行为描述: 修改原系统的EXE文件
详情信息:
C:\install.exe
C:\Python27\python.exe
C:\Python27\python2.7.exe
C:\Python27\python2.exe
C:\Python27\pythonw.exe
C:\Python27\pythonw2.7.exe
C:\Python27\pythonw2.exe
C:\Python27\w9xpopen.exe
行为描述: 跨进程写入数据
详情信息:
TargetProcess = C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe, WriteAddress = 0x00400000, Size = 0x00000400
TargetProcess = C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe, WriteAddress = 0x00401000, Size = 0x0000fa00
TargetProcess = C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe, WriteAddress = 0x00411000, Size = 0x00005800
TargetProcess = C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe, WriteAddress = 0x00417000, Size = 0x00001400
TargetProcess = C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe, WriteAddress = 0x00423000, Size = 0x00002400
TargetProcess = C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe, WriteAddress = 0x7ffd5008, Size = 0x00000004
行为描述: 修改敏感的系统文件
详情信息:
C:\boot.ini ---> Offset = 0
C:\boot.ini ---> Offset = 224
C:\boot.ini ---> Offset = 256
行为描述: 设置线程上下文
详情信息:
C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe |