基本信息
文件名称:
nvssvc.exe
MD5: f4fa0d3d2978c0f812a45f87143189d4
文件类型: EXE
上传时间: 2014-12-09 21:32:28
出品公司: N/A
版本: 1.0.0.0---1.0.0.0
壳或编译器信息: COMPILER:Elan
关键行为
行为描述: 设置特殊文件夹属性
详情信息:
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
行为描述: 隐藏指定窗口
详情信息:
[Window,Class] = [,Afx:400000:8:10011:1900015:0]
[Window,Class] = [,WTWindow]
进程行为
行为描述: 创建下载文件进程
详情信息:
ImagePath = c:\monitor\Baidusd.Setup.2.1.0.3086.youqian_1000025647.exe, CmdLine = c:\monitor\Baidusd.Setup.2.1.0.3086.youqian_1000025647.exe
ImagePath = c:\monitor\BaiduAn.Setup.1117.3.0.0.3971_1000025647.exe, CmdLine = c:\monitor\BaiduAn.Setup.1117.3.0.0.3971_1000025647.exe
ImagePath = c:\monitor\bdBrowserSetup-5953-ftn_1000025647.exe, CmdLine = c:\monitor\bdBrowserSetup-5953-ftn_1000025647.exe
ImagePath = c:\monitor\service_680_11000.exe, CmdLine = c:\monitor\service_680_11000.exe
文件行为
行为描述: 设置特殊文件夹属性
详情信息:
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
网络行为
行为描述: 连接指定站点
详情信息:
InternetConnectA: ServerName = dlsw.br.baidu.com, PORT = 80
InternetConnectA: ServerName = down.xiami321.com, PORT = 80
行为描述: 下载文件
详情信息:
C:\monitor\Baidusd.Setup.2.1.0.3086.youqian_1000025647.exe
C:\monitor\BaiduAn.Setup.1117.3.0.0.3971_1000025647.exe
C:\monitor\bdBrowserSetup-5953-ftn_1000025647.exe
C:\monitor\service_680_11000.exe
行为描述: 读取网络文件
详情信息:
hFile = 0x000006b0, BytesToRead =10240, BytesRead = 10240.
hFile = 0x000006a8, BytesToRead =10240, BytesRead = 10240.
hFile = 0x000006a4, BytesToRead =10240, BytesRead = 10240.
hFile = 0x000006b4, BytesToRead =10240, BytesRead = 10240.
行为描述: 打开HTTP请求
详情信息:
HttpOpenRequestA: dlsw.br.baidu.com:80/ditui/zujian/baidusd.setup.2.1.0.3086.youqian_1000025647.exe, hConnect = 0x000006b4
HttpOpenRequestA: dlsw.br.baidu.com:80/ditui/zujian/baiduan.setup.1117.3.0.0.3971_1000025647.exe, hConnect = 0x000006ac
HttpOpenRequestA: dlsw.br.baidu.com:80/ditui/zujian/bdbrowsersetup-5953-ftn_1000025647.exe, hConnect = 0x000006b0
HttpOpenRequestA: down.xiami321.com:80/download/service_680_11000.exe, hConnect = 0x000006a8
其他行为
行为描述: 创建互斥体
详情信息:
RasPbFile
行为描述: 隐藏指定窗口
详情信息:
[Window,Class] = [,Afx:400000:8:10011:1900015:0]
[Window,Class] = [,WTWindow] |