SHA256: bd40b0ef40a3df1f2f549f475840075124191a27828ae82b53e7f2ed0e308005
File name: bd40b0ef40a3df1f2f549f475840075124191a27828ae82b53e7f2ed0e308005.exe
Detection ratio: 1 / 54
Analysis date: 2015-12-22 11:18:38 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1450783118/
2015/12/22 19:20:32,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AAA\Desktop\1\bd40b0ef40a3df1f2f549f475840075124191a27828ae82b53e7f2ed0e308005.exe" )
2015/12/22 19:20:33,C:\Users\AAA\Desktop\1\bd40b0ef40a3df1f2f549f475840075124191a27828ae82b53e7f2ed0e308005.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2015/12/22 19:20:37,C:\Users\AAA\Desktop\1\bd40b0ef40a3df1f2f549f475840075124191a27828ae82b53e7f2ed0e308005.exe,53,Allowed ;执行应用程序 (C:\windows\system32\cmd.exe /c ""C:\Users\AAA\Desktop\1\6034625.bat" "C:\Users\AAA\Desktop\1\bd40b0ef40a3df1f2f549f475840075124191a27828ae82b53e7f2ed0e308005.exe"")
2015/12/22 19:20:40,C:\Windows\SysWOW64\cmd.exe,53,Blocked ;执行应用程序 (attrib -r -s -h "C:\Users\AAA\Desktop\1\bd40b0ef40a3df1f2f549f475840075124191a27828ae82b53e7f2ed0e308005.exe")
2015/12/22 19:20:42,C:\Windows\SysWOW64\explorer.exe,41,Allowed ;修改受保护的文件 (C:\Windows\-1293562734-1430344641.exe)
2015/12/22 19:20:44,C:\Windows\SysWOW64\explorer.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/22 19:20:45,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon,Shell)
2015/12/22 19:20:47,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2015/12/22 19:21:19,C:\Windows\SysWOW64\explorer.exe,40,Blocked ;以修改权限打开进程或线程 (explorer.exe(pid=3568))
2015/12/22 19:21:21,C:\Windows\SysWOW64\explorer.exe,40,Blocked ;以修改权限打开进程或线程 (esif_assist.exe(pid=3180))
2015/12/22 19:21:26,C:\Windows\SysWOW64\explorer.exe,54,Allowed ;接受入站网络数据包
|