本帖最后由 墨家小子 于 2015-12-28 17:51 编辑
SHA256: 714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51
File name: 714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe
Detection ratio: 3 / 52
Analysis date: 2015-12-28 09:39:25 UTC ( 2 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1451295565/
2015/12/28 17:39:35,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe" )
2015/12/28 17:40:39,C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe" )
2015/12/28 17:41:55,C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe,53,Allowed ;执行应用程序 ("C:\Windows\System32\schtasks.exe" /Create /TN "Update\32qjowieJFEK3jqiewklDAd" /XML "C:\Users\AA\AppData\Local\Temp\z930.xml")
2015/12/28 17:41:55,C:\Windows\System32\conhost.exe,40,Allowed ;以修改权限打开进程或线程 (schtasks.exe(pid=5260))
2015/12/28 17:41:57,C:\Windows\SysWOW64\schtasks.exe,51,Blocked ;进程间通信 (TaskScheduler)
2015/12/28 17:41:59,C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\System,EnableLUA)
2015/12/28 17:42:01,C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe")
2015/12/28 17:42:03,C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe")
2015/12/28 17:43:09,C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe,53,Allowed ;执行应用程序 ("C:\Windows\System32\schtasks.exe" /Create /TN "Update\32qjowieJFEK3jqiewklDAd" /XML "C:\Users\AA\AppData\Local\Temp\z653.xml")
2015/12/28 17:43:09,C:\Windows\System32\conhost.exe,40,Allowed ;以修改权限打开进程或线程 (schtasks.exe(pid=2768))
2015/12/28 17:43:11,C:\Windows\SysWOW64\schtasks.exe,51,Blocked ;进程间通信 (TaskScheduler)
2015/12/28 17:43:12,C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Policies\System,EnableLUA)
2015/12/28 17:43:14,C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe")
2015/12/28 17:43:16,C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe")
2015/12/28 17:43:18,C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe,53,Allowed ;执行应用程序 ("C:\windows\SysWOW64\explorer.exe")
2015/12/28 17:43:20,C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe,40,Blocked ;以修改权限打开进程或线程 (explorer.exe(pid=6924))
2015/12/28 17:43:23,C:\Windows\SysWOW64\explorer.exe,40,Blocked ;以修改权限打开进程或线程 (explorer.exe(pid=4148))
2015/12/28 17:43:24,C:\Windows\SysWOW64\explorer.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/28 17:43:24,C:\Windows\System32\svchost.exe,53,Allowed ;执行应用程序 ("C:\Program Files\Windows Mail\WinMail.exe" -Embedding)
2015/12/28 17:43:29,C:\Windows\SysWOW64\explorer.exe,54,Allowed ;接受入站网络数据包
2015/12/28 17:43:30,C:\Program Files\Windows Mail\WinMail.exe,53,Blocked ;执行应用程序 ("C:\Program Files\Windows Mail\WinMail" OCInstallUserConfigOE)
2015/12/28 17:43:32,C:\Windows\SysWOW64\explorer.exe,48,Blocked ;出站网络访问
2015/12/28 17:43:49,C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe,53,Blocked ;执行应用程序 ("C:\windows\system32\cmd.exe" /c "C:\Users\AA\AppData\Local\Temp\tmp892eaf85.bat")
2015/12/28 17:43:51,C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe")
2015/12/28 17:43:54,C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe")
2015/12/28 17:43:55,C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe,40,Blocked ;以修改权限打开进程或线程 (esif_assist.exe(pid=4128))
2015/12/28 17:43:58,C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\1\714e29900377c1319450b17e6f9970493c2a8425a3e7cb0eaa4875fc64b97d51.exe")
2015/12/28 17:44:00,C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe,53,Terminated ;执行应用程序 ("C:\Users\AA\AppData\Roaming\Idgeez\kugia.exe")
|