本帖最后由 墨家小子 于 2015-12-14 19:59 编辑
SHA256: 51c3c92063b65fac8d7e748debca7d5897a9e8b5c5d31b359a363041366bfeaf
File name: lite543.exe
Detection ratio: 6 / 54
Analysis date: 2015-12-14 11:29:21 UTC ( 1 minute ago )
https://www.virustotal.com/en/fi ... nalysis/1450092561/
2015/12/14 19:30:19,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\W\lite543.exe" )
2015/12/14 19:30:29,C:\Users\AA\Desktop\W\lite543.exe,53,Allowed ;执行应用程序 ("C:\windows\system32\msiexec.exe")
2015/12/14 19:30:32,C:\Windows\SysWOW64\msiexec.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/14 19:30:38,C:\Windows\SysWOW64\msiexec.exe,48,Allowed ;出站网络访问
2015/12/14 19:30:42,C:\Windows\SysWOW64\msiexec.exe,47,Allowed ;创建交换数据流 (C:\ProgramData\msojglxqp.exe:Zone.Identifier)
2015/12/14 19:30:44,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows,Load)
2015/12/14 19:30:46,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run)
2015/12/14 19:30:47,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,80835775)
2015/12/14 19:31:10,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22530312.exe)
2015/12/14 19:31:20,C:\ProgramData\CreativeAudio\aa7e19539gkcw.exe,47,Allowed ;创建交换数据流 (C:\ProgramData\CreativeAudio\aa7e19539gkcw.exe:Zone.Identifier)
2015/12/14 19:31:25,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22551859.exe)
2015/12/14 19:31:28,C:\ProgramData\CreativeAudio\aa7e19539gkcw.exe,53,Allowed ;执行应用程序 (C:\windows\SysWOW64\explorer.exe)
2015/12/14 19:31:31,C:\Users\AA\AppData\Local\Temp\KB22551859.exe,53,Allowed ;执行应用程序 ("C:\windows\system32\msiexec.exe")
2015/12/14 19:31:33,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2015/12/14 19:31:35,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2015/12/14 19:31:37,C:\Windows\SysWOW64\msiexec.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/14 19:31:52,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22572265.exe)
2015/12/14 19:31:54,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2015/12/14 19:31:58,C:\Windows\SysWOW64\msiexec.exe,48,Allowed ;出站网络访问
2015/12/14 19:31:59,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2015/12/14 19:32:02,C:\Users\AA\AppData\Local\Temp\KB22572265.exe,53,Allowed ;执行应用程序 ("C:\windows\system32\msiexec.exe")
2015/12/14 19:32:04,C:\Windows\SysWOW64\msiexec.exe,47,Allowed ;创建交换数据流 (C:\ProgramData\msxkrd.exe:Zone.Identifier)
2015/12/14 19:32:06,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Internet Explorer\Main,NoProtectedModeBanner)
2015/12/14 19:32:07,C:\Windows\SysWOW64\msiexec.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/14 19:32:09,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows,Load)
2015/12/14 19:32:10,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2015/12/14 19:32:14,C:\Windows\SysWOW64\msiexec.exe,48,Allowed ;出站网络访问
2015/12/14 19:32:16,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,2077409781)
2015/12/14 19:32:18,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2015/12/14 19:32:20,C:\Windows\SysWOW64\msiexec.exe,47,Allowed ;创建交换数据流 (C:\ProgramData\msxkrd.exe:Zone.Identifier)
2015/12/14 19:32:22,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2015/12/14 19:32:23,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows,Load)
2015/12/14 19:32:43,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22618750.exe)
2015/12/14 19:32:44,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2015/12/14 19:32:45,C:\Windows\SysWOW64\msiexec.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,2077409781)
2015/12/14 19:32:48,C:\Users\AA\AppData\Local\Temp\KB22618750.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2015/12/14 19:32:49,C:\Windows\SysWOW64\explorer.exe,40,Blocked ;以修改权限打开进程或线程 (esif_assist.exe(pid=4064))
2015/12/14 19:33:11,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22645390.exe)
2015/12/14 19:33:12,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,djSaS011arbaaa1za13a1)
2015/12/14 19:33:14,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2015/12/14 19:33:15,C:\Windows\SysWOW64\explorer.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/14 19:33:46,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22652390.exe)
2015/12/14 19:33:48,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2015/12/14 19:33:49,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,djSaS011arbaaa1za13a1)
2015/12/14 19:33:54,C:\Windows\SysWOW64\explorer.exe,48,Blocked ;出站网络访问
2015/12/14 19:33:56,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2015/12/14 19:34:11,C:\Users\AA\AppData\Local\Temp\KB22652390.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2015/12/14 19:34:13,C:\Users\AA\AppData\Local\Temp\KB22645390.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2015/12/14 19:34:15,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2015/12/14 19:34:17,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2015/12/14 19:34:18,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,a12121zq)
2015/12/14 19:34:20,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2015/12/14 19:34:22,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2015/12/14 19:34:28,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22709750.exe)
2015/12/14 19:34:30,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,a12121zq)
2015/12/14 19:34:44,C:\Windows\SysWOW64\msiexec.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22672562.exe)
2015/12/14 19:34:45,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2015/12/14 19:34:46,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,a12121zq)
2015/12/14 19:34:53,C:\Users\AA\AppData\Local\Temp\KB22709750.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2015/12/14 19:35:10,C:\Users\AA\AppData\Local\Temp\KB22672562.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2015/12/14 19:35:12,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2015/12/14 19:35:13,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,KdjSaS011arbaaa1za13a)
2015/12/14 19:35:14,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2015/12/14 19:35:16,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,KdjSaS011arbaaa1za13a)
2015/12/14 19:35:17,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,KdjSaS011arbaaa1za13a)
2015/12/14 19:35:18,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,CreativeAudio)
2015/12/14 19:35:19,C:\Windows\SysWOW64\explorer.exe,47,Terminated ;创建交换数据流 (C:\ProgramData\CreativeAudio\aa7e19539gkcw.exe:Zone.Identifier)
2015/12/14 19:35:21,C:\Windows\SysWOW64\explorer.exe,26,Terminated ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,a12121zq)
2015/12/14 19:35:23,C:\Windows\SysWOW64\explorer.exe,26,Terminated ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2015/12/14 19:35:45,C:\Windows\SysWOW64\msiexec.exe,53,Blocked ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22750031.exe)
2015/12/14 19:35:45,C:\Windows\SysWOW64\explorer.exe,33,Blocked ;设置钩子以监控网络请求 (C:\Windows\SysWOW64\explorer.exe(PID=8108))
2015/12/14 19:35:46,C:\Windows\SysWOW64\msiexec.exe,53,Blocked ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22765343.exe)
2015/12/14 19:35:48,C:\Windows\SysWOW64\explorer.exe,48,Terminated ;出站网络访问
2015/12/14 19:36:08,C:\Windows\SysWOW64\msiexec.exe,53,Blocked ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22826265.exe)
2015/12/14 19:36:09,C:\Windows\SysWOW64\msiexec.exe,53,Blocked ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22828500.exe)
2015/12/14 19:36:26,C:\Windows\SysWOW64\msiexec.exe,53,Terminated ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22849703.exe)
2015/12/14 19:36:27,C:\Windows\SysWOW64\msiexec.exe,53,Terminated ;执行应用程序 (C:\Users\AA\AppData\Local\Temp\KB22850687.exe)
|