mountvol。。。
SSF:
- 2021/8/23 21:58:09,22896,C:\Windows\System32\conhost.exe,52,Allowed ;修改属于其它进程的窗口的属性 (a6d209babee9369a36522c1007d33483279a9430b9d17b2e9b6ff5aa1afbfcf0.exe(pid=22880))
- 2021/8/23 21:58:15,22880,C:\Program Files (x86)\Huorong\a6d209babee9369a36522c1007d33483279a9430b9d17b2e9b6ff5aa1afbfcf0.exe,53,Blocked ;执行应用程序 (C:\Windows\system32\cmd.exe /c mountvol C: /D)
- 2021/8/23 21:58:18,22880,C:\Program Files (x86)\Huorong\a6d209babee9369a36522c1007d33483279a9430b9d17b2e9b6ff5aa1afbfcf0.exe,53,Blocked ;执行应用程序 (C:\Windows\system32\cmd.exe /c rd /s /q C:\)
- 2021/8/23 21:58:19,22880,C:\Program Files (x86)\Huorong\a6d209babee9369a36522c1007d33483279a9430b9d17b2e9b6ff5aa1afbfcf0.exe,53,Blocked ;执行应用程序 (C:\Windows\system32\cmd.exe /c rd /s /q C:\)
- 2021/8/23 21:58:21,22880,C:\Program Files (x86)\Huorong\a6d209babee9369a36522c1007d33483279a9430b9d17b2e9b6ff5aa1afbfcf0.exe,53,Blocked ;执行应用程序 (cmd.exe /c mountvol C: /D)
- 2021/8/23 21:58:33,22880,C:\Program Files (x86)\Huorong\a6d209babee9369a36522c1007d33483279a9430b9d17b2e9b6ff5aa1afbfcf0.exe,53,Terminated ;执行应用程序 (cmd.exe /c rd /s /q C:\)
- 2021/8/23 21:58:35,22880,C:\Program Files (x86)\Huorong\a6d209babee9369a36522c1007d33483279a9430b9d17b2e9b6ff5aa1afbfcf0.exe,53,Terminated ;执行应用程序 (cmd.exe /c rd /s /q C:\)
- 2021/8/23 21:58:37,22880,C:\Program Files (x86)\Huorong\a6d209babee9369a36522c1007d33483279a9430b9d17b2e9b6ff5aa1afbfcf0.exe,26,Blocked ;修改受保护的注册表键值 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,WDNMD)
复制代码
国人写的? |