https://www.virustotal.com/en/fi ... nalysis/1449662178/
SHA256: a567515e0c0818d889bc7d2ab0263915a071b5374906e8101a57c7e04e196cba
File name: a567515e0c0818d889bc7d2ab0263915a071b5374906e8101a57c7e04e196cba.exe
Detection ratio: 1 / 54
Analysis date: 2015-12-09 11:56:18 UTC ( 1 minute ago )
2015/12/9 19:56:27,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\SSSS\Desktop\S\a567515e0c0818d889bc7d2ab0263915a071b5374906e8101a57c7e04e196cba.exe" )
2015/12/9 19:56:30,C:\Users\SSSS\Desktop\S\a567515e0c0818d889bc7d2ab0263915a071b5374906e8101a57c7e04e196cba.exe,53,Allowed ;执行应用程序 ("C:\Users\SSSS\Desktop\S\a567515e0c0818d889bc7d2ab0263915a071b5374906e8101a57c7e04e196cba.exe" )
2015/12/9 19:56:32,C:\Users\SSSS\Desktop\S\a567515e0c0818d889bc7d2ab0263915a071b5374906e8101a57c7e04e196cba.exe,53,Allowed ;执行应用程序 ("C:\Users\SSSS\Desktop\S\a567515e0c0818d889bc7d2ab0263915a071b5374906e8101a57c7e04e196cba.exe" )
2015/12/9 19:56:33,C:\Users\SSSS\Desktop\S\a567515e0c0818d889bc7d2ab0263915a071b5374906e8101a57c7e04e196cba.exe,53,Allowed ;执行应用程序 ("C:\Users\SSSS\Desktop\S\a567515e0c0818d889bc7d2ab0263915a071b5374906e8101a57c7e04e196cba.exe" )
2015/12/9 19:56:36,C:\Users\SSSS\Desktop\S\a567515e0c0818d889bc7d2ab0263915a071b5374906e8101a57c7e04e196cba.exe,53,Allowed ;执行应用程序 ("C:\windows\system32\explorer.exe")
2015/12/9 19:56:38,C:\Windows\SysWOW64\explorer.exe,41,Blocked ;修改受保护的文件 (C:\Windows\osirohex.exe)
2015/12/9 19:56:39,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Run,etcxogoz)
2015/12/9 19:56:40,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,alacmkil)
2015/12/9 19:56:42,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Run,ujogymyf)
2015/12/9 19:56:43,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,acokimup)
2015/12/9 19:56:44,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Run,eronyrom)
2015/12/9 19:56:46,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,emejadij)
2015/12/9 19:56:53,C:\Windows\SysWOW64\explorer.exe,53,Blocked ;执行应用程序 (vssadmin.exe Delete Shadows /All /Quiet)
2015/12/9 19:56:55,C:\Windows\SysWOW64\explorer.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/9 19:56:58,C:\Windows\SysWOW64\explorer.exe,48,Blocked ;出站网络访问
|