SHA256: 706eba08e70e2f0a22333521b5f7f3e9f7d1825bb63b0dda375da5e1520e056b
File name: 706eba08e70e2f0a22333521b5f7f3e9f7d1825bb63b0dda375da5e1520e056b.exe
Detection ratio: 4 / 55
Analysis date: 2015-12-03 01:55:30 UTC ( 1 minute ago )
https://www.virustotal.com/en/fi ... nalysis/1449107730/
2015/12/3 9:55:43,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAAA\Desktop
\3333\706eba08e70e2f0a22333521b5f7f3e9f7d1825bb63b0dda375da5e1520e056b.exe" )
2015/12/3 9:55:46,C:\Users\AAAAA\Desktop
\3333\706eba08e70e2f0a22333521b5f7f3e9f7d1825bb63b0dda375da5e1520e056b.exe,26,Blocked ;修
改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,mdvlinx)
2015/12/3 9:55:55,C:\Users\AAAAA\Desktop
\3333\706eba08e70e2f0a22333521b5f7f3e9f7d1825bb63b0dda375da5e1520e056b.exe,53,Allowed ;执
行应用程序 ("C:\Users\AAAAA\Desktop
\3333\706eba08e70e2f0a22333521b5f7f3e9f7d1825bb63b0dda375da5e1520e056b.exe" )
2015/12/3 9:55:57,C:\Users\AAAAA\Desktop
\3333\706eba08e70e2f0a22333521b5f7f3e9f7d1825bb63b0dda375da5e1520e056b.exe,40,Blocked ;以
修改权限打开进程或线程 (svchost.exe(pid=7032))
2015/12/3 9:56:01,C:\Users\AAAAA\AppData\Local\Temp\svchost.exe,47,Allowed ;创建交换数据流 (C:\Users
\AAAAA\AppData\Local\Temp\svchost.exe:Zone.Identifier)
2015/12/3 9:56:02,C:\Users\AAAAA\AppData\Local\Temp\svchost.exe,11,Blocked ;记录键盘输入
2015/12/3 9:56:04,C:\Users\AAAAA\AppData\Local\Temp\svchost.exe,31,Blocked ;访问摄像头
2015/12/3 9:56:07,C:\Users\AAAAA\AppData\Local\Temp\svchost.exe,50,Allowed ;使用 DNS 解析服务访问网
络
2015/12/3 9:56:09,C:\Users\AAAAA\AppData\Local\Temp\svchost.exe,48,Allowed ;出站网络访问
|