本来想双击,奈何我这里依然抛不出行为。。。
给出一个样本的行为日志吧。。
- [:346:]本来想双击,奈何我这里依然抛不出行为。。。
- [code]# Time of Day Thread Module API Return Value Error Duration
- 798 10:42:08.191 PM 1 KERNELBASE.dll LdrLoadDll ( "麜", 0x000000000022f0e0, 0x000000000022f070, 0x000000000022f0d0 ) STATUS_SUCCESS 0.0000051
- 1067 10:42:13.119 PM 1 winhttp.dll CertFreeCertificateContext ( 0x0000000000a65720 ) TRUE 0.0000004
- 1073 10:42:13.119 PM 1 winhttp.dll RpcBindingFree ( 0x000007fef6084650 ) RPC_S_OK 0.0000020
- 1074 10:42:13.119 PM 1 winhttp.dll RpcBindingFree ( 0x000007fef6084658 ) RPC_S_OK 0.0000012
- 1077 10:42:13.599 PM 1 KERNELBASE.dll LdrLoadDll ( "麜", 0x000000000022f0e0, 0x000000000022f070, 0x000000000022f0d0 ) STATUS_SUCCESS 0.0000051
- 1299 10:42:33.421 PM 1 schannel.DLL SslEncryptPacket ( 10519136, 0x00000000009ce2d0, 0x0000000000a705e5, 2, 0x0000000000a705e0, 79, 0x000000000022ec9c, 3, CT_ALERT, 0 ) S_OK 0.0000063
- 1300 10:42:33.421 PM 1 ncrypt.dll BCryptCreateHash ( 0x0000000000a0c480, 0x000000000022e7f0, 0x000000000022e6c8, 286, 0x00000000009e1ab8, 20, 0 ) STATUS_SUCCESS 0.0000020
- 1301 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e200, 0x00000000009e1ab8, 20 ) 0x000000000022e200 0.0000000
- 1302 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e240, 0x00000000009e1ab8, 20 ) 0x000000000022e240 0.0000000
- 1303 10:42:33.421 PM 1 bcryptprimitives.dll memset ( 0x000000000022e214, 0, 44 ) 0x000000000022e214 0.0000004
- 1304 10:42:33.421 PM 1 bcryptprimitives.dll memset ( 0x000000000022e254, 0, 44 ) 0x000000000022e254 0.0000004
- 1305 10:42:33.421 PM 1 ncrypt.dll BCryptHashData ( 0x000000000022e6d0, 0x000000000022e7f8, 13, 0 ) STATUS_SUCCESS 0.0000004
- 1306 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e718, 0x000000000022e7f8, 13 ) 0x000000000022e718 0.0000000
- 1307 10:42:33.421 PM 1 ncrypt.dll BCryptHashData ( 0x000000000022e6d0, 0x0000000000a705e5, 2, 0 ) STATUS_SUCCESS 0.0000000
- 1308 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e725, 0x0000000000a705e5, 2 ) 0x000000000022e725 0.0000000
- 1309 10:42:33.421 PM 1 ncrypt.dll BCryptFinishHash ( 0x000000000022e6d0, 0x0000000000a705e7, 20, 0 ) STATUS_SUCCESS 0.0000008
- 1310 10:42:33.421 PM 1 bcryptprimitives.dll memset ( 0x000000000022e2b0, 0, 41 ) 0x000000000022e2b0 0.0000000
- 1311 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e727, 0x000000000022e2b0, 49 ) 0x000000000022e727 0.0000000
- 1312 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e778, 0x000000000022e330, 20 ) 0x000000000022e778 0.0000000
- 1313 10:42:33.421 PM 1 bcryptprimitives.dll memset ( 0x000000000022e2b0, 0, 36 ) 0x000000000022e2b0 0.0000000
- 1314 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e78c, 0x000000000022e2b0, 44 ) 0x000000000022e78c 0.0000000
- 1315 10:42:33.421 PM 1 ncrypt.dll BCryptDestroyHash ( 0x000000000022e6d0 ) STATUS_SUCCESS 0.0000000
- 1316 10:42:33.421 PM 1 bcryptprimitives.dll memset ( 0x000000000022e700, 0, 216 ) 0x000000000022e700 0.0000000
- 1317 10:42:33.421 PM 1 ncrypt.dll memset ( 0x0000000000a705fb, 9, 10 ) 0x0000000000a705fb 0.0000004
- 1318 10:42:33.421 PM 1 ncrypt.dll BCryptEncrypt ( 0x00000000009e1af0, 0x0000000000a705e5, 32, NULL, NULL, 0, 0x0000000000a705e5, 32, 0x000000000022e938, 0 ) STATUS_SUCCESS 0.0000016
