关键行为 |
行为描述: | 修改原系统的EXE文件 |
详细信息: | C:\ Documents and Settings \ Administrator \ Application Data \ SogouExplorer \ Extension \ com.sogou.snapTaker \ 0.4.2 \ npprintscreen.dll |
行为描述: | 设置特殊文件夹属性 |
详细信息: | C:\ DiskX \ RECYCLER |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Internet临时文件 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Internet临时文件\ Content.IE5 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ History |
| C:\ Documents and Settings \ Administrator \ Local Settings \ History \ History.IE5 |
| C:\ Documents and Settings \ Administrator \ Cookies |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Feeds \ {5588ACFD-6436-411B-A5CE-666AE6A92D3D}〜\ WebSlices〜 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Feed \ {5588ACFD-6436-411B-A5CE-666AE6A92D3D}〜 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Feeds缓存 |
| C:\ Documents and Settings \ Administrator \ IECompatCache |
行为描述: | 发现文件方式探测虚拟机 |
详细信息: | FindFirstFileEx:FileName = C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ VMware \ *。* |
| FindFirstFileEx:FileName = C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \ VMwareDnD \ *。* |
行为描述: | 修改注册表_启动项 |
详细信息: | \ REGISTRY \ MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Userinit |
进步行为 |
行为描述: | 创建进程 |
详细信息: | [0x00000a68] ImagePath = C:\ Program Files \ Internet Explorer \ iexplore.exe,CmdLine =“ C:\ Program Files \ Internet Explorer \ IEXPLORE.EXE” |
| [0x00000b18] ImagePath = C:\ Program Files \ Internet Explorer \ iexplore.exe,CmdLine =“ C:\ Program Files \ Internet Explorer \ IEXPLORE.EXE” SCODEF:2772 CREDAT:79873 |
行为描述: | 创建新文件进程 |
详细信息: | [0x00000a1c] ImagePath = C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe,CmdLine =“ C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe” |
| [0x00000a5c] ImagePath = C:\ Program Files \ Microsoft \ DesktopLayer.exe,CmdLine =“ C:\ Program Files \ Microsoft \ DesktopLayer.exe” |
行为描述: | 枚举进展 |
详细信息: | 不适用 |
行为描述: | 创建本地线程 |
详细信息: | TargetProcess:iexplore.exe,InheritedFromPID = 2652,ProcessID = 2664,ThreadID = 2672,StartAddress = 20057ACA,参数= 00050034 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2652,ProcessID = 2664,ThreadID = 2676,StartAddress = 20057626,参数= 00000000 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2652,ProcessID = 2664,ThreadID = 2680,StartAddress = 2005781F,参数= 00000000 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2652,ProcessID = 2664,ThreadID = 2684,StartAddress = 2005790C,参数= 00000000 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2652,ProcessID = 2664,ThreadID = 2688,StartAddress = 20056EA8,参数= 00000000 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2652,ProcessID = 2664,ThreadID = 2692,StartAddress = 20056EC2,参数= 00000000 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2152,ProcessID = 2772,ThreadID = 2780,StartAddress = 77DC845A,参数= 00000000 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2152,ProcessID = 2772,ThreadID = 2808,StartAddress = 7C947EBB,参数= 00000000 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2152,ProcessID = 2772,ThreadID = 2812,StartAddress = 7C930230,参数= 00000000 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2152,ProcessID = 2772,ThreadID = 2816,StartAddress = 7C949B6F,参数= 00000000 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2152,ProcessID = 2772,ThreadID = 2820,StartAddress = 77E56C7D,参数= 001967A0 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2152,ProcessID = 2772,ThreadID = 2824,StartAddress = 5DE05ABD,参数= 001986F0 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2152,ProcessID = 2772,ThreadID = 2828,StartAddress = 5DE05BC0,参数= 00194100 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2152,ProcessID = 2772,ThreadID = 2832,StartAddress = 0122F74F,参数= 00000214 |
| TargetProcess:iexplore.exe,InheritedFromPID = 2772,ProcessID = 2840,ThreadID = 2848,StartAddress = 77DC845A,参数= 00000000 |
文件行为 |
行为描述: | 创建文件 |
详细信息: | C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe |
| C:\ Program Files \ Microsoft \ px3.tmp |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe |
