下面是我跑的结果,可能环境还没满足。
[17:44:26] 开始工作
[17:44:26] 解析文件结果:
******************
文件名:C:\巨人密保卡资料\pjee7TGiHcBY8.exe
文件类型:常见exe文件
Subsystem:IMAGE_SUBSYSTEM_WINDOWS_GUI
********************
[17:44:26] 成功初始化
[17:44:26] 初始化成功
[17:44:26] Create thread StartFilter
[17:44:26] Create thread StartFilter
[17:44:26] Create thread StartFilter
[17:44:27] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 创建 文件 C:\Program Files\439250.jpg, 结果:成功
[17:44:27] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改 文件 C:\Program Files\439250.jpg, 结果:成功
[17:44:28] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Personal Value="C:\Documents and Settings\Administrator\My Documents",结果:成功 BehavioursName:SetValue
[17:44:28] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2cb183ad-b5e4-11df-afdf-806d6172696f} 键值名:BaseClass Value="Drive",结果:成功 BehavioursName:SetValue
[17:44:28] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2cb183ab-b5e4-11df-afdf-806d6172696f} 键值名:BaseClass Value="Drive",结果:成功 BehavioursName:SetValue
[17:44:28] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2cb183aa-b5e4-11df-afdf-806d6172696f} 键值名:BaseClass Value="Drive",结果:成功 BehavioursName:SetValue
[17:44:29] 预处理组件要求break out
[17:44:29] 父进程(0x53c):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 创建 子进程(0x65c):C:\WINDOWS\system32\rundll32.exe,参数:"rundll32.exe" C:\WINDOWS\system32\shimgvw.dll,ImageView_Fullscreen C:\Program Files\439250.jpg,EventTIme=17:44:26
[17:44:29] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 创建 文件 C:\Program Files\39472.dek, 结果:成功
[17:44:29] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改 文件 C:\Program Files\39472.dek, 结果:成功
[17:44:29] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Common Documents Value="C:\Documents and Settings\All Users\Documents",结果:成功 BehavioursName:SetValue
[17:44:29] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Desktop Value="C:\Documents and Settings\Administrator\桌面",结果:成功 BehavioursName:SetValue
[17:44:30] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Common Desktop Value="C:\Documents and Settings\All Users\桌面",结果:成功 BehavioursName:SetValue
[17:44:30] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache 键值名:C:\WINDOWS\system32\shimgvw.dll Value="Windows 图片和传真查看器",结果:成功 BehavioursName:SetValue
[17:44:32] 进程(1628):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2cb183ad-b5e4-11df-afdf-806d6172696f} 键值名:BaseClass Value="Drive",结果:成功 BehavioursName:SetValue
[17:44:32] 进程(1628):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2cb183ab-b5e4-11df-afdf-806d6172696f} 键值名:BaseClass Value="Drive",结果:成功 BehavioursName:SetValue
[17:44:32] 进程(1628):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2cb183aa-b5e4-11df-afdf-806d6172696f} 键值名:BaseClass Value="Drive",结果:成功 BehavioursName:SetValue
[17:44:32] 预处理组件要求break out
[17:44:33] 预处理组件要求break out
[17:44:33] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改 文件 C:\Program Files\39472.dek, 结果:成功
[17:44:33] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改 文件 C:\Program Files\39472.dek, 结果:成功
[17:44:33] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 创建 文件 C:\Program Files\tmp.dat, 结果:成功
[17:44:33] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改 文件 C:\Program Files\tmp.dat, 结果:成功
[17:44:33] 父进程(0x53c):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 创建 子进程(0x79c):C:\WINDOWS\system32\rundll32.exe,参数:"C:\windows\system32\rundll32.exe" "C:\Program Files\39472.dek",DllRegisterServer,EventTIme=17:44:32
[17:44:33] 父进程(0x53c):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 创建 子进程(0xa4):C:\WINDOWS\system32\rundll32.exe,参数:"C:\windows\system32\rundll32.exe" "C:\Program Files\39472.dek",DllUnregisterServer,EventTIme=17:44:32
[17:44:33] 预处理组件要求break out
[17:44:34] 预处理组件要求break out
[17:44:34] 预处理组件要求break out
[17:44:34] 源进程 C:\WINDOWS\system32\rundll32.exe 被注入模块 C:\Program Files\39472.dek ****,EventTIme=17:44:32
