本帖最后由 墨家小子 于 2015-12-1 21:17 编辑
https://www.virustotal.com/en/fi ... nalysis/1448975349/
SHA256: ca7a7c0f91bb28a426208b24797343bf987f3aca34d68a4a06ce7144a018ebff
File name: anbd.exe
Detection ratio: 2 / 55
Analysis date: 2015-12-01 13:09:09 UTC ( 0 minutes ago )
2015/12/1 21:14:13,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAAA\Desktop\1111\anbd.exe" )
2015/12/1 21:14:16,C:\Users\AAAAA\Desktop\1111\anbd.exe,41,Blocked ;修改受保护的文件 (C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini)
2015/12/1 21:14:18,C:\Users\AAAAA\Desktop\1111\anbd.exe,38,Blocked ;访问硬盘驱动器
2015/12/1 21:14:20,C:\Users\AAAAA\Desktop\1111\anbd.exe,41,Blocked ;修改受保护的文件 (C:\Users\AAAAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini)
2015/12/1 21:14:24,C:\Users\AAAAA\Desktop\1111\anbd.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/1 21:14:26,C:\Users\AAAAA\Desktop\1111\anbd.exe,48,Allowed ;出站网络访问 |