SHA256: bd30233e79cc5cd03cf6c14e54ea8b92c600937467778fe4b4a3fc95f53b365f
File name: bd30233e79cc5cd03cf6c14e54ea8b92c600937467778fe4b4a3fc95f53b365f.exe
Detection ratio: 7 / 54
Analysis date: 2016-01-05 04:18:19 UTC ( 0 minutes ago )
https://www.virustotal.com/en/fi ... nalysis/1451967499/
2016/1/5 12:19:01,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\1\bd30233e79cc5cd03cf6c14e54ea8b92c600937467778fe4b4a3fc95f53b365f.exe" )
2016/1/5 12:19:04,C:\Users\AA\Desktop\1\bd30233e79cc5cd03cf6c14e54ea8b92c600937467778fe4b4a3fc95f53b365f.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Local\Temp\two.exe" )
2016/1/5 12:19:25,C:\Users\AA\AppData\Local\Temp\two.exe,53,Allowed ;执行应用程序 (explorer.exe)
2016/1/5 12:19:28,C:\Users\AA\Desktop\1\bd30233e79cc5cd03cf6c14e54ea8b92c600937467778fe4b4a3fc95f53b365f.exe,53,Allowed ;执行应用程序 ("C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoMaster.exe" playback "C:\Users\AA\AppData\Local\Temp\wan.jpg")
2016/1/5 12:19:40,C:\Windows\SysWOW64\explorer.exe,50,Allowed ;使用 DNS 解析服务访问网络
2016/1/5 12:19:45,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;出站网络访问
2016/1/5 12:19:53,C:\Windows\SysWOW64\explorer.exe,47,Allowed ;创建交换数据流 (C:\Users\AA\AppData\Roaming\wrabfbvr\jgigeece.exe:Zone.Identifier)
2016/1/5 12:19:55,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Kingsoft)
|