SHA256: 34675c00140a9a26ba0fd02bb8797b256260ffe0ffa22839d5ed21f1e65e7450
File name: jblix5hz.b2e.exe
Detection ratio: 6 / 55
Analysis date: 2015-12-04 01:55:54 UTC ( 1 minute ago )
https://www.virustotal.com/en/fi ... nalysis/1449194154/
2015/12/4 9:57:36,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe" )
2015/12/4 9:58:21,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,53,Allowed ;执行应用程序 ("C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe")
2015/12/4 9:58:45,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,53,Allowed ;执行应用程序 ("C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe")
2015/12/4 9:58:53,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,11,Blocked ;记录键盘输入
2015/12/4 9:58:54,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,40,Blocked ;以修改权限打开进程或线程 (360chrome.exe(pid=3136))
2015/12/4 9:58:57,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,comhost.exe)
2015/12/4 9:59:18,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,11,Blocked ;记录键盘输入
2015/12/4 9:59:20,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,47,Blocked ;创建交换数据流 (C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe:Zone.Identifier)
2015/12/4 9:59:29,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,57,Blocked ;正在以只读方式打开受保护的进程 (explorer.exe(pid=3660))
2015/12/4 9:59:36,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/4 9:59:39,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,comhost.exe)
2015/12/4 9:59:41,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,48,Blocked ;出站网络访问
2015/12/4 9:59:44,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,comhost.exe)
2015/12/4 9:59:49,C:\Users\AAAAA\Desktop\111\jblix5hz.b2e.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,comhost.exe)
|