[17:44:34] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap 键值名:ProxyBypass Value=0x1,结果:成功 BehavioursName:SetValue
[17:44:34] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap 键值名:IntranetName Value=0x1,结果:成功 BehavioursName:SetValue
[17:44:34] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap 键值名:UNCAsIntranet Value=0x1,结果:成功 BehavioursName:SetValue
[17:44:34] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap 键值名:ProxyBypass Value=0x1,结果:成功 BehavioursName:SetValue
[17:44:35] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap 键值名:IntranetName Value=0x1,结果:成功 BehavioursName:SetValue
[17:44:35] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap 键值名:UNCAsIntranet Value=0x1,结果:成功 BehavioursName:SetValue
[17:44:35] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Cache Value="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files",结果:成功 BehavioursName:SetValue
[17:44:35] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Cookies Value="C:\Documents and Settings\Administrator\Cookies",结果:成功 BehavioursName:SetValue
[17:44:35] 进程(1340):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache 键值名:C:\windows\system32\rundll32.exe Value="Run a DLL as an App",结果:成功 BehavioursName:SetValue
[17:44:36] 进程(0x53c):C:\巨人密保卡资料\pjee7TGiHcBY8.exe 退出,EventTIme=17:44:32
[17:44:36] 源进程 C:\WINDOWS\system32\rundll32.exe 被注入模块 C:\Program Files\39472.dek ****,EventTIme=17:44:32
[17:44:36] 进程(1948):C:\WINDOWS\system32\rundll32.exe 创建 文件夹 C:\cmr, 结果:成功
[17:44:36] 进程(1948):C:\WINDOWS\system32\rundll32.exe 创建 文件 C:\cmr\wandoujia_dll.dll, 结果:成功
[17:44:55] 预处理组件要求break out
[17:44:55] 预处理组件要求break out
[17:44:56] 父进程(0x79c):C:\WINDOWS\system32\rundll32.exe 创建 子进程(0x5d8):C:\WINDOWS\system32\cmd.exe,参数:cmd.exe /c md "C:\cmrb..\",EventTIme=17:44:46
[17:44:56] 父进程(0x79c):C:\WINDOWS\system32\rundll32.exe 创建 子进程(0x570):C:\WINDOWS\system32\cmd.exe,参数:cmd.exe /c copy C:\cmr\MUnpya.exe C:\cmrb..\\,EventTIme=17:44:48
[17:44:56] 预处理组件要求break out
[17:44:56] 预处理组件要求break out
[17:44:57] 预处理组件要求break out
[17:44:57] 进程(1948):C:\WINDOWS\system32\rundll32.exe 创建 文件 C:\cmr\MUnpya.exe, 结果:成功
[17:44:57] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改 文件 C:\cmr\MUnpya.exe, 结果:成功
[17:44:57] 进程(1948):C:\WINDOWS\system32\rundll32.exe 创建 文件夹 C:\cmrb, 结果:成功
[17:44:57] 进程(1948):C:\WINDOWS\system32\rundll32.exe 创建 文件 C:\cmrb\wandoujia_dll.dll, 结果:成功
[17:44:57] 父进程(0x570): 创建 子进程(0x68c):C:\WINDOWS\system32\conime.exe,参数:C:\WINDOWS\system32\conime.exe,EventTIme=17:44:49
[17:44:57] 进程(0x5d8):C:\WINDOWS\system32\cmd.exe 退出,EventTIme=17:44:49
[17:44:58] 进程(0x570):C:\WINDOWS\system32\cmd.exe 退出,EventTIme=17:44:49
[17:44:58] 进程(1496):C:\WINDOWS\system32\cmd.exe 创建 文件夹 C:\cmrb., 结果:成功
[17:44:58] 进程(1392):C:\WINDOWS\system32\cmd.exe 创建 文件 C:\cmrb.\MUnpya.exe, 结果:成功
[17:44:58] 进程(1392):C:\WINDOWS\system32\cmd.exe 修改 文件 C:\cmrb.\MUnpya.exe, 结果:成功
[17:44:58] 进程(1392):C:\WINDOWS\system32\cmd.exe 修改 文件 C:\cmrb.\MUnpya.exe, 结果:成功
[17:44:58] 进程(1392):C:\WINDOWS\system32\cmd.exe 修改 文件 C:\cmrb.\MUnpya.exe, 结果:成功
[17:44:58] 进程(1392):C:\WINDOWS\system32\cmd.exe 修改 文件 C:\cmrb.\MUnpya.exe, 结果:成功
[17:44:58] 进程(1392):C:\WINDOWS\system32\cmd.exe 修改 文件 C:\cmrb.\MUnpya.exe, 结果:成功
[17:44:59] 预处理组件要求break out
[17:44:59] 预处理组件要求break out
[17:45:00] 父进程(0x79c): 创建 子进程(0x164):C:\WINDOWS\system32\cmd.exe,参数:cmd.exe /c rd /s /q C:\cmr,EventTIme=17:44:56
[17:45:01] 进程(0x164):C:\WINDOWS\system32\cmd.exe 退出,EventTIme=17:44:56
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 创建 文件 C:\Program Files\Unpya.dat, 结果:成功
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改 文件 C:\Program Files\Unpya.dat, 结果:成功
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 创建 文件夹 C:\Unpya, 结果:成功
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2cb183ad-b5e4-11df-afdf-806d6172696f} 键值名:BaseClass Value="Drive",结果:成功 BehavioursName:SetValue
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2cb183ab-b5e4-11df-afdf-806d6172696f} 键值名:BaseClass Value="Drive",结果:成功 BehavioursName:SetValue
