本帖最后由 墨家小子 于 2015-11-30 22:44 编辑
SHA256: 16ebc150998d18a2f00ba92ff7704d8e3615f6cddf8a48921b678439189a1bd3
File name: crypt.exe
Detection ratio: 2 / 55
Analysis date: 2015-11-30 14:40:20 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1448894420/
2015/11/30 22:41:48,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAAA\Desktop
\11\crypt.exe" )
2015/11/30 22:42:14,C:\Users\AAAAA\Desktop\11\crypt.exe,53,Allowed ;执行应用程序 ("C:\Users
\AAAAA\Desktop\11\crypt.exe")
2015/11/30 22:42:30,C:\Users\AAAAA\Desktop\11\crypt.exe,47,Allowed ;创建交换数据流 (C:
\ProgramData\412540\client.exe:Zone.Identifier)
2015/11/30 22:42:31,C:\Users\AAAAA\Desktop\11\crypt.exe,11,Blocked ;记录键盘输入
2015/11/30 22:42:33,C:\Users\AAAAA\Desktop\11\crypt.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/11/30 22:42:34,C:\Users\AAAAA\Desktop\11\crypt.exe,11,Blocked ;记录键盘输入
2015/11/30 22:42:37,C:\Users\AAAAA\Desktop\11\crypt.exe,48,Allowed ;出站网络访问
2015/11/30 22:42:39,C:\Users\AAAAA\Desktop\11\crypt.exe,40,Blocked ;以修改权限打开进程或线程
(360chrome.exe(pid=5332))
2015/11/30 22:42:41,C:\Users\AAAAA\Desktop\11\crypt.exe,26,Blocked ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon,shell)
2015/11/30 22:42:42,C:\Users\AAAAA\Desktop\11\crypt.exe,57,Blocked ;正在以只读方式打开受保护的进
程 (explorer.exe(pid=644))
2015/11/30 22:42:46,C:\Users\AAAAA\Desktop\11\crypt.exe,26,Blocked ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon,shell)
2015/11/30 22:42:51,C:\Users\AAAAA\Desktop\11\crypt.exe,26,Terminated ;修改受保护的注册表键
(HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon,shell)
|