- 17:11:46:607, 360.exe, 2744:0, 2744, EXEC_create, C:\Users\Administrator\Desktop\360.exe, parent_pid:1664 cmdline:'"C:\Users\Administrator\Desktop\360.exe" ' image_base:0x00400000 image_size:0x0002A000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:670, 360.exe, 2744:0, 2744, EXEC_module_load, C:\Windows\System32\dtrampo.dll, base:0x75130000 size:0x0005F000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:670, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\sechost.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:670, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\sechost.dll, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:46:670, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:46:670, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:46:670, 360.exe, 2744:2632, 2744, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\TSUserEnabled, type:0x00000004 datalen:4 data:'00 00 00 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:46:670, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:46:670, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\api-ms-win-core-synch-l1-2-0.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:670, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\api-ms-win-core-synch-l1-2-0.dll, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:46:670, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\Select, access:0x000F003F , 0x00000000 [操作成功完成。 ],
- 17:11:46:670, 360.exe, 2744:2632, 2744, REG_getval, HKEY_LOCAL_MACHINE\SYSTEM\Select\Current, type:0x00000004 datalen:4 data:'01 00 00 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:46:670, 360.exe, 2744:2632, 2744, FILE_open, C:\Users\Administrator\Desktop\360.exe, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:46:701, 360.exe, 2744:2632, 2744, FILE_open, C:\Users\Administrator\AppData\Local\Temp\E_4\krnln.fnr, access:0x00120196 alloc_size:0 attrib:0x00000080 share_access:0x00000000 disposition:0x00000005 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:46:701, 360.exe, 2744:2632, 2744, FILE_truncate, C:\Users\Administrator\AppData\Local\Temp\E_4\krnln.fnr, eof:0x00000000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:701, 360.exe, 2744:2632, 2744, FILE_write, C:\Users\Administrator\AppData\Local\Temp\E_4\krnln.fnr, offset:0x00000000 datalen:0x00066400 , 0x00000000 [操作成功完成。 ],
- 17:11:46:701, 360.exe, 2744:2632, 2744, FILE_modified, C:\Users\Administrator\AppData\Local\Temp\E_4\krnln.fnr, , 0x00000000 [操作成功完成。 ],
- 17:11:46:701, 360.exe, 2744:2632, 2744, FILE_open, C:\Users\Administrator\AppData\Local\Temp\E_4\Exmlrpc.fne, access:0x00120196 alloc_size:0 attrib:0x00000080 share_access:0x00000000 disposition:0x00000005 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:46:701, 360.exe, 2744:2632, 2744, FILE_truncate, C:\Users\Administrator\AppData\Local\Temp\E_4\Exmlrpc.fne, eof:0x00000000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:701, 360.exe, 2744:2632, 2744, FILE_write, C:\Users\Administrator\AppData\Local\Temp\E_4\Exmlrpc.fne, offset:0x00000000 datalen:0x00012000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:701, 360.exe, 2744:2632, 2744, FILE_modified, C:\Users\Administrator\AppData\Local\Temp\E_4\Exmlrpc.fne, , 0x00000000 [操作成功完成。 ],
- 17:11:46:716, 360.exe, 2744:2632, 2744, FILE_open, C:\Users\Administrator\AppData\Local\Temp\E_4\dp1.fne, access:0x00120196 alloc_size:0 attrib:0x00000080 share_access:0x00000000 disposition:0x00000005 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:46:716, 360.exe, 2744:2632, 2744, FILE_truncate, C:\Users\Administrator\AppData\Local\Temp\E_4\dp1.fne, eof:0x00000000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:716, 360.exe, 2744:2632, 2744, FILE_write, C:\Users\Administrator\AppData\Local\Temp\E_4\dp1.fne, offset:0x00000000 datalen:0x0001C000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:716, 360.exe, 2744:2632, 2744, FILE_modified, C:\Users\Administrator\AppData\Local\Temp\E_4\dp1.fne, , 0x00000000 [操作成功完成。 ],
