本帖最后由 firefox3 于 2012-5-15 11:07 编辑
https://www.virustotal.com/file/ ... nalysis/1337050814/
DefenseWall log file
05.15.2012 11:06:16, 模块 C:\Program Files\Common Files\Microsoft Shared\help.exe, Attempt to create service (服务)
05.15.2012 11:06:15, 模块 C:\Program Files\Common Files\Microsoft Shared\help.exe, Attempt to delete service (服务)
05.15.2012 11:05:54, 模块 C:\Program Files\Common Files\Microsoft Shared\help.exe, 1:Process is running untrusted now (进程)
05.15.2012 11:05:54, 模块 C:\Documents and Settings\Administrator\桌面\2010312161625886.exe, Attempt to delete service (服务)
05.15.2012 11:05:54, 模块 C:\Documents and Settings\Administrator\桌面\2010312161625886.exe, Attempt to set value Common Documents within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
05.15.2012 11:05:54, 模块 C:\Documents and Settings\Administrator\桌面\2010312161625886.exe, Attempt to set value Desktop within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
05.15.2012 11:05:54, 模块 C:\Documents and Settings\Administrator\桌面\2010312161625886.exe, Attempt to set value Common Desktop within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
05.15.2012 11:05:54, 模块 C:\Documents and Settings\Administrator\桌面\2010312161625886.exe, Attempt to set value Cache within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
05.15.2012 11:05:54, 模块 C:\Documents and Settings\Administrator\桌面\2010312161625886.exe, Attempt to set value Cookies within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
05.15.2012 11:05:54, 模块 C:\Documents and Settings\Administrator\桌面\2010312161625886.exe, Attempt to set value Personal within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
|