【1】2016-09-16 17:22:55,系统防护,自定义防护,ammnms.exe触犯自定义文件防护规则, 已阻止
操作进程:D:\My Documents\Tencent Files\240364538\ammnms\ammnms.exe
触犯规则:基础防御 12 | FLY_MC
操作类型:创建
操作文件:C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\Microsoft UpdatX.lnk
用户操作:已阻止
17:23:12:906, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x00000000 wparam:0x00000000 lparam:0x00000000 , 0x00000000 [操作成功完成。 ],
17:23:12:906, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x0000000E wparam:0x00000000 lparam:0x00000000 , 0x0000000D [],
17:23:12:906, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x0000000D wparam:0x0000000E lparam:0x0275C360 , 0x0000000D [],
17:23:12:953, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x00000000 wparam:0x00000000 lparam:0x00000000 , 0x00000000 [操作成功完成。 ],
17:23:12:953, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x0000000E wparam:0x00000000 lparam:0x00000000 , 0x0000000D [],
17:23:12:953, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x0000000D wparam:0x0000000E lparam:0x0275C988 , 0x0000000D [],
17:23:13:000, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x00000000 wparam:0x00000000 lparam:0x00000000 , 0x00000000 [操作成功完成。 ],
17:23:13:000, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x0000000E wparam:0x00000000 lparam:0x00000000 , 0x0000000D [],
17:23:13:000, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x0000000D wparam:0x0000000E lparam:0x0275C360 , 0x0000000D [],
17:23:13:046, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x00000000 wparam:0x00000000 lparam:0x00000000 , 0x00000000 [操作成功完成。 ],
17:23:13:046, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x0000000E wparam:0x00000000 lparam:0x00000000 , 0x0000000D [],
17:23:13:046, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x0000000D wparam:0x0000000E lparam:0x0275C988 , 0x0000000D [],
17:23:13:093, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x00000000 wparam:0x00000000 lparam:0x00000000 , 0x00000000 [操作成功完成。 ],
17:23:13:093, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x0000000E wparam:0x00000000 lparam:0x00000000 , 0x0000000D [],
17:23:13:093, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x0000000D wparam:0x0000000E lparam:0x0275C360 , 0x0000000D [],
17:23:13:140, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x00000000 wparam:0x00000000 lparam:0x00000000 , 0x00000000 [操作成功完成。 ],
17:23:13:140, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x0000000E wparam:0x00000000 lparam:0x00000000 , 0x0000000D [],
17:23:13:140, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x0000000D wparam:0x0000000E lparam:0x0275C988 , 0x0000000D [],
17:23:13:187, ammnms.exe, 3088:4208, 3088, W32_sendmsg, C:\Program Files\huorong\Sysdiag\bin\HRSword.exe, target_pid:4168 hwnd:0x001A0158 msg:0x00000000 wparam:0x00000000 lparam:0x00000000 , 0x00000000 [操作成功完成。 ],
一直在向火绒剑发送消息,没什么别的行为(估计是想绕过火绒剑的分析) |