- 17:11:46:716, 360.exe, 2744:2632, 2744, FILE_open, C:\Users\Administrator\AppData\Local\Temp\E_4\krnln.fnr, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:716, 360.exe, 2744:2632, 2744, FILE_open, C:\Users\Administrator\AppData\Local\Temp\E_4\krnln.fnr, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:46:716, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:716, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:0, 2744, EXEC_module_load, C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll, base:0x73700000 size:0x0019E000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\olepro32.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\olepro32.dll, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\winspool.drv, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\winspool.drv, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER, access:0x02000000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\MUI\Settings, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER, access:0x02000000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER\Software\Policies\Microsoft\Control Panel\Desktop, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER\Control Panel\Desktop\LanguageConfiguration, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\MUI\Settings, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER, access:0x02000000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER\Software\Policies\Microsoft\Control Panel\Desktop, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER\Control Panel\Desktop, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\MUI\Settings, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER, access:0x02000000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_getval, HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages, type:0x00000007 datalen:12 data:'7A 00 68 00 2D 00 43 00 4E 00 00 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\WindowsShell.Manifest, access:0x001200A9 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:46:732, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:46:794, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\Globalization\Sorting\SortDefault.nls, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:46:841, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\zh-CN\msctf.dll.mui, access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:857, 360.exe, 2744:2632, 2744, SYS_enumproc, , , 0x00000000 [操作成功完成。 ],
- 17:11:46:857, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System, access:0x00000001 , 0x00000000 [操作成功完成。 ],
- 17:11:46:857, 360.exe, 2744:2632, 2744, FILE_open, C:\Users\Administrator\Desktop\360.exe, access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00200044 , 0x00000000 [操作成功完成。 ],
- 17:11:46:872, 360.exe, 2744:2632, 2744, FILE_open, C:\Users\Administrator\Desktop\360.exe, access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00200064 , 0x00000000 [操作成功完成。 ],
- 17:11:46:872, 360.exe, 2744:2632, 2744, FILE_open, C:\Program Files\36OsafeDat.exe, access:0x00130197 alloc_size:673816 attrib:0x00000020 share_access:0x00000000 disposition:0x00000005 options:0x00000044 , 0x00000000 [操作成功完成。 ],
- 17:11:46:872, 360.exe, 2744:2632, 2744, FILE_truncate, C:\Program Files\36OsafeDat.exe, eof:0x00000000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:872, 360.exe, 2744:2632, 2744, FILE_open, C:\Program Files\36OsafeDat.exe, access:0x00130197 alloc_size:673816 attrib:0x00000020 share_access:0x00000000 disposition:0x00000003 options:0x00000064 , 0x00000000 [操作成功完成。 ],
- 17:11:46:904, 360.exe, 2744:2632, 2744, FILE_truncate, C:\Program Files\36OsafeDat.exe, eof:0x000A4818 , 0x00000000 [操作成功完成。 ],
- 17:11:46:904, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System, access:0x00000001 , 0x00000000 [操作成功完成。 ],
- 17:11:46:904, 360.exe, 2744:2632, 2744, FILE_write, C:\Program Files\36OsafeDat.exe, offset:0x00000000 datalen:0x00010000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:904, 360.exe, 2744:2632, 2744, FILE_chmod, C:\Program Files\36OsafeDat.exe, attrib:0x00000000 , 0x00000000 [操作成功完成。 ],
- 17:11:46:919, 360.exe, 2744:2632, 2744, FILE_modified, C:\Program Files\36OsafeDat.exe, , 0x00000000 [操作成功完成。 ],
- 17:11:46:919, 360.exe, 2744:2632, 2744, SYS_enumproc, , , 0x00000000 [操作成功完成。 ],
