SHA256: 3579e77f8f7f5064add8923b4eb16ffce2f527cda26ecbab8559be2d0e5a9c8a
File name: 7F25.tmp.exe
Detection ratio: 2 / 55
Analysis date: 2015-11-30 13:36:42 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1448890602/
+++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++
2015/11/30 21:32:54,C:\Program Files (x86)\Internet Explorer\iexplore.exe,53,Allowed ;执行应用程序
(C:\Users\AAAAA\AppData\Local\Temp\Low\7F25.tmp.exe)
2015/11/30 21:32:57,C:\Users\AAAAA\AppData\Local\Temp\Low\7F25.tmp.exe,47,Allowed ;创建交换数
据流 (C:\Users\AAAAA\AppData\Local\Temp\Low\hsckcecr.exe:Zone.Identifier)
2015/11/30 21:33:38,C:\Users\AAAAA\AppData\Local\Temp\Low\7F25.tmp.exe,53,Allowed ;执行应用程
序 (C:\Users\AAAAA\AppData\Local\Temp\Low\hsckcecr.exe)
2015/11/30 21:34:07,C:\Program Files (x86)\Internet Explorer\iexplore.exe,53,Allowed ;执行应用程序
(C:\Users\AAAAA\AppData\Local\Temp\Low\E9E1.tmp.exe)
2015/11/30 21:34:25,C:\Users\AAAAA\AppData\Local\Temp\Low\hsckcecr.exe,53,Blocked ;执行应用程
序 (C:\windows\system32\svchost.exe)
2015/11/30 21:34:37,C:\Users\AAAAA\AppData\Local\Temp\Low\E9E1.tmp.exe,47,Allowed ;创建交换数
据流 (oyjawytm.exe:Zone.Identifier)
2015/11/30 21:34:48,C:\Users\AAAAA\AppData\Local\Temp\Low\hsckcecr.exe,53,Blocked ;执行应用程
序 (C:\windows\system32\svchost.exe)
2015/11/30 21:35:15,C:\Users\AAAAA\AppData\Local\Temp\Low\hsckcecr.exe,53,Blocked ;执行应用程
序 ("C:\windows\SysWOW64\cmd.exe" /C ""C:\Users\AAAAA\AppData\Local\Temp\Low
\oyjawytm.exe"")
2015/11/30 21:35:23,C:\Users\AAAAA\AppData\Local\Temp\Low\hsckcecr.exe,53,Allowed ;执行应用程
序 ("C:\windows\SysWOW64\cmd.exe" /C ""C:\Users\AAAAA\AppData\Local\Temp\Low
\oyjawytm.exe"")
2015/11/30 21:35:27,C:\Windows\SysWOW64\cmd.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAAA
\AppData\Local\Temp\Low\oyjawytm.exe")
2015/11/30 21:35:37,C:\Users\AAAAA\AppData\Local\Temp\Low\oyjawytm.exe,41,Blocked ;修改受保护
的文件 (C:\Users\AAAAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
\xwkfrrvo.exe )
2015/11/30 21:35:47,C:\Users\AAAAA\AppData\Local\Temp\Low\oyjawytm.exe,26,Blocked ;修改受保护
的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,XwkFrrvo)
2015/11/30 21:35:56,C:\Users\AAAAA\AppData\Local\Temp\Low\oyjawytm.exe,26,Blocked ;修改受保护
的注册表键 (HKLM\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\System,EnableLUA)
2015/11/30 21:36:09,C:\Users\AAAAA\AppData\Local\Temp\Low\oyjawytm.exe,26,Blocked ;修改受保护
的注册表键 (HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\Winlogon,Userinit)
2015/11/30 21:36:12,C:\Users\AAAAA\AppData\Local\Temp\Low\oyjawytm.exe,26,Blocked ;修改受保护
的注册表键 (HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion
\Winlogon,Userinit)
|