn\_R_E_A_D___T_H_I_S___XSG5_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\powerpoint.zh-cn\_R_E_A_D___T_H_I_S___WLJ4H_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\proofing.zh-cn\proof.en\_R_E_A_D___T_H_I_S___KBPG_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\proofing.zh-cn\proof.en\_R_E_A_D___T_H_I_S___LOB7T_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\proplus.ww\_R_E_A_D___T_H_I_S___HQZ3X_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\proofing.zh-cn\_R_E_A_D___T_H_I_S___VCEXL_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\proplus.ww\_R_E_A_D___T_H_I_S___74SZW_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\proofing.zh-cn\_R_E_A_D___T_H_I_S___WEKYW1X_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\proofing.zh-cn\proof.zh-cn\_R_E_A_D___T_H_I_S___W54G7TE0_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\proofing.zh-cn\proof.zh-cn\_R_E_A_D___T_H_I_S___5Y11RX_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\publisher.zh-cn\_R_E_A_D___T_H_I_S___MLDII_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\publisher.zh-cn\_R_E_A_D___T_H_I_S___MJFJ2Z_.txt
        Created: F:\Office_Professional_Plus_2013_64Bit\word.zh-cn\_R_E_A_D___T_H_I_S___MGHE52U5_.hta
        Created: F:\Office_Professional_Plus_2013_64Bit\word.zh-cn\_R_E_A_D___T_H_I_S___NODUBHUL_.txt
        Created: F:\新建文件夹\_R_E_A_D___T_H_I_S___97GIJNF_.hta
        Created: F:\新建文件夹\_R_E_A_D___T_H_I_S___R7DD17_.txt
        Created: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\IE\R8TC6SKE\guard_day_update[1].htm
        Created: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\IE\K2ZQJHON\guard_day_update[1].htm
        ----------------------------------------------------------------

The user blocked access.
fever腾腾
发表于 2017-7-7 09:41:50 | 显示全部楼层
费尔kill
安全守护者
头像被屏蔽
发表于 2017-7-7 11:54:13 | 显示全部楼层
[mw_shl_code=sql,true]文件检测评级:
高度风险
文件名称: 855658.rar

基本信息
文件名称:       
855658.rar
MD5:        0a5a8991c335a0fb3549535846d7bfa2
文件类型:        Rar
上传时间:        2017-07-07 10:17:32
出品公司:        N/A
版本:        N/A
壳或编译器信息:        PACKER:UPolyX v0.5
子文件信息:       
855658.exedumpFile /  d41d8cd98f00b204e9800998ecf8427e /  Unknown
855658.exe /  86d10b27f80f1a1f82c3b93625b6f4e2 /  EXE
关键行为
行为描述:        获取文件属性探测虚拟机
详情信息:       
GetFileAttributes: FileName = c:\documents and settings\administrator\「开始」菜单\程序\oracle vm virtualbox guest additions\
行为描述:        设置特殊文件夹属性
详情信息:       
C:\Documents and Settings\Administrator\favorites
C:\Documents and Settings\Administrator\Favorites\链接
C:\Documents and Settings\Administrator\my documents
C:\Documents and Settings\Administrator\My Documents\My Music
C:\Documents and Settings\Administrator\My Documents\my pictures
C:\Documents and Settings\Administrator\UserData
C:\Documents and Settings\Administrator\UserData\01Q7WLAR
C:\Documents and Settings\Administrator\UserData\KL238XQ7
C:\Documents and Settings\Administrator\UserData\OH67GPIF
C:\Documents and Settings\Administrator\UserData\OX6JK5YB
C:\Documents and Settings\Administrator\「开始」菜单
C:\Documents and Settings\Administrator\「开始」菜单\程序
C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
C:\Documents and Settings\Administrator\「开始」菜单\程序\附件
C:\Documents and Settings\Administrator\「开始」菜单\程序\附件\娱乐
行为描述:        直接获取CPU时钟
详情信息:       
EAX = 0x0578e668, EDX = 0x000000b8
行为描述:        在桌面创建文件
详情信息:       
C:\Documents and Settings\Administrator\桌面\_R_E_A_D___T_H_I_S___IV9G0_.hta
C:\Documents and Settings\Administrator\桌面\_R_E_A_D___T_H_I_S___0HTC3EZ_.txt
行为描述:        获取TickCount值
详情信息:       
TickCount = 223531, SleepMilliseconds = 1000.
TickCount = 223578, SleepMilliseconds = 1000.
TickCount = 223593, SleepMilliseconds = 1000.
TickCount = 223734, SleepMilliseconds = 1000.
TickCount = 223765, SleepMilliseconds = 1000.