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2cb183aa-b5e4-11df-afdf-806d6172696f} 键值名:BaseClass Value="Drive",结果:成功 BehavioursName:SetValue
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Desktop Value="C:\Documents and Settings\Administrator\桌面",结果:成功 BehavioursName:SetValue
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Start Menu Value="C:\Documents and Settings\Administrator\「开始」菜单",结果:成功 BehavioursName:SetValue
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Common Start Menu Value="C:\Documents and Settings\All Users\「开始」菜单",结果:成功 BehavioursName:SetValue
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Common Desktop Value="C:\Documents and Settings\All Users\桌面",结果:成功 BehavioursName:SetValue
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Common AppData Value="C:\Documents and Settings\All Users\Application Data",结果:成功 BehavioursName:SetValue
[17:45:01] 进程(356):C:\WINDOWS\system32\cmd.exe 删除 文件 C:\cmr\MUnpya.exe, 结果:成功
[17:45:01] 进程(356):C:\WINDOWS\system32\cmd.exe 删除 文件 C:\cmr\WANDOU~1.DLL, 结果:成功
[17:45:01] 进程(356):C:\WINDOWS\system32\cmd.exe 删除 文件夹 C:\cmr, 结果:成功
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 创建 文件夹 C:\470390, 结果:成功
[17:45:01] 进程(1948):C:\WINDOWS\system32\rundll32.exe 创建 文件 C:\470390\470390.lnk, 结果:成功
[17:45:02] 预处理组件要求break out
[17:45:02] 预处理组件要求break out
[17:45:02] 预处理组件要求break out
[17:45:02] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:AppData Value="C:\Documents and Settings\Administrator\Application Data",结果:成功 BehavioursName:SetValue
[17:45:03] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:My Pictures Value="C:\Documents and Settings\Administrator\My Documents\My Pictures",结果:成功 BehavioursName:SetValue
[17:45:03] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Personal Value="C:\Documents and Settings\Administrator\My Documents",结果:成功 BehavioursName:SetValue
[17:45:03] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:CommonPictures Value="C:\Documents and Settings\All Users\Documents\My Pictures",结果:成功 BehavioursName:SetValue
[17:45:03] 父进程(0x79c): 创建 子进程(0x120):C:\WINDOWS\system32\cmd.exe,参数:cmd /c move C:\470390 "C:\Documents and Settings\All Users\「开始」菜单\程序\Unpya",EventTIme=17:44:58
[17:45:03] 进程(0x79c):C:\WINDOWS\system32\rundll32.exe 退出,EventTIme=17:44:58
[17:45:03] 进程(0x120):C:\WINDOWS\system32\cmd.exe 退出,EventTIme=17:44:58
[17:45:03] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:Common Documents Value="C:\Documents and Settings\All Users\Documents",结果:成功 BehavioursName:SetValue
[17:45:03] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:CommonMusic Value="C:\Documents and Settings\All Users\Documents\My Music",结果:成功 BehavioursName:SetValue
[17:45:03] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改/添加 键值 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 键值名:CommonVideo Value="C:\Documents and Settings\All Users\Documents\My Videos",结果:成功 BehavioursName:SetValue
[17:45:03] 进程(1948):C:\WINDOWS\system32\rundll32.exe 修改 文件 C:\470390\470390.lnk, 结果:成功
[17:45:03] 进程(288):C:\WINDOWS\system32\cmd.exe 更改名字 文件夹 C:\470390,新文件名为:\??\C:\Documents and Settings\All Users\「开始」菜单\程序\Unpya 结果:成功
[17:45:04] pid:164, C:\windows\system32\rundll32.exe resolve Dns: baoshao135.gnway.net
[17:45:05] PID:164,父进程ID:1340, 进程路径:C:\WINDOWS\system32\rundll32.exe 行为:连接,协议:TCP,源:0.0.0.0:1033 ->目标:27.40.250.236:311
[17:45:06] pid:164, C:\windows\system32\rundll32.exe resolve Dns: baoshao135.gnway.net
[17:45:06] PID:164,父进程ID:1340, 进程路径:C:\WINDOWS\system32\rundll32.exe 行为:连接,协议:TCP,源:0.0.0.0:1034 ->目标:27.40.250.236:311
[17:45:06] PID:164,父进程ID:1340, 进程路径:C:\WINDOWS\system32\rundll32.exe 行为:发送数据,协议:TCP,源:0.0.0.0:1034 ->目标:27.40.250.236:311
[17:46:08] 第(1)个可能被注入的进程是:C:\WINDOWS\system32\rundll32.exe,模块名:39472.dek,ExeTime:5330761805827820 100-nanosecond
[17:46:08] 结束监视规则中的进程
[17:46:08] 重置环境成功
|