SHA256: e2e9820dde1aebe8826877475438e816cffa886da416b7facbcb035bde5d18a3
File name: e2e9820dde1aebe8826877475438e816cffa886da416b7facbcb035bde5d18a3.exe
Detection ratio: 8 / 55
Analysis date: 2015-12-14 03:16:42 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1450063002/
2015/12/14 11:16:46,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAA\Desktop\w
\e2e9820dde1aebe8826877475438e816cffa886da416b7facbcb035bde5d18a3.exe" )
2015/12/14 11:17:05,C:\Users\AAA\Desktop\w
\e2e9820dde1aebe8826877475438e816cffa886da416b7facbcb035bde5d18a3.exe,53,Allowed ;执行应用
程序 (explorer.exe)
2015/12/14 11:17:17,C:\Windows\SysWOW64\explorer.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/14 11:17:43,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2015/12/14 11:18:23,C:\Windows\SysWOW64\explorer.exe,47,Allowed ;创建交换数据流 (C:\Users\AAA
\AppData\Roaming\vuujrghd\jgigeece.exe:Zone.Identifier)
2015/12/14 11:18:26,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows\CurrentVersion\Run,NetMeterEvo)
2015/12/14 11:18:29,C:\Windows\SysWOW64\explorer.exe,53,Allowed ;执行应用程序 (C:\windows
\SysWOW64\WerFault.exe -u -p 7284 -s 976)
|