SHA256: 50591e59024ebca507471bea0fa3fbf18d71f939c97644f4fadb8a8b49d1da47
File name: doc.exe
Detection ratio: 2 / 55
Analysis date: 2015-11-30 01:58:29 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1448848709/
2015/11/30 9:59:18,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\工头不高兴了\Desktop\111\doc.exe" )
2015/11/30 9:59:21,C:\Users\工头不高兴了\Desktop\111\doc.exe,53,Allowed ;执行应用程序 ("C:\Users\工头不高兴了\Desktop\111\doc.exe" )
2015/11/30 9:59:23,C:\Users\工头不高兴了\Desktop\111\doc.exe,47,Allowed ;创建交换数据流 (C:\Users\工头不高兴了\Desktop\111\doc.exe:Zone.Identifier)
2015/11/30 9:59:25,C:\Users\工头不高兴了\Desktop\111\doc.exe,53,Allowed ;执行应用程序 (C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe)
2015/11/30 9:59:29,C:\Users\工头不高兴了\Desktop\111\doc.exe,53,Blocked ;执行应用程序 ("C:\windows\system32\cmd.exe" /c DEL C:\Users\工头不高兴了\Desktop\111\doc.exe)
2015/11/30 9:59:31,C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe,53,Allowed ;执行应用程序 (C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe)
2015/11/30 9:59:33,C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe,47,Allowed ;创建交换数据流 (C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe:Zone.Identifier)
2015/11/30 9:59:36,C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe,53,Blocked ;执行应用程序 (bcdedit.exe /set {current} bootems off)
2015/11/30 9:59:38,C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe,53,Blocked ;执行应用程序 (bcdedit.exe /set {current} advancedoptions off)
2015/11/30 9:59:40,C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe,53,Blocked ;执行应用程序 (bcdedit.exe /set {current} optionsedit off)
2015/11/30 9:59:43,C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe,53,Blocked ;执行应用程序 (bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures)
2015/11/30 9:59:45,C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe,53,Blocked ;执行应用程序 (bcdedit.exe /set {current} recoveryenabled off)
2015/11/30 9:59:49,C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\System,EnableLinkedConnections)
2015/11/30 9:59:53,C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe,53,Blocked ;执行应用程序 ("C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet )
2015/11/30 9:59:55,C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe,40,Blocked ;以修改权限打开进程或线程 (esif_assist.exe(pid=4160))
2015/11/30 9:59:57,C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe,50,Blocked ;使用 DNS 解析服务访问网络
2015/11/30 10:00:00,C:\Users\工头不高兴了\AppData\Roaming\rqctm-a.exe,48,Blocked ;出站网络访问
|