本帖最后由 墨家小子 于 2015-12-10 14:40 编辑
SHA256: afb1621f557956fbfbd573240d6b89dec9b21a66197be991329f3d2188ac6ebb
File name: svchost_.exe
Detection ratio: 1 / 55
Analysis date: 2015-12-10 06:35:50 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1449729350/
2015/12/10 14:37:21,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\PPPP\Desktop\zz\svchost_.exe" )
2015/12/10 14:37:36,C:\Users\PPPP\Desktop\zz\svchost_.exe,53,Allowed ;执行应用程序 (explorer.exe)
2015/12/10 14:37:38,C:\Users\PPPP\Desktop\zz\svchost_.exe,40,Blocked ;以修改权限打开进程或线程 (explorer.exe(pid=4788))
2015/12/10 14:37:39,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon,JWbfPAhoQMvnteB)
2015/12/10 14:37:40,C:\Windows\SysWOW64\explorer.exe,41,Blocked ;修改受保护的文件 (C:\Windows\SysWOW64\BQbXLhnTZFZVrN.exe)
2015/12/10 14:37:44,C:\Windows\SysWOW64\explorer.exe,53,Blocked ;执行应用程序 ("C:\windows\SysWOW64\cmd.exe" /c C:\Users\PPPP\AppData\Local\Temp\akk18beccc18467.bat)
|