TickCount = 223781, SleepMilliseconds = 1000.
TickCount = 223796, SleepMilliseconds = 1000.
TickCount = 223875, SleepMilliseconds = 1000.
TickCount = 223921, SleepMilliseconds = 1000.
TickCount = 223937, SleepMilliseconds = 1000.
TickCount = 223968, SleepMilliseconds = 1000.
TickCount = 224015, SleepMilliseconds = 1000.
TickCount = 224031, SleepMilliseconds = 1000.
TickCount = 224078, SleepMilliseconds = 1000.
TickCount = 224515, SleepMilliseconds = 1000.
进程行为
行为描述:        创建本地线程
详情信息:       
TargetProcess: 855658.exe, InheritedFromPID = 2000, ProcessID = 2616, ThreadID = 2728, StartAddress = 00406980, Parameter = 00000000
TargetProcess: 855658.exe, InheritedFromPID = 2000, ProcessID = 2616, ThreadID = 2760, StartAddress = 004066A5, Parameter = 00B463B0
TargetProcess: 855658.exe, InheritedFromPID = 2000, ProcessID = 2616, ThreadID = 3000, StartAddress = 004066A5, Parameter = 00B463B0
TargetProcess: 855658.exe, InheritedFromPID = 2000, ProcessID = 2616, ThreadID = 3004, StartAddress = 004066A5, Parameter = 00B46390
文件行为
行为描述:        创建文件
详情信息:       
C:\Documents and Settings\Administrator\Local Settings\Temp\dcff734b\43cb.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\dcff734b\bc3f.tmp
C:\Documents and Settings\Administrator\_R_E_A_D___T_H_I_S___WR15S_.hta
C:\Documents and Settings\Administrator\_R_E_A_D___T_H_I_S___GOC044_.txt
C:\Documents and Settings\Administrator\My Documents\_R_E_A_D___T_H_I_S___9GIR928S_.hta
C:\Documents and Settings\Administrator\My Documents\_R_E_A_D___T_H_I_S___CAJ12Y_.txt
C:\Documents and Settings\Administrator\UserData\_R_E_A_D___T_H_I_S___FCMR6JHB_.hta
C:\Documents and Settings\Administrator\UserData\_R_E_A_D___T_H_I_S___R31UAR_.txt
C:\Documents and Settings\root\Cookies\_R_E_A_D___T_H_I_S___D4I6_.hta
C:\Documents and Settings\root\Cookies\_R_E_A_D___T_H_I_S___4JCY51_.txt
C:\_R_E_A_D___T_H_I_S___OTE5ICI_.hta
C:\_R_E_A_D___T_H_I_S___YXJC9S_.txt
C:\Python27\Doc\_R_E_A_D___T_H_I_S___TUPKUJA_.hta
C:\Python27\Doc\_R_E_A_D___T_H_I_S___ZXL2METZ_.txt
C:\Python27\include\_R_E_A_D___T_H_I_S___AA5MQ_.hta
行为描述:        获取文件属性探测虚拟机
详情信息:       
GetFileAttributes: FileName = c:\documents and settings\administrator\「开始」菜单\程序\oracle vm virtualbox guest additions\
行为描述:        查找文件
详情信息:       
FileName = C:\WINDOWS
FileName = C:\WINDOWS\system32
FileName = C:\Documents and Settings\Administrator\Recent\*.lnk
FileName = C:\Program Files
FileName = c:\*
FileName = c:\222c25ed\*
FileName = c:\222c25ed\ie8-setup-full\*
FileName = c:\222c25ed\ie8-setup-full\log\*
FileName = c:\analyzecontrol\*
FileName = c:\diskd\*
FileName = c:\diskx\*
FileName = c:\documents and settings\*
FileName = c:\documents and settings\administrator\*
FileName = c:\documents and settings\administrator\.oracle_jre_usage\*
FileName = c:\documents and settings\administrator\cmb\*
行为描述:        在桌面创建文件
详情信息:       
C:\Documents and Settings\Administrator\桌面\_R_E_A_D___T_H_I_S___IV9G0_.hta
C:\Documents and Settings\Administrator\桌面\_R_E_A_D___T_H_I_S___0HTC3EZ_.txt
行为描述:        重命名文件
详情信息:       
C:\Documents and Settings\Administrator\UserData\index.dat ---> c:\documents and settings\administrator\userdata\FKJejI3E-Q.8911
C:\Documents and Settings\root\Cookies\index.dat ---> c:\documents and settings\root\cookies\9WNEjMTWdL.8911
C:\eula.2052.txt ---> c:\BlnsbwFRSv.8911
C:\Python27\Doc\license-openssl.txt ---> c:\python27\doc\XUQk6PplQI.8911
