SHA256: 807f8e77f8557fb5eb892dcd5931ac2cfe5a477f9aff75b242100569e22e64a6
File name: 807f8e77f8557fb5eb892dcd5931ac2cfe5a477f9aff75b242100569e22e64a6.exe
Detection ratio: 1 / 55
Analysis date: 2015-12-02 02:11:36 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1449022296/
2015/12/2 10:11:47,C:\Windows\explorer.exe,53,Allowed ;Execution of an application ("C:\Users\AAAAAA\Desktop\1111\807f8e77f8557fb5eb892dcd5931ac2cfe5a477f9aff75b242100569e22e64a6.exe" )
2015/12/2 10:11:49,C:\Users\AAAAAA\Desktop\1111\807f8e77f8557fb5eb892dcd5931ac2cfe5a477f9aff75b242100569e22e64a6.exe,53,Allowed ;Execution of an application ("C:\Users\AAAAAA\AppData\Local\TempWise Memory Optimizer.exe" )
2015/12/2 10:11:51,C:\Users\AAAAAA\Desktop\1111\807f8e77f8557fb5eb892dcd5931ac2cfe5a477f9aff75b242100569e22e64a6.exe,53,Allowed ;Execution of an application ("C:\Users\AAAAAA\AppData\Local\Tempaldalam.exe" )
2015/12/2 10:11:54,C:\Users\AAAAAA\AppData\Local\TempWise Memory Optimizer.exe,51,Blocked ;Inter-process communication (TaskScheduler)
2015/12/2 10:11:56,C:\Users\AAAAAA\AppData\Local\Tempaldalam.exe,53,Allowed ;Execution of an application ("C:\Users\AAAAAA\AppData\Roaming\svchost.exe" )
2015/12/2 10:12:01,C:\Users\AAAAAA\AppData\Local\TempWise Memory Optimizer.exe,53,Allowed ;Execution of an application (C:\windows\SysWOW64\WerFault.exe -u -p 1424 -s 536)
2015/12/2 10:12:01,C:\Windows\SysWOW64\WerFault.exe,40,Allowed ;Opening process or thread for modify access (TempWise Memory Optimizer.exe(pid=1424))
2015/12/2 10:12:02,C:\Windows\SysWOW64\WerFault.exe,50,Allowed ;Accessing the network via DNSResolver service
2015/12/2 10:12:02,C:\Windows\SysWOW64\WerFault.exe,48,Allowed ;Outgoing network access
establish an outgoing network connection (TCP)
RemoteAddress=games32.no-ip.biz(149.255.192.97) RemotePort=1188
2015/12/2 10:12:06,C:\Users\AAAAAA\AppData\Roaming\svchost.exe,53,Blocked ;Execution of an application (netsh firewall add allowedprogram "C:\Users\AAAAAA\AppData\Roaming\svchost.exe" "svchost.exe" ENABLE)
2015/12/2 10:12:07,C:\Users\AAAAAA\AppData\Roaming\svchost.exe,26,Blocked ;Modifying protected registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,23556fb1360f366337f97c924e76ead3)
2015/12/2 10:12:11,C:\Users\AAAAAA\AppData\Roaming\svchost.exe,41,Blocked ;Modifying protected file (C:\Users\AAAAAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\23556fb1360f366337f97c924e76ead3.exe)
2015/12/2 10:12:14,C:\Users\AAAAAA\AppData\Roaming\svchost.exe,17,Blocked ;Recording keyboard input
2015/12/2 10:12:17,C:\Users\AAAAAA\AppData\Roaming\svchost.exe,26,Blocked ;Modifying protected registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,23556fb1360f366337f97c924e76ead3)
2015/12/2 10:12:20,C:\Users\AAAAAA\AppData\Roaming\svchost.exe,50,Allowed ;Accessing the network via DNSResolver service
2015/12/2 10:12:21,C:\Users\AAAAAA\AppData\Roaming\svchost.exe,26,Blocked ;Modifying protected registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,23556fb1360f366337f97c924e76ead3)
2015/12/2 10:12:28,C:\Users\AAAAAA\AppData\Roaming\svchost.exe,48,Blocked ;Outgoing network access
2015/12/2 10:12:30,C:\Users\AAAAAA\AppData\Roaming\svchost.exe,18,Terminated ;Recording keyboard input
2015/12/2 10:12:32,C:\Users\AAAAAA\AppData\Roaming\svchost.exe,26,Terminated ;Modifying protected registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,23556fb1360f366337f97c924e76ead3)
|