https://www.virustotal.com/en/fi ... nalysis/1448886722/
SHA256: d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0
File name: d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0.exe
Detection ratio: 3 / 55
Analysis date: 2015-11-30 12:32:02 UTC ( 0 minutes ago )
+++++++++++++++++++++++++++++++++++++++++
SHA256: e8db50145a5563abf3d245e146d57e93ccbf4203e7a18b7babc608aa720717ea
File name: glitch-56.exe
Detection ratio: 4 / 55
Analysis date: 2015-11-30 12:40:55 UTC ( 1 minute ago )
https://www.virustotal.com/en/fi ... nalysis/1448887255/
++++++++++++++++++++++++++++++++++++++++
SHA256: 9c9b997a01907d797a4ed4d80cf0994e86ff94fb225970913a25aa0928fd1418
File name: jedec-3.exe
Detection ratio: 4 / 55
Analysis date: 2015-11-30 12:41:07 UTC ( 1 minute ago )
https://www.virustotal.com/en/fi ... nalysis/1448887267/
++++++++++++++++++++++++++++++++++++++++
2015/11/30 20:32:40,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAAAA\Desktop\11\d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0.exe" )
2015/11/30 20:32:54,C:\Users\AAAAAA\Desktop\11\d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAAAA\Desktop\11\d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0.exe" )
2015/11/30 20:33:03,C:\Users\AAAAAA\Desktop\11\d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0.exe,53,Blocked ;执行应用程序 ( -lg hekoyo.dll)
2015/11/30 20:33:05,C:\Users\AAAAAA\Desktop\11\d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0.exe,40,Blocked ;以修改权限打开进程或线程 (explorer.exe(pid=644))
2015/11/30 20:35:10,C:\Users\AAAAAA\Desktop\11\d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/11/30 20:35:12,C:\Users\AAAAAA\Desktop\11\d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0.exe,48,Allowed ;出站网络访问
2015/11/30 20:35:38,C:\Users\AAAAAA\Desktop\11\d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,jedec-81)
2015/11/30 20:36:04,C:\Users\AAAAAA\Desktop\11\d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0.exe,53,Allowed ;执行应用程序 ( -o)
2015/11/30 20:36:22,C:\ProgramData\jedec-6\jedec-3.exe,53,Blocked ;执行应用程序 ( -o kjnps.dll)
2015/11/30 20:36:30,C:\ProgramData\jedec-6\jedec-3.exe,40,Blocked ;以修改权限打开进程或线程 (explorer.exe(pid=644))
2015/11/30 20:36:32,C:\Users\AAAAAA\Desktop\11\d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,glitch-6)
2015/11/30 20:37:11,C:\Users\AAAAAA\Desktop\11\d6dfe0521d13b069864b93d77a5465706f1544fd78b5c6bd556fa37d7ca0a7b0.exe,53,Allowed ;执行应用程序 ( -m0)
2015/11/30 20:37:14,C:\Users\AAAAAA\AppData\Roaming\glitch-81\glitch-56.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,glitch-6) |