https://www.virustotal.com/en/fi ... 22f850b08/analysis/
SHA256: 06dfad95007532ccf46d593eedc2474936614aedcea7bf983e36dad22f850b08
File name: 06dfad95007532ccf46d593eedc2474936614aedcea7bf983e36dad22f850b08.exe
Detection ratio: 0 / 54
Analysis date: 2015-12-10 03:39:39 UTC ( 3 minutes ago )
2015/12/10 11:42:02,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\Z\Desktop\zz\06dfad95007532ccf46d593eedc2474936614aedcea7bf983e36dad22f850b08.exe" )
2015/12/10 11:42:09,C:\Users\Z\Desktop\zz\06dfad95007532ccf46d593eedc2474936614aedcea7bf983e36dad22f850b08.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run,MSPY2002)
2015/12/10 11:42:11,C:\Users\Z\Desktop\zz\06dfad95007532ccf46d593eedc2474936614aedcea7bf983e36dad22f850b08.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E4288337-873B-11D1-BAA0-00AA00BBB8C0})
2015/12/10 11:42:13,C:\Users\Z\Desktop\zz\06dfad95007532ccf46d593eedc2474936614aedcea7bf983e36dad22f850b08.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\Classes\Wow6432Node\CLSID)
2015/12/10 11:42:15,C:\Users\Z\Desktop\zz\06dfad95007532ccf46d593eedc2474936614aedcea7bf983e36dad22f850b08.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E4288337-873B-11D1-BAA0-00AA00BBB8C0}\InprocServer32)
2015/12/10 11:42:16,C:\Users\Z\Desktop\zz\06dfad95007532ccf46d593eedc2474936614aedcea7bf983e36dad22f850b08.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\Classes\Wow6432Node\CLSID)
2015/12/10 11:42:17,C:\Users\Z\Desktop\zz\06dfad95007532ccf46d593eedc2474936614aedcea7bf983e36dad22f850b08.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E4288337-873B-11D1-BAA0-00AA00BBB8C0}\ProgID)
2015/12/10 11:42:18,C:\Users\Z\Desktop\zz\06dfad95007532ccf46d593eedc2474936614aedcea7bf983e36dad22f850b08.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\Classes\Wow6432Node\CLSID)
2015/12/10 11:42:19,C:\Users\Z\Desktop\zz\06dfad95007532ccf46d593eedc2474936614aedcea7bf983e36dad22f850b08.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E4288337-873B-11D1-BAA0-00AA00BBB8C0}\VersionIndependentProgID)
2015/12/10 11:42:20,C:\Users\Z\Desktop\zz\06dfad95007532ccf46d593eedc2474936614aedcea7bf983e36dad22f850b08.exe,26,Terminated ;修改受保护的注册表键 (HKLM\SOFTWARE\Classes\Wow6432Node\CLSID)
|