日期和时间 | 应用程序 | 行为 | 目标 |
2022-05-14 11:09:56 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 修改文件 | C:\Users\Administrator\AppData\Local\Temp\MSI9f67c.LOG |
2022-05-14 11:09:51 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 修改文件 | C:\Users\Administrator\AppData\Local\Temp\MSI9f67c.LOG |
2022-05-14 11:09:43 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 修改文件 | C:\Users\Administrator\AppData\Local\Temp\MSI9f67b.LOG |
2022-05-14 11:09:33 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 修改文件 | C:\Users\Administrator\AppData\Local\Temp\MSI9f67b.LOG |
2022-05-14 11:09:28 | C:\Windows\System32\msiexec.exe | 修改文件 | C:\Windows\Installer\SourceHash{5A2F4D37-FBA4-45A8-9319-733FF36EF441} |
2022-05-14 11:09:16 | C:\Windows\System32\msiexec.exe | 修改文件 | C:\Windows\Installer\SourceHash{5A2F4D37-FBA4-45A8-9319-733FF36EF441} |
2022-05-14 11:09:16 | C:\Windows\System32\msiexec.exe | 访问内存 | C:\Program Files\COMODO\COMODO Internet Security\cis.exe |
2022-05-14 11:09:13 | C:\Windows\System32\msiexec.exe | 创建进程 | C:\Windows\System32\msiexec.exe |
2022-05-14 11:09:10 | C:\Windows\System32\msiexec.exe | 修改文件 | C:\Windows\Installer\MSI7946.tmp |
2022-05-14 11:09:07 | C:\Windows\System32\msiexec.exe | 修改文件 | C:\Windows\Temp\~DF09110C799C15BBF3.TMP |
2022-05-14 11:09:04 | C:\Windows\System32\msiexec.exe | 修改文件 | C:\Windows\Installer\inprogressinstallinfo.ipi |
2022-05-14 11:09:02 | C:\Windows\System32\msiexec.exe | 修改注册表项 | HKLM\SYSTEM\ControlSet001\Services\VSS\Diag |
2022-05-14 11:09:00 | C:\Windows\System32\msiexec.exe | 修改文件 | C:\Windows\Installer |
2022-05-14 11:08:56 | C:\Windows\System32\msiexec.exe | 修改文件 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log |
2022-05-14 11:08:50 | C:\Windows\System32\msiexec.exe | 修改文件 | C:\Windows\Installer\a2d0a.msi |
2022-05-14 11:08:49 | C:\Windows\System32\msiexec.exe | 修改注册表项 | HKLM\SYSTEM\ControlSet001\Services\VSS |
2022-05-14 11:08:47 | C:\Windows\System32\msiexec.exe | 修改注册表项 | HKLM\SYSTEM\ControlSet001\Services\VSS\Diag |
2022-05-14 11:08:46 | C:\Windows\System32\msiexec.exe | 修改注册表项 | HKLM\SYSTEM\ControlSet001\Services\VSS |
2022-05-14 11:08:41 | C:\Windows\System32\msiexec.exe | 修改注册表项 | HKLM\SYSTEM\ControlSet001\Services\VSS\Diag |
2022-05-14 11:08:37 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | LocalSecurityAuthority.SystemEnvironment |
2022-05-14 11:08:36 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 修改文件 | C:\MSI9f679.tmp |
2022-05-14 11:08:34 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | LocalSecurityAuthority.Restore |
2022-05-14 11:08:32 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | LocalSecurityAuthority.SystemEnvironment |
2022-05-14 11:08:31 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | LocalSecurityAuthority.Backup |
2022-05-14 11:08:29 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | LocalSecurityAuthority.Restore |
2022-05-14 11:08:28 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | LocalSecurityAuthority.SystemTime |
2022-05-14 11:08:25 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | LocalSecurityAuthority.Backup |
2022-05-14 11:08:22 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | LocalSecurityAuthority.Tcb |
2022-05-14 11:08:21 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | LocalSecurityAuthority.SystemTime |
2022-05-14 11:08:17 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | LocalSecurityAuthority.Tcb |
2022-05-14 11:08:14 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | C:\Windows\System32\msiexec.exe |
2022-05-14 11:08:09 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | IMsiServer |
2022-05-14 11:08:05 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 修改文件 | \Device\MountPointManager |
2022-05-14 11:08:04 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | LocalSecurityAuthority.Shutdown |
2022-05-14 11:08:00 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 访问COM接口 | LocalSecurityAuthority.Shutdown |
2022-05-14 11:07:54 | C:\Users\Administrator\Desktop\Magniber五一最新样本.msi | 安装钩子 | C:\Windows\System32\MSCTF.dll
|