- 17:11:46:919, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\360SD, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:46:919, 360.exe, 2744:2632, 2744, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\360SD\ver, type:0x00000001 datalen:22 data:'35 00 2E 00 30 00 2E 00 30 00 2E 00 38 00 30 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:46:919, 360.exe, 2744:2632, 2744, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\360SD\ver, type:0x00000001 datalen:22 data:'35 00 2E 00 30 00 2E 00 30 00 2E 00 38 00 30 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:46:919, 360.exe, 2744:2632, 2744, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\360SD\ver, type:0x00000001 datalen:22 data:'35 00 2E 00 30 00 2E 00 30 00 2E 00 38 00 30 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:46:919, 360.exe, 2744:2632, 2744, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\360SD\ver, type:0x00000001 datalen:22 data:'35 00 2E 00 30 00 2E 00 30 00 2E 00 38 00 30 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:46:919, 360.exe, 2744:2632, 2744, FILE_open, C:\Program Files\36OsafeDat.exe, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:044, 360.exe, 2744:2632, 2744, FILE_open, C:\Program Files\36OsafeDat.exe, access:0x00120196 alloc_size:0 attrib:0x00000080 share_access:0x00000000 disposition:0x00000005 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:044, 360.exe, 2744:2632, 2744, FILE_truncate, C:\Program Files\36OsafeDat.exe, eof:0x00000000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:091, 360.exe, 2744:2632, 2744, FILE_write, C:\Program Files\36OsafeDat.exe, offset:0x01000000 datalen:0x00040000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:138, 360.exe, 2744:2632, 2744, FILE_write, C:\Program Files\36OsafeDat.exe, offset:0x00000000 datalen:0x01534B18 , 0x00000000 [操作成功完成。 ],
- 17:11:47:138, 360.exe, 2744:2632, 2744, FILE_modified, C:\Program Files\36OsafeDat.exe, , 0x00000000 [操作成功完成。 ],
- 17:11:47:153, 360.exe, 2744:2632, 2744, FILE_open, C:\Program Files\36OsafeDat.exe, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:153, 360.exe, 2744:2632, 2744, FILE_open, C:\Program Files\36OsafeDat.exe, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:153, 360.exe, 2744:2632, 2744, FILE_open, C:\Program Files\36OsafeDat.exe, access:0x001000A1 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:231, 360.exe, 2744:2632, 2744, PROC_open, , target_pid:3584 access:0x00000400 , 0x00000AB8 [],
- 17:11:47:231, 360.exe, 2744:2632, 2744, PROC_open, , target_pid:3584 access:0x00000400 , 0x00000AB8 [],
- 17:11:47:247, 360.exe, 2744:0, 2744, PROC_exec, C:\Program Files\36OsafeDat.exe, target_pid:3584 , 0x00000000 [操作成功完成。 ],
- 17:11:47:309, 360.exe, 2744:0, 2744, BA_exec_extratedfile, C:\Program Files\36OsafeDat.exe, , 0x00000000 [操作成功完成。 ],
- 17:11:47:247, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls, access:0x00000001 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:247, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls, access:0x00000001 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option, access:0x00000003 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option, access:0x00000003 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option, access:0x00000001 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option, access:0x00000001 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility, access:0x00000001 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility, access:0x00000001 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AppCompat, access:0x00000001 , 0x00000000 [操作成功完成。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\apphelp.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\apphelp.dll, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\AppPatch\sysmain.sdb, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, access:0x00000001 , 0x00000000 [操作成功完成。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, REG_getval, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache, type:0x00000001 datalen:160 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\36OsafeDat.exe, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:262, 360.exe, 2744:2632, 2744, FILE_open, C:\Program Files\36OsafeDat.exe, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:278, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:47:309, 360.exe, 2744:2632, 2744, FILE_open, C:\Program Files\36OsafeDat.exe, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:309, 360.exe, 2744:2632, 2744, FILE_open, C:\Program Files\36OsafeDat.exe, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:309, 360.exe, 2744:2632, 2744, PROC_writevm, C:\Program Files\36OsafeDat.exe, target_pid:3584 base:0x00150000 bytes_written:0x00000020 datalen:0x00000020 data:'01 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:47:309, 360.exe, 2744:2632, 2744, PROC_writevm, C:\Program Files\36OsafeDat.exe, target_pid:3584 base:0x00150020 bytes_written:0x00000034 datalen:0x00000034 data:'57 14 01 E2 46 15 C5 43 A5 FE 00 8D EE E3 D3 F0 ' , 0x00000000 [操作成功完成。 ],
