实在太可怕了
Executing -> \Device\HarddiskVolume3\Users\Gateway\Downloads\极品大合集,黑丝.豹纹,性感,,翘臀,看到暴爽.rar.exe (PID: 7224)
Command-line: "C:\Users\Gateway\Downloads\极品大合集,黑丝.豹纹,性感,,翘臀,看到暴爽.rar.exe"
C:\Users\Gateway\Downloads\极品大合集,黑丝.豹纹,性感,,翘臀,看到暴爽.rar.exe
Write File, C:\Program Files (x86)\jm.exe
Executing -> \Device\HarddiskVolume3\Sandbox\Gateway\Analyzer\drive\C\Program Files (x86)\jm.exe (PID: 7352)
Command-line: "C:\Program Files (x86)\jm.exe"
Terminated -> \Device\HarddiskVolume3\Users\Gateway\Downloads\极品大合集 (PID: 7224)
C:\Program Files (x86)\jm.exe
Write File, C:\Program Files (x86)\EShow_3500_2481_v1.07.exe
C:\Program Files (x86)\jm.exe
Write File, C:\Program Files (x86)\KINSTALLERS_66_45411.exe
C:\Program Files (x86)\jm.exe
Write File, C:\Program Files (x86)\setups_66_29812.exe
Executing -> \Device\HarddiskVolume5\Program Files (x86)\Opera\launcher.exe (PID: 7444)
Command-line: "K:\Program Files (x86)\Opera\Launcher.exe" -noautoupdate "http://493680670.qzone.qq.com/#!app=2&via=QZ.HashRefresh&pos=1361597285"
Executing -> \Device\HarddiskVolume5\Program Files (x86)\Opera\launcher.exe (PID: 7456)
Command-line: "K:\Program Files (x86)\Opera\Launcher.exe" -noautoupdate "http://www.247ptp.com/p?uid=3523&ad=2"
Executing -> \Device\HarddiskVolume5\Program Files (x86)\Opera\15.0.1147.130\opera.exe (PID: 7468)
Command-line: "K:\Program Files (x86)\Opera\15.0.1147.130\opera.exe" -noautoupdate --ran-launcher http://493680670.qzone.qq.com/#! ... &pos=1361597285
K:\Program Files (x86)\Opera\15.0.1147.130\opera.exe
Monitor Registry Key, SOFTWARE\MozillaPlugins
K:\Program Files (x86)\Opera\15.0.1147.130\opera.exe
Monitor Registry Key, SOFTWARE\MozillaPlugins
K:\Program Files (x86)\Opera\15.0.1147.130\opera.exe
Monitor Registry Key, Software\Microsoft\Windows\CurrentVersion\Internet Settings
K:\Program Files (x86)\Opera\15.0.1147.130\opera.exe
Monitor Registry Key, Software\Microsoft\Windows\CurrentVersion\Internet Settings
K:\Program Files (x86)\Opera\15.0.1147.130\opera.exe
Monitor Registry Key, SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
K:\Program Files (x86)\Opera\15.0.1147.130\opera.exe
Monitor Registry Key, Software\Microsoft\Windows\CurrentVersion\Internet Settings
K:\Program Files (x86)\Opera\15.0.1147.130\opera.exe
Monitor Registry Key, Software\Microsoft\Windows\CurrentVersion\Internet Settings
K:\Program Files (x86)\Opera\15.0.1147.130\opera.exe
Monitor Registry Key, SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
C:\Program Files (x86)\setups_66_29812.exe
Delete File, C:\Windows\system32\drivers\bc.sys
K:\Program Files (x86)\Opera\15.0.1147.130\opera_autoupdate.exe
Write Registry Key, System\CurrentControlSet\Control\SecurityProviders\Schannel
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, Install Path
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write File, C:\Users\Gateway\AppData\Local\Temp\is-J2N0Q.tmp\_isetup\_shfoldr.dll
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\Coop
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, Software\Microsoft\RestartManager\Session0000
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, OEMName
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, Software\Microsoft\RestartManager\Session0000
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, OrgOEM
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, Owner
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, PreOEM
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, SessionHash
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\Coop
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, Software\Microsoft\RestartManager\Session0000
C:\Windows\SysWOW64\WerFault.exe (PID: 7660)
Access Program, K:\Program Files (x86)\Opera\15.0.1147.130\opera_crashreporter.exe (PID: 7496)
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, Sequence
C:\Windows\SysWOW64\WerFault.exe (PID: 7660)
Access Program, K:\Program Files (x86)\Opera\15.0.1147.130\opera_crashreporter.exe (PID: 7496)
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\union
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write File, C:\Users\Gateway\AppData\Local\Temp\is-J2N0Q.tmp\UpdateIcon.dll
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, Software\Microsoft\Windows\Windows Error Reporting\Debug
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, ProductID
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write File, C:\Users\Gateway\AppData\Local\Temp\is-J2N0Q.tmp\psvince.dll
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, ExceptionRecord
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, versiontypes
C:\Windows\SysWOW64\WerFault.exe (PID: 7660)
Access Program, K:\Program Files (x86)\Opera\15.0.1147.130\opera_crashreporter.exe (PID: 7496)
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\union\Setup
Terminated -> \Device\HarddiskVolume5\Program Files (x86)\Opera\launcher.exe (PID: 7444)
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, iid
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, tod1
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, tod2
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, tid1
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, tid2
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, time
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\Microsoft\Windows\CurrentVersion\Run
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, KSafeTray
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, Software\Microsoft\RestartManager\Session0000
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\kws
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, Software\Microsoft\RestartManager\Session0000
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\kws
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, RegFiles0000
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, i
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, RegFilesHash
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\KEng
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, Software\Microsoft\RestartManager\Session0000
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, Install
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, Software\Microsoft\RestartManager\Session0000
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\update
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, Software\Microsoft\RestartManager\Session0000
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, config3a.dat
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write Registry Key, Software\Microsoft\RestartManager\Session0000
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\update
C:\Users\Gateway\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp
Write File, C:\Program Files (x86)\StarEShow\AppCore.dll
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, kwsu.dat
Executing -> Unknown program (PID: 7484)
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\update
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, script.db
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\update
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, sp3a.nlb
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, System\CurrentControlSet\Control\SecurityProviders\Schannel
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\update
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, WhiteList.dat
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine\KxEScanSystem\ksecore.config.top\appconfig\kse.kspfeng.kspolfile
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, cfgval
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine\KxEScanSystem\ksecore.config.top\appconfig\kse.kspfeng.ksksgpath
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, cfgval
C:\Windows\SysWOW64\WerFault.exe (PID: 7508)
Access PROTECTED Program, C:\Sandbox\Gateway\Analyzer\user\current\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp (PID: 8148)
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine\KxEScanSystem\ksecore.config.top\appconfig\kse.kspfeng.virinfo_cfgpath
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, cfgval
C:\Windows\SysWOW64\WerFault.exe (PID: 7508)
Access PROTECTED Program, C:\Sandbox\Gateway\Analyzer\user\current\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp (PID: 8148)
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine\KxEScanSystem\ksecore.config.top\appconfig\kse.kspfeng.virinfo_libpath
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, cfgval
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, Software\Microsoft\Windows\Windows Error Reporting\Debug
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine\KxEScanSystem\ksecore.config.top\appconfig\kse.kspfeng.ksinifile
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, ExceptionRecord
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, cfgval
C:\Windows\SysWOW64\WerFault.exe (PID: 7508)
Access PROTECTED Program, C:\Sandbox\Gateway\Analyzer\user\current\AppData\Local\Temp\is-6AMDC.tmp\EShow_3500_2481_v1.07.tmp (PID: 8148)
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine\KxEScanSystem\ksecore.config.top\appconfig\kse.kspfeng.ksbwmpath
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, cfgval
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?qk?
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, DisplayName
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, Software\Microsoft\Windows\Windows Error Reporting\Debug
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?qk?
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, StoreLocation
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, UninstallString
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, Software\Microsoft\Windows\Windows Error Reporting\Debug
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?qk?
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, StoreLocation
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, DisplayIcon
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?qk?
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, DisplayVersion
Executing -> \Device\HarddiskVolume5\Program Files (x86)\Opera\15.0.1147.130\opera_crashreporter.exe (PID: 7496)
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?qk?
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, Publisher
Terminated -> \Device\HarddiskVolume5\Program Files (x86)\Opera\launcher.exe (PID: 7456)
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?qk?