| C:\ Program Files \ Internet Explorer \ dmlconf.dat |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ RecoveryStore。{C6E44272-60E4-11E9-91C0-7B **** 28} .dat |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \〜DF267.tmp |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ {C6E44273-60E4-11E9-91C0-7B **** 28} .dat |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \〜DFFEB.tmp |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Internet临时文件\ Content.IE5 \ C1OS62RY \ yixun_com [1] |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Internet临时文件\ Content.IE5 \ C1OS62RY \ favicon [1] .ico |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Services \ search_ {0633EE93-D776-472f-A0FF-E1416B8B2E3A} .ico |
行为描述: | 修改原系统的EXE文件 |
详细信息: | C:\ Documents and Settings \ Administrator \ Application Data \ SogouExplorer \ Extension \ com.sogou.snapTaker \ 0.4.2 \ npprintscreen.dll |
行为描述: | 创建重新文件 |
详细信息: | C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Services \ search_ {0633EE93-D776-472f-A0FF-E1416B8B2E3A} .ico |
行为描述: | 覆盖现有文件 |
详细信息: | C:\ Program Files \ Microsoft \ px3.tmp |
| C:\ Program Files \ Internet Explorer \ dmlconf.dat |
行为描述: | 复制文件 |
详细信息: | C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe ---> C:\ Program Files \ Microsoft \ DesktopLayer.exe |
行为描述: | 内存映射方式修改重组文件 |
详细信息: | C:\ Documents and Settings \ Administrator \ Application Data \ SogouExplorer \ Extension \ com.sogou.snapTaker \ 0.4.2 \ npprintscreen.dll |
行为描述: | 删除文件 |
详细信息: | C:\ Program Files \ Microsoft \ px3.tmp |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \〜DF267.tmp |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \〜DFFEB.tmp |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Internet临时文件\ Content.IE5 \ C1OS62RY \ favicon [1] .ico |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Services \ search_ {0633EE93-D776-472f-A0FF-E1416B8B2E3A} .ico |
行为描述: | 发现文件 |
详细信息: | FileName = C:\ Documents and Settings \ Administrator \ Local Settings \ Temp |
| FileName = C:\ Documents and Settings \ Administrator \ Local Settings \%temp% |
| FileName = C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe |
| FileName = C:\ Program Files \ Internet Explorer \ IEXPLORE.EXE |
| FileName = C:\ Program Files \ Internet Explorer \ iexplore.exe |
| FileName = C:\ *。* |
| 文件名= C:\ 222c25ed \ *。* |
| 文件名= C:\ 222c25ed \ IE8-Setup-Full \ *。* |
| FileName = C:\ 222c25ed \ IE8-Setup-Full \ log \ *。* |
| FileName = C:\ AnalyzeControl \ *。* |
| FileName = C:\ DiskD \ *。* |
| FileName = C:\ DiskX \ *。* |
| FileName = C:\ DiskX \ RECYCLER \ *。* |
| FileName = C:\ Documents and Settings \ *。* |
| FileName = C:\ Documents and Settings \ Administrator \ *。* |
行为描述: | 设置特殊文件夹属性 |
详细信息: | C:\ DiskX \ RECYCLER |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Internet临时文件 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Internet临时文件\ Content.IE5 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ History |
| C:\ Documents and Settings \ Administrator \ Local Settings \ History \ History.IE5 |
| C:\ Documents and Settings \ Administrator \ Cookies |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Feeds \ {5588ACFD-6436-411B-A5CE-666AE6A92D3D}〜\ WebSlices〜 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Feed \ {5588ACFD-6436-411B-A5CE-666AE6A92D3D}〜 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Feeds缓存 |
| C:\ Documents and Settings \ Administrator \ IECompatCache |
行为描述: | 修改文件内容 |
详细信息: | C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe --->偏移= 0 |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe --->偏移= 0 |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe --->偏移= 4096 |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe --->偏移= 8192 |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe --->偏移= 12288 |
| C:\ Program Files \ Internet Explorer \ dmlconf.dat --->偏移= 0 |