- 17:11:47:309, 360.exe, 2744:2632, 2744, PROC_writevm, C:\Program Files\36OsafeDat.exe, target_pid:3584 base:0x7FFDE238 bytes_written:0x00000004 datalen:0x00000004 data:'00 00 15 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:47:309, 360.exe, 2744:2632, 2744, THRD_resume, C:\Program Files\36OsafeDat.exe, target_pid:3584 target_tid:320 , 0x00000000 [操作成功完成。 ],
- 17:11:47:309, 360.exe, 2744:2632, 2744, FILE_open, C:\Program Files\36OsafeDat.exe, access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:528, System, 4:2520, 0, NET_accept, 192.168.184.255:138, protocol:(UDP)1 , 0x00000000 [操作成功完成。 ],
- 17:11:47:699, 36OsafeDat.exe, 3584:0, 2744, EXEC_create, C:\Program Files\36OsafeDat.exe, parent_pid:2744 cmdline:'"C:\Program Files\36OsafeDat.exe"' image_base:0x00400000 image_size:0x0002A000 , 0x00000001 [ERROR_WAIT_1 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\TSUserEnabled, type:0x00000004 datalen:4 data:'00 00 00 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option, access:0x00000003 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option, access:0x00000003 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Srp\GP\DLL, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Srp\GP\DLL, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers, access:0x00000001 , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers, access:0x00000001 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Versions, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Versions, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Versions\, type:0x00000001 datalen:36 data:'30 00 30 00 30 00 36 00 30 00 31 00 30 00 31 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager, access:0x00000001 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager, access:0x00000001 , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, FILE_open, C:\Windows\System32\imm32.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, FILE_open, C:\Windows\System32\imm32.dll, access:0x00100001 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, FILE_open, C:\Windows\System32\imm32.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, FILE_open, C:\Windows\System32\imm32.dll, access:0x00100001 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, FILE_open, C:\Windows\System32\imm32.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:715, 36OsafeDat.exe, 3584:320, 2744, FILE_open, C:\Windows\System32\imm32.dll, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:730, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Error Message Instrument, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ],
- 17:11:47:730, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Error Message Instrument, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:730, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:47:730, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE, access:0x02000000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:730, 36OsafeDat.exe, 3584:320, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:47:730, 36OsafeDat.exe, 3584:320, 2744, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs, type:0x00000004 datalen:4 data:'00 00 00 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:47:730, 360.exe, 2744:2632, 2744, FILE_open, C:\Users\Administrator\AppData\Local\Temp\E_4\dp1.fne, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:730, 360.exe, 2744:2632, 2744, FILE_open, C:\Users\Administrator\AppData\Local\Temp\E_4\dp1.fne, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:746, 360.exe, 2744:2632, 2744, FILE_touch, C:\360.exe_And xMe.bat, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000002 disposition:0x00000002 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:746, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\lz32.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:746, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\lz32.dll, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:730, 36OsafeDat.exe, 3584:0, 2744, EXEC_destroy, C:\Program Files\36OsafeDat.exe, parent_pid:2744 cmdline:'"C:\Program Files\36OsafeDat.exe"' , 0x00000000 [操作成功完成。 ],
