某工具记录得还行
PID: 1768, 0x7D5BF51A: RegCreateKeyExW(key: HKEY_CURRENT_USER, subkey: Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders) -> SUCCESS
PID: 1768, --- handle: 0000076C
PID: 1768, 0x7D5F9C96: GetFileAttributesW(C:\Documents and Settings\Administrator\Local Settings\Application Data)
PID: 1768, 0x7D5BF51A: RegCreateKeyExW(key: HKEY_CURRENT_USER, subkey: Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders) -> SUCCESS
PID: 1768, --- handle: 0000076C
PID: 1768, 0x7D5F9CFF: RegSetValueExW(keyHandle: 0000076C, valueName: Local AppData, data: C:\Documents and Settings\Administrator\Local Settings\Application Data) -> SUCCESS
PID: 1768, 0x00402ACF: CreateFileW(file: C:\Documents and Settings\Administrator\Local Settings\Application Data\S-1-5-31-1286970278978-5713669491-166975984-320, OPEN_EXISTING)
PID: 1768, -- CreateFileW result - fHandle: FFFFFFFF
PID: 1768, 0x00402B0A: SetFileAttributesW(file: C:\Documents and Settings\Administrator\Local Settings\Application Data\S-1-5-31-1286970278978-5713669491-166975984-320, attrs: 00000007)
PID: 1768, 0x00402B87: CreateFileW(file: C:\WINDOWS\system32\KERNEL32.DLL, OPEN_EXISTING)
PID: 1768, -- CreateFileW result - fHandle: 00000768
PID: 1768, 0x00402BC4: SetFileTime(h: 0000076C)
PID: 1768, 0x00402ACF: CreateFileW(file: C:\Documents and Settings\Administrator\Local Settings\Application Data\S-1-5-31-1286970278978-5713669491-166975984-320\dmc, OPEN_EXISTING)
PID: 1768, -- CreateFileW result - fHandle: FFFFFFFF
PID: 1768, 0x00402B0A: SetFileAttributesW(file: C:\Documents and Settings\Administrator\Local Settings\Application Data\S-1-5-31-1286970278978-5713669491-166975984-320\dmc, attrs: 00000007)
PID: 1768, 0x00402B87: CreateFileW(file: C:\WINDOWS\system32\KERNEL32.DLL, OPEN_EXISTING)
PID: 1768, -- CreateFileW result - fHandle: 00000768
PID: 1768, 0x00402BC4: SetFileTime(h: 0000076C)
PID: 1768, 0x00402ACF: CreateFileW(file: C:\Documents and Settings\Administrator\Local Settings\Application Data\S-1-5-31-1286970278978-5713669491-166975984-320\tlsr, OPEN_EXISTING)
PID: 1768, -- CreateFileW result - fHandle: FFFFFFFF
PID: 1768, 0x00402B0A: SetFileAttributesW(file: C:\Documents and Settings\Administrator\Local Settings\Application Data\S-1-5-31-1286970278978-5713669491-166975984-320\tlsr, attrs: 00000007)
PID: 1768, 0x00402B87: CreateFileW(file: C:\WINDOWS\system32\KERNEL32.DLL, OPEN_EXISTING)
PID: 1768, -- CreateFileW result - fHandle: 00000768
PID: 1768, 0x00402BC4: SetFileTime(h: 0000076C)
PID: 1768, 0x00402ACF: CreateFileW(file: C:\Documents and Settings\Administrator\Local Settings\Application Data\S-1-5-31-1286970278978-5713669491-166975984-320\Rotinom, OPEN_EXISTING)
PID: 1768, -- CreateFileW result - fHandle: FFFFFFFF
PID: 1768, 0x00402B0A: SetFileAttributesW(file: C:\Documents and Settings\Administrator\Local Settings\Application Data\S-1-5-31-1286970278978-5713669491-166975984-320\Rotinom, attrs: 00000007)
PID: 1768, 0x00402B87: CreateFileW(file: C:\WINDOWS\system32\KERNEL32.DLL, OPEN_EXISTING)
PID: 1768, -- CreateFileW result - fHandle: 00000768
PID: 1768, 0x00402BC4: SetFileTime(h: 0000076C)
PID: 1768, 0x004022B5: RegOpenKeyExW(key: HKEY_CURRENT_USER, subkey: Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced) -> SUCCESS
PID: 1768, --- handle: 0000076C
PID: 1768, 0x00402319: RegSetValueExW(keyHandle: 0000076C, valueName: Hidden, data: ) -> SUCCESS
PID: 1768, 0x00402373: RegSetValueExW(keyHandle: 0000076C, valueName: HideFileExt, data: ) -> SUCCESS
PID: 1768, 0x004023E3: RegSetValueExW(keyHandle: 0000076C, valueName: ShowSuperHidden, data: ) -> SUCCESS
PID: 1768, 0x00402443: RegSetValueExW(keyHandle: 0000076C, valueName: WebViewBarricade, data: ) -> SUCCESS
PID: 1768, 0x004027F3: SetFileAttributesW(file: C:\Documents and Settings\Administrator\Local Settings\Application Data\Start, attrs: 00000007)
PID: 1768, 0x0040280D: CreateFileW(file: C:\Documents and Settings\Administrator\Local Settings\Application Data\Start, OPEN_EXISTING)
PID: 1768, -- CreateFileW result - fHandle: FFFFFFFF
PID: 1768,
PID: 1768, 0x00402896: CreateFileW(file: C:\Documents and Settings\Administrator\Local Settings\Application Data\Start\update.exe, OPEN_EXISTING)
PID: 1768, -- CreateFileW result - fHandle: 00000768
PID: 1768, 0x004028B6: SetFileTime(h: 00000768)
PID: 1768, 0x004028DA: RegOpenKeyExW(key: HKEY_CURRENT_USER, subkey: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders) -> SUCCESS
PID: 1768, --- handle: 00000768
PID: 1768, 0x0040298F: RegSetValueExW(keyHandle: 00000768, valueName: Startup, data: C:\Documents and Settings\Administrator\Local Settings\Application Data\Start) -> SUCCESS
PID: 1768, 0x004029B1: RegOpenKeyExW(key: HKEY_CURRENT_USER, subkey: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders) -> SUCCESS
PID: 1768, --- handle: 00000768
PID: 1768, 0x00402A4F: RegSetValueExW(keyHandle: 00000768, valueName: Startup, data: C:\Documents and Settings\Administrator\Local Settings\Application Data\Start) -> SUCCESS
PID: 1768, 0x00402CB3: CreateFileW(file: \\.\C:, OPEN_EXISTING)
PID: 1768, -- CreateFileW result - fHandle: 00000768
PID: 1768,
PID: 1768,
PID: 1768, 0x00402CB3: CreateFileW(file: \\.\C:, OPEN_EXISTING)
PID: 1768, -- CreateFileW result - fHandle: 000006F4
PID: 1768, 0x004035AA: CreateMutexW(name: LDLLMAIN, owner: 00000000)
PID: 1768, 0x00403B17: RegOpenKeyExW(key: HKEY_LOCAL_MACHINE, subkey: SYSTEM\CurrentControlSet\Services\USBSTOR\Enum) -> FAIL
PID: 1768, 0x00403B17: RegOpenKeyExW(key: HKEY_LOCAL_MACHINE, subkey: SYSTEM\CurrentControlSet\Services\USBSTOR\Enum) -> FAIL
PID: 1768, 0x00403B17: RegOpenKeyExW(key: HKEY_LOCAL_MACHINE, subkey: SYSTEM\CurrentControlSet\Services\USBSTOR\Enum) -> FAIL |