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, URLInfoAbout
Executing -> Unknown program (PID: 7580)
C:\Program Files (x86)\setups_66_29812.exe
Write PROTECTED File, \\.\PIPE\srvsvc
Terminated -> Unknown program (PID: 7484)
Terminated -> Unknown program (PID: 7580)
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, Software\Microsoft\Windows\Windows Error Reporting\Debug
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, StoreLocation
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, Software\Microsoft\Windows\Windows Error Reporting\Debug
C:\Windows\SysWOW64\WerFault.exe
Write Registry Key, StoreLocation
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, cfgval
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, {E44A3E87-876D-46BB-8831-836A4C74918B}
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
Executing -> Unknown program (PID: 7760)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, bksafesvc.EXE
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, AppID
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, {E44A3E87-876D-46BB-8831-836A4C74918B}
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, LocalService
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, bksafesvc.bkcomm.1
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
Executing -> Unknown program (PID: 7772)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, CLSID
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, bksafesvc.bkcomm
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, CLSID
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
Terminated -> Unknown program (PID: 7760)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, CurVer
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, {C313E554-97AB-49F9-988F-04DF64CD0451}
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, ProgID
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
Executing -> Unknown program (PID: 7964)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, VersionIndependentProgID
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, Programmable
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, LocalServer32
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, AppID
Executing -> Unknown program (PID: 7976)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, TypeLib
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
Executing -> Unknown program (PID: 7960)
Executing -> Unknown program (PID: 8064)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, cfgval
Executing -> Unknown program (PID: 7840)
Terminated -> Unknown program (PID: 7964)
Terminated -> Unknown program (PID: 7976)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine\CLASSES_ROOT
Executing -> Unknown program (PID: 7792)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
Executing -> Unknown program (PID: 7812)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
Terminated -> Unknown program (PID: 7840)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
Terminated -> Unknown program (PID: 7792)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
Terminated -> Unknown program (PID: 8064)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
Terminated -> Unknown program (PID: 7812)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine\CLASSES_ROOT
Terminated -> \Device\HarddiskVolume3\Sandbox\Gateway\Analyzer\drive\C\Program Files (x86)\jm.exe (PID: 7352)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine\SP_ROOT\KBasicSP
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, Name
Terminated -> Unknown program (PID: 7960)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, SOFTWARE\kingsoft\KSWSVC
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, guid
Executing -> Unknown program (PID: 7660)
Terminated -> Unknown program (PID: 7772)
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine\SP_ROOT\KwsCommunicateSP
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key, Name
C:\Program Files (x86)\setups_66_29812.exe
Delete File, c:\program files (x86)\ksafe\cp\KSafeSvc.exe
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, SOFTWARE\Microsoft\Windows\CurrentVersion\Run
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, KSafeTray
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, CLSID\{9B7A98EC-7EF9-468c-ACC8-37C793DBD7E0}\Implemented Categories\{A5F7140E-4311-4ef9-AABC-F55941B5EBE5}
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, idno
C:\Program Files (x86)\ksafe\KSafeTray.exe
Write Registry Key, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, CLSID\{9B7A98EC-7EF9-468c-ACC8-37C793DBD7E0}\Implemented Categories\{A5F7140E-4311-4ef9-AABC-F55941B5EBE5}
C:\Program Files (x86)\ksafe\KSafeTray.exe
Write Registry Key, NoDriveTypeAutorun
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, idex
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, CLSID\{9B7A98EC-7EF9-468c-ACC8-37C793DBD7E0}\Implemented Categories\{A5F7140E-4311-4ef9-AABC-F55941B5EBE5}
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, idno
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, CLSID\{9B7A98EC-7EF9-468c-ACC8-37C793DBD7E0}\Implemented Categories\{A5F7140E-4311-4ef9-AABC-F55941B5EBE5}
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\setups_66_29812.exe
Write Registry Key, idex
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\ksafevulfix.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\ksafevulfix.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine\SP_ROOT\KxeVulFixEngin
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\ksafevulfix.exe
Write Registry Key, Name
C:\Program Files (x86)\ksafe\ksetupwiz.exe
Write Registry Key, SOFTWARE\KSafe\Coop
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\ksafevulfix.exe
Write Registry Key, SOFTWARE\KSafe\KXEngine\SP_ROOT\CKxeVulFixCommu
C:\Program Files (x86)\ksafe\KSafeTray.exe
Write Registry Key, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\ksafevulfix.exe
Write Registry Key, Name
C:\Program Files (x86)\ksafe\KSafeTray.exe
Write Registry Key, NoDriveTypeAutorun
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\ksafevulfix.exe
Write Registry Key, CLSID\{9B7A98EC-7EF9-468c-ACC8-37C793DBD7E0}\Implemented Categories\{A5F7140E-4311-4ef9-AABC-F55941B5EBE5}
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\ksafevulfix.exe
Write Registry Key, CLSID\{9B7A98EC-7EF9-468c-ACC8-37C793DBD7E0}\Implemented Categories\{A5F7140E-4311-4ef9-AABC-F55941B5EBE5}
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeTray.exe
Write Registry Key, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeTray.exe
Write Registry Key, NoDriveTypeAutorun
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeTray.exe
Write Registry Key, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeTray.exe
Write Registry Key, NoDriveTypeAutorun
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeTray.exe
Write Registry Key, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeTray.exe
Write Registry Key, NoDriveTypeAutorun
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeTray.exe
Write Registry Key, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeTray.exe
Write Registry Key, NoDriveTypeAutorun
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\KSafeSvc.exe
Write Registry Key,
C:\Program Files (x86)\ksafe\kdumprep.exe
Write PROTECTED File, \\.\PIPE\srvsvc
Rolling back...
Analysis ended
Reason: Malware detected and rolled back
Anomalies:
- Modifies protected resource. The executable modifies critical resources (files, processes, etc.) |