- 17:11:47:762, 360.exe, 2744:2632, 2744, FILE_open, C:\360.exe_And xMe.bat, access:0x0012019F alloc_size:0 attrib:0x00000000 share_access:0x00000003 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, FILE_write, C:\360.exe_And xMe.bat, offset:0x00000000 datalen:0x00000076 , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, FILE_modified, C:\360.exe_And xMe.bat, , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, FILE_open, C:\360.exe_And xMe.bat, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, FILE_open, C:\360.exe_And xMe.bat, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, FILE_open, C:\360.exe_And xMe.bat, access:0x001000A1 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, FILE_write, C:\360.exe_And xMe.bat, offset:0x00000000 datalen:0x00001000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\AppPatch\sysmain.sdb, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, access:0x00000001 , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, REG_getval, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache, type:0x00000001 datalen:160 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\360.exe_And xMe.bat, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, FILE_open, C:\360.exe_And xMe.bat, access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, FILE_open, C:\360.exe_And xMe.bat, access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, FILE_open, C:\360.exe_And xMe.bat, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, FILE_open, C:\360.exe_And xMe.bat, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:777, 360.exe, 2744:2632, 2744, FILE_open, C:\360.exe_And xMe.bat, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:793, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\cmd.exe, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:793, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\cmd.exe, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:793, 360.exe, 2744:2632, 2744, FILE_open, C:\Windows\System32\cmd.exe, access:0x001000A1 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
- 17:11:47:793, 360.exe, 2744:2632, 2744, PROC_open, , target_pid:2112 access:0x00000400 , 0x00000AB8 [],
- 17:11:47:793, 360.exe, 2744:2632, 2744, PROC_open, , target_pid:2112 access:0x00000400 , 0x00000AB8 [],
- 17:11:47:840, 360.exe, 2744:0, 2744, PROC_exec, C:\Windows\system32\cmd.exe, target_pid:2112 , 0x00000000 [操作成功完成。 ],
- 17:11:47:840, 360.exe, 2744:2632, 2744, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, access:0x00020019 , 0x00000000 [操作成功完成。 ],
- 17:11:47:855, 360.exe, 2744:2632, 2744, PROC_writevm, C:\Windows\system32\cmd.exe, target_pid:2112 base:0x00050000 bytes_written:0x00000020 datalen:0x00000020 data:'01 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:47:855, 360.exe, 2744:2632, 2744, PROC_writevm, C:\Windows\system32\cmd.exe, target_pid:2112 base:0x00050020 bytes_written:0x00000034 datalen:0x00000034 data:'9A 8B 13 35 96 5D BD 4F 8E 2D A2 44 02 25 F9 3A ' , 0x00000000 [操作成功完成。 ],
- 17:11:47:855, 360.exe, 2744:2632, 2744, PROC_writevm, C:\Windows\system32\cmd.exe, target_pid:2112 base:0x7FFDF238 bytes_written:0x00000004 datalen:0x00000004 data:'00 00 05 00 ' , 0x00000000 [操作成功完成。 ],
- 17:11:47:855, 360.exe, 2744:2632, 2744, THRD_resume, C:\Windows\system32\cmd.exe, target_pid:2112 target_tid:1216 , 0x00000000 [操作成功完成。 ],
- 17:11:47:855, cmd.exe, 2112:0, 2744, EXEC_create, C:\Windows\System32\cmd.exe, parent_pid:2744 cmdline:'C:\Windows\system32\cmd.exe /c ""c:\360.exe_And xMe.bat""' image_base:0x4A1C0000 image_size:0x0004C000 , 0x00000000 [操作成功完成。 ],
- 17:11:47:918, csrss.exe, 448:0, 0, PROC_exec, C:\Windows\system32\conhost.exe, target_pid:3560 , 0x00000000 [操作成功完成。 ],
- 17:11:47:886, 360.exe, 2744:0, 2744, EXEC_destroy, C:\Users\Administrator\Desktop\360.exe, parent_pid:1664 cmdline:'"C:\Users\Administrator\Desktop\360.exe" ' , 0x00000000 [操作成功完成。 ],
复制代码
|