C:\Python27\Doc\license-python.txt ---> c:\python27\doc\iat9nBGKM5.8911
C:\Python27\Doc\license-tcltk.txt ---> c:\python27\doc\WajWyzoflM.8911
C:\Python27\Doc\LICENSE.txt ---> c:\python27\doc\mloEswG5vA.8911
C:\Python27\include\abstract.h ---> c:\python27\include\z1buGc8yta.8911
C:\Python27\include\bytes_methods.h ---> c:\python27\include\-UsGkrevV4.8911
C:\Python27\include\ceval.h ---> c:\python27\include\a8EGOOtZX2.8911
C:\Python27\include\classobject.h ---> c:\python27\include\sy6S2PAGwr.8911
C:\Python27\include\cobject.h ---> c:\python27\include\dfmQ01g58O.8911
C:\Python27\include\code.h ---> c:\python27\include\8OmofzQkkG.8911
C:\Python27\include\codecs.h ---> c:\python27\include\t8lWBVgAM9.8911
C:\Python27\include\cstringio.h ---> c:\python27\include\Mnb0FR4NSn.8911
行为描述:        设置特殊文件夹属性
详情信息:       
C:\Documents and Settings\Administrator\favorites
C:\Documents and Settings\Administrator\Favorites\链接
C:\Documents and Settings\Administrator\my documents
C:\Documents and Settings\Administrator\My Documents\My Music
C:\Documents and Settings\Administrator\My Documents\my pictures
C:\Documents and Settings\Administrator\UserData
C:\Documents and Settings\Administrator\UserData\01Q7WLAR
C:\Documents and Settings\Administrator\UserData\KL238XQ7
C:\Documents and Settings\Administrator\UserData\OH67GPIF
C:\Documents and Settings\Administrator\UserData\OX6JK5YB
C:\Documents and Settings\Administrator\「开始」菜单
C:\Documents and Settings\Administrator\「开始」菜单\程序
C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
C:\Documents and Settings\Administrator\「开始」菜单\程序\附件
C:\Documents and Settings\Administrator\「开始」菜单\程序\附件\娱乐
行为描述:        修改文件内容
详情信息:       
C:\Documents and Settings\Administrator\Local Settings\Temp\dcff734b\43cb.tmp ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\dcff734b\bc3f.tmp ---> Offset = 0
C:\222c25ed\installer.zip ---> Offset = 1860
C:\222c25ed\installer.zip ---> Offset = 264004
C:\222c25ed\installer.zip ---> Offset = 526148
C:\222c25ed\installer.zip ---> Offset = 788292
C:\222c25ed\installer.zip ---> Offset = 1050436
C:\Documents and Settings\Administrator\_R_E_A_D___T_H_I_S___WR15S_.hta ---> Offset = 0
C:\Documents and Settings\Administrator\_R_E_A_D___T_H_I_S___GOC044_.txt ---> Offset = 0
C:\Documents and Settings\Administrator\My Documents\_R_E_A_D___T_H_I_S___9GIR928S_.hta ---> Offset = 0
C:\Documents and Settings\Administrator\My Documents\_R_E_A_D___T_H_I_S___CAJ12Y_.txt ---> Offset = 0
C:\Documents and Settings\Administrator\UserData\index.dat ---> Offset = 1860
C:\Documents and Settings\Administrator\UserData\index.dat ---> Offset = 1800
C:\Documents and Settings\Administrator\UserData\index.dat ---> Offset = 32768
C:\Documents and Settings\Administrator\UserData\index.dat ---> Offset = 32818
其他行为
行为描述:        创建互斥体
详情信息:       
shell.{D66352C0-6C91-24D8-E1A2-94E37DAFC593}
CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
行为描述:        创建事件对象
详情信息:       
EventName = Global\crypt32LogoffEvent
EventName = Global\userenv: User Profile setup event
行为描述:        打开互斥体
详情信息:       
ShimCacheMutex
行为描述:        加密数据
详情信息:       
[CryptEncrypt] Data: 0x00B34A98, PlainTextLen: 107218, CipherTextLen: 107218, Flags: 0x00000000
[CryptEncrypt] Data: 0x00B35FC8, PlainTextLen: 256, CipherTextLen: 256, Flags: 0x00000000
[CryptEncrypt] Data: 0x00B3E598, PlainTextLen: 110, CipherTextLen: 110, Flags: 0x00000000
[CryptEncrypt] Data: 0x00C3AC50, PlainTextLen: 262144, CipherTextLen: 262144, Flags: 0x00000000
[CryptEncrypt] Data: 0x00B3E730, PlainTextLen: 110, CipherTextLen: 110, Flags: 0x00000000
[CryptEncrypt] Data: 0x014D0050, PlainTextLen: 21180, CipherTextLen: 21180, Flags: 0x00000000
[CryptEncrypt] Data: 0x00C35E60, PlainTextLen: 50, CipherTextLen: 50, Flags: 0x00000000
[CryptEncrypt] Data: 0x00B3E6A8, PlainTextLen: 110, CipherTextLen: 110, Flags: 0x00000000
[CryptEncrypt] Data: 0x00B5F488, PlainTextLen: 50, CipherTextLen: 50, Flags: 0x00000000
[CryptEncrypt] Data: 0x00B3E7B8, PlainTextLen: 110, CipherTextLen: 110, Flags: 0x00000000
[CryptEncrypt] Data: 0x014D0050, PlainTextLen: 30908, CipherTextLen: 30908, Flags: 0x00000000
[CryptEncrypt] Data: 0x00B5F518, PlainTextLen: 50, CipherTextLen: 50, Flags: 0x00000000
[CryptEncrypt] Data: 0x00B3E840, PlainTextLen: 110, CipherTextLen: 110, Flags: 0x00000000
[CryptEncrypt] Data: 0x00B5F5A8, PlainTextLen: 50, CipherTextLen: 50, Flags: 0x00000000
[CryptEncrypt] Data: 0x00B3E950, PlainTextLen: 110, CipherTextLen: 110, Flags: 0x00000000
行为描述:        获取TickCount值
详情信息:       
TickCount = 223531, SleepMilliseconds = 1000.
TickCount = 223578, SleepMilliseconds = 1000.
TickCount = 223593, SleepMilliseconds = 1000.
TickCount = 223734, SleepMilliseconds = 1000.
TickCount = 223765, SleepMilliseconds = 1000.
TickCount = 223781, SleepMilliseconds = 1000.
TickCount = 223796, SleepMilliseconds = 1000.
TickCount = 223875, SleepMilliseconds = 1000.
TickCount = 223921, SleepMilliseconds = 1000.
TickCount = 223937, SleepMilliseconds = 1000.
TickCount = 223968, SleepMilliseconds = 1000.
TickCount = 224015, SleepMilliseconds = 1000.
TickCount = 224031, SleepMilliseconds = 1000.
TickCount = 224078, SleepMilliseconds = 1000.
TickCount = 224515, SleepMilliseconds = 1000.
行为描述:        调整进程token权限
详情信息:       
SE_SHUTDOWN_PRIVILEGE
SE_LOAD_DRIVER_PRIVILEGE
行为描述:        打开事件
详情信息:       
Global\crypt32LogoffEvent
HookSwitchHookEnabledEvent
_fCanRegisterWithShellService
行为描述:        调用Sleep函数
详情信息:       
[1]: MilliSeconds = 1000.
[2]: MilliSeconds = 1000.
[3]: MilliSeconds = 1000.
[4]: MilliSeconds = 1000.
[5]: MilliSeconds = 1.
[6]: MilliSeconds = 1.
[7]: MilliSeconds = 1.
[8]: MilliSeconds = 1.
[9]: MilliSeconds = 1.
[10]: MilliSeconds = 1.
行为描述:        直接获取CPU时钟
详情信息:       
EAX = 0x0578e668, EDX = 0x000000b8
行为描述:        导入密钥
详情信息:       
[CryptImportKey] Algorithm: CALG_RC4 (0x00006801), Data: 0x0012FCA0, DataLen: 28, Flags: 0x00000000
[CryptImportKey] Algorithm: CALG_RSA_KEYX (0x0000a400), Data: 0x001920B0, DataLen: 276, Flags: 0x00000000
[CryptImportKey] Algorithm: CALG_RSA_KEYX (0x0000a400), Data: 0x00B34EB0, DataLen: 130, Flags: 0x00000000
[CryptImportKey] Algorithm: CALG_RC4 (0x00006801), Data: 0x014CF750, DataLen: 28, Flags: 0x00000000
[CryptImportKey] Algorithm: CALG_RC4 (0x00006801), Data: 0x0118F750, DataLen: 28, Flags: 0x00000000
[CryptImportKey] Algorithm: CALG_RC4 (0x00006801), Data: 0x0118F77C, DataLen: 28, Flags: 0x00000000
[CryptImportKey] Algorithm: CALG_RC4 (0x00006801), Data: 0x014CF77C, DataLen: 28, Flags: 0x00000000
Copyright©1998 - 2017 Tencent.All Rights Reserved
腾讯公司 版权所有[/mw_shl_code]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-26 19:34 , Processed in 0.095240 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表