SHA256: dac8b3924395ee640150df8fbec9de0c8bdf088a19fbc6f44c6536c4d600e696
File name: lol.exe
Detection ratio: 7 / 55
Analysis date: 2016-01-05 02:18:47 UTC ( 1 minute ago )
https://www.virustotal.com/en/fi ... nalysis/1451960327/
2016/1/5 10:17:44,C:\Windows\System32\wscript.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData
\Local\Temp\lol.exe" )
2016/1/5 10:17:46,C:\Users\AA\AppData\Local\Temp\lol.exe,50,Allowed ;使用 DNS 解析服务访问网络
2016/1/5 10:17:48,C:\Users\AA\AppData\Local\Temp\lol.exe,48,Allowed ;出站网络访问
2016/1/5 10:17:55,C:\Users\AA\AppData\Local\Temp\lol.exe,53,Allowed ;执行应用程序 ("C:\Users\f
\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe" )
2016/1/5 10:17:59,C:\Users\AA\AppData\Local\Temp\lol.exe,26,Blocked ;修改受保护的注册表键 (HKCU
\Software\Microsoft\Windows\CurrentVersion\Run,Sidebar(32.1Updated))
2016/1/5 10:18:01,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,17,Blocked ;记
录键盘输入
2016/1/5 10:18:02,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,26,Blocked ;修
改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Sidebar(32.1Updated))
2016/1/5 10:18:04,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,18,Blocked ;记
录键盘输入
2016/1/5 10:18:05,C:\Windows\System32\services.exe,53,Allowed ;执行应用程序 (C:\windows
\System32\svchost.exe -k WerSvcGroup)
2016/1/5 10:18:10,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,41,Blocked ;修
改受保护的文件 (C:\Users\AA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
\Startup32.1Updated.exe)
2016/1/5 10:18:11,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,26,Blocked ;修
改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Sidebar(32.1Updated))
2016/1/5 10:18:13,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,50,Allowed ;使
用 DNS 解析服务访问网络
2016/1/5 10:18:16,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,48,Allowed ;出
站网络访问
2016/1/5 10:18:18,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,26,Blocked ;修
改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Sidebar(32.1Updated))
2016/1/5 10:18:19,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,26,Blocked ;修
改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Sidebar(32.1Updated))
2016/1/5 10:18:21,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,26,Blocked ;修
改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Sidebar(32.1Updated))
2016/1/5 10:18:23,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,26,Blocked ;修
改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Sidebar(32.1Updated))
2016/1/5 10:18:25,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,26,Blocked ;修
改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Sidebar(32.1Updated))
2016/1/5 10:18:27,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,26,Blocked ;修
改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Sidebar(32.1Updated))
2016/1/5 10:18:30,C:\Users\AA\AppData\Roaming\ProgramFiles(32.1)Updated\svchost.exe,26,Terminated
;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Sidebar
(32.1Updated))
|