- 1319 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x00000000009e1d30, 0x0000000000a705f5, 16 ) 0x00000000009e1d30 0.0000000
- 1320 10:42:33.421 PM 1 schannel.DLL SslEncryptPacket ( 10519136, 0x00000000009ce2d0, 0x0000000000a78795, 2, 0x0000000000a78790, 79, 0x000000000022eb6c, 4, CT_ALERT, 0 ) S_OK 0.0000055
- 1321 10:42:33.421 PM 1 ncrypt.dll BCryptCreateHash ( 0x0000000000a0c480, 0x000000000022e6c0, 0x000000000022e598, 286, 0x00000000009e1ab8, 20, 0 ) STATUS_SUCCESS 0.0000016
- 1322 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e0d0, 0x00000000009e1ab8, 20 ) 0x000000000022e0d0 0.0000000
- 1324 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e110, 0x00000000009e1ab8, 20 ) 0x000000000022e110 0.0000004
- 1325 10:42:33.421 PM 1 bcryptprimitives.dll memset ( 0x000000000022e0e4, 0, 44 ) 0x000000000022e0e4 0.0000004
- 1326 10:42:33.421 PM 1 bcryptprimitives.dll memset ( 0x000000000022e124, 0, 44 ) 0x000000000022e124 0.0000000
- 1327 10:42:33.421 PM 1 ncrypt.dll BCryptHashData ( 0x000000000022e5a0, 0x000000000022e6c8, 13, 0 ) STATUS_SUCCESS 0.0000004
- 1328 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e5e8, 0x000000000022e6c8, 13 ) 0x000000000022e5e8 0.0000000
- 1329 10:42:33.421 PM 1 ncrypt.dll BCryptHashData ( 0x000000000022e5a0, 0x0000000000a78795, 2, 0 ) STATUS_SUCCESS 0.0000000
- 1330 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e5f5, 0x0000000000a78795, 2 ) 0x000000000022e5f5 0.0000000
- 1331 10:42:33.421 PM 1 ncrypt.dll BCryptFinishHash ( 0x000000000022e5a0, 0x0000000000a78797, 20, 0 ) STATUS_SUCCESS 0.0000008
- 1332 10:42:33.421 PM 1 bcryptprimitives.dll memset ( 0x000000000022e180, 0, 41 ) 0x000000000022e180 0.0000000
- 1333 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e5f7, 0x000000000022e180, 49 ) 0x000000000022e5f7 0.0000000
- 1334 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e648, 0x000000000022e200, 20 ) 0x000000000022e648 0.0000000
- 1335 10:42:33.421 PM 1 bcryptprimitives.dll memset ( 0x000000000022e180, 0, 36 ) 0x000000000022e180 0.0000000
- 1336 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x000000000022e65c, 0x000000000022e180, 44 ) 0x000000000022e65c 0.0000000
- 1337 10:42:33.421 PM 1 ncrypt.dll BCryptDestroyHash ( 0x000000000022e5a0 ) STATUS_SUCCESS 0.0000004
- 1338 10:42:33.421 PM 1 bcryptprimitives.dll memset ( 0x000000000022e5d0, 0, 216 ) 0x000000000022e5d0 0.0000004
- 1339 10:42:33.421 PM 1 ncrypt.dll memset ( 0x0000000000a787ab, 9, 10 ) 0x0000000000a787ab 0.0000000
- 1340 10:42:33.421 PM 1 ncrypt.dll BCryptEncrypt ( 0x00000000009e1af0, 0x0000000000a78795, 32, NULL, NULL, 0, 0x0000000000a78795, 32, 0x000000000022e808, 0 ) STATUS_SUCCESS 0.0000016
- 1341 10:42:33.421 PM 1 bcryptprimitives.dll memcpy ( 0x00000000009e1d30, 0x0000000000a787a5, 16 ) 0x00000000009e1d30 0.0000004
- 1343 10:42:33.421 PM 1 winhttp.dll CertFreeCertificateContext ( 0x0000000000a657a0 ) TRUE 0.0000004
- 1347 10:42:33.421 PM 1 winhttp.dll RpcBindingFree ( 0x000007fef6084650 ) RPC_S_OK 0.0000024
- 1349 10:42:33.421 PM 1 winhttp.dll RpcBindingFree ( 0x000007fef6084658 ) RPC_S_OK 0.0000008
复制代码 [/code]
|