基本信息
文件名称:
lcsebody.zip
MD5: e8be788d329a66ca37cba237bd37497d
文件类型: zip
上传时间: 2017-06-04 12:41:49
出品公司: N/A
版本: N/A
壳或编译器信息: COMPILER:Microsoft Visual C++ 6.0
子文件信息: 详情
关键行为
行为描述: 设置消息钩子
详情信息:
C:\WINDOWS\system32\DINPUT.dll
文件行为
行为描述: 查找文件
详情信息:
FileName = C:\Documents and Settings\Administrator\Local Settings\Temp
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\lcsebody.exe
FileName = C:\Documents and Settings
FileName = C:\Documents and Settings\Administrator
FileName = C:\Documents and Settings\Administrator\Local Settings
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump
FileName = C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\%temp%\****.EXE_7ZDUMP\*.*
其他行为
行为描述: 创建互斥体
详情信息:
DirectSound DllMain mutex (0x000009D8)
CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
Nexton LikeCScriptEngine
DirectSound Administrator shared thread array (lock)
MSCTF.Shared.MUTEX.ELH
行为描述: 创建事件对象
详情信息:
EventName = DINPUTWINMM
行为描述: 查找指定窗口
详情信息:
NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
行为描述: 打开事件
详情信息:
HookSwitchHookEnabledEvent
DINPUTWINMM
Global\SvcctrlStartEvent_A3752DX
CTF.ThreadMIConnectionEvent.000007B4.00000000.00000052
CTF.ThreadMarshalInterfaceEvent.000007B4.00000000.00000052
MSCTF.SendReceiveConection.Event.ELH.IC
MSCTF.SendReceive.Event.ELH.IC
行为描述: 窗口信息
详情信息:
Pid = 2520, Hwnd=0x140306, Text = 确定, ClassName = Button.
Pid = 2520, Hwnd=0xa03b0, Text = DirectSound儅僱乕僕儍惗惉偵幐攕, ClassName = Static.
Pid = 2520, Hwnd=0x60380, Text = error, ClassName = #32770.
Pid = 2520, Hwnd=0x150342, Text = LC-ScriptEngine ver1.0, ClassName = LCSE.
行为描述: 打开互斥体
详情信息:
ShimCacheMutex
进程树
lcsebody.exe (PID: 0x000009d8) |