| C:\ Documents and Settings \ Administrator \ Application Data \ SogouExplorer \ Extension \ com.sogou.privateSurf \ 0.0.0.1 \ backgroundpage.html --->偏移= 2787 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ RecoveryStore。{C6E44272-60E4-11E9-91C0-7B **** 28} .dat --->偏移= 512 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ RecoveryStore。{C6E44272-60E4-11E9-91C0-7B **** 28} .dat --->偏移= 0 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \〜DF267.tmp --->偏移= 16383 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \〜DF267.tmp --->偏移= 12288 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ RecoveryStore。{C6E44272-60E4-11E9-91C0-7B **** 28} .dat --->偏移= 3072 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ RecoveryStore。{C6E44272-60E4-11E9-91C0-7B **** 28} .dat --->偏移= 1536 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ {C6E44273-60E4-11E9-91C0-7B **** 28} .dat ---> Offset = 512 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ {C6E44273-60E4-11E9-91C0-7B **** 28} .dat --->偏移= 0 |
网络行为 |
行为描述: | 下载文件 |
详细信息: | URLDownloadToFileW:http://ww****om/favicon.ico ---> C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Services \ search_ {0633EE93-D776-472f- A0FF-E1416B8B2E3A} .ico |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Services \ search_ {0633EE93-D776-472f-A0FF-E1416B8B2E3A} .ico |
行为描述: | 连接指定站点 |
详细信息: | InternetConnectA:ServerName = ww **** om,PORT = 80,UserName =,Password =,hSession = 0x00cc0004,hConnect = 0x00cc0008,标志= 0x00000000 |
| InternetConnectA:ServerName = ur **** om,PORT = 443,UserName =,密码=,hSession = 0x00cc0010,hConnect = 0x00cc0014,标志= 0x00000200 |
行为描述: | :HTTP连接 |
详细信息: | InternetOpenA:UserAgent:Mozilla / 4.0(兼容; MSIE 8.0; Windows NT 5.1; Trident / 4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4。 0E; KB974489),hSession = 0x00cc0004 |
| InternetOpenA:UserAgent:VCSoapClient,hSession = 0x00cc0010 |
行为描述: | 建立到一个指定的专有连接 |
详细信息: | 网址:go **** om,IP:**。133.40。**:80,SOCKET = 0x000000ac |
| URL:fg **** om,IP:**。133.40。**:443,SOCKET = 0x000000b0 |
| URL:ww **** om,IP:**。133.40。**:80,SOCKET = 0x00000458 |
| URL:ww **** om,IP:**。133.40。**:80,SOCKET = 0x00000594 |
| URL:ur **** om,IP:**。133.40。**:443,套接字= 0x0000059c |
行为描述: | 读取网络文件 |
详细信息: | hFile = 0x00cc000c,BytesToRead = 2048,BytesRead = 2048。 |
| hFile = 0x00cc0018,BytesToRead = 4095,BytesRead = 4095。 |
行为描述: | 发送HTTP包 |
详细信息: | GET / HTTP / 1.1接受:* / *接受语言:zh-cn用户代{过}{滤}理:Mozilla / 4.0(兼容; MSIE 8.0; Windows NT 5.1; Trident / 4.0; .NET CLR 2.0.50727; .NET CLR 3.0。 4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489)Accept-Encoding:gzip,deflate主机:ww **** om连接:保持活动 |
| GET /favicon.ico HTTP / 1.1接受:* / *接受编码:gzip,压缩用户代{过}{滤}理:Mozilla / 4.0(兼容; MSIE 8.0; Windows NT 5.1; Trident / 4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489)主机:ww **** om连接:保持活动 |
行为描述: | :HTTP请求 |
详细信息: | HttpOpenRequestA:ww **** om:80 /,hConnect = 0x00cc0008,hRequest = 0x00cc000c,Verb:GET,Referer:,标志= 0x00400200 |
| HttpOpenRequestA:ww **** om:80 / favicon.ico,hConnect = 0x00cc0008,hRequest = 0x00cc000c,动词:GET,引荐来源地址:,标志= 0x00600010 |
| HttpOpenRequestA:ur **** om:443 / urs.asmx?msurs-client-key = p3i7jxlvwuigv0czobly6q%3d%3d&msurs-patented-lock = tvphcosm2xa%3d,hConnect = 0x00cc0014,hRequest = 0x00cc0018,Verb:标志= 0x04880300 |
行为描述: | 按名称获取主机地址 |
详细信息: | gethostbyname:go **** om |
| gethostbyname:fg **** om |
| GetAddrInfoW:ww **** om |
| GetAddrInfoW:ur **** om |
宣传行为 |
行为描述: | 修改注册表 |
详细信息: | \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet设置\ Connections \ SavedLegacySettings |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ Internet Explorer \ Recovery \ Active \ {C6E44272-60E4-11E9-91C0-7B **** 28} |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ CTF \ TIP \ {1188450c-fdab-47ae-80d8-c9633f71be64} \ LanguageProfile \ 0x00000000 \ {63800dac-e7ca-4df9-9a5c-20765055488d} \启用 |
| \ REGISTRY \ MACHINE \ SOFTWARE \ Classes \ TypeLib \ {1EA4DBF0-3C3B-11CF-810C-00AA00389B71} \ 1.1 \ 0 \ win32 \ |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ Internet Explorer \ Main \ Window_Placement |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ Windows \ CurrentVersion \ Ext \ Stats \ {18DF081C-E8AD-4283-A596-FA578C2EBDC3} \ iexplore \ Count |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ Windows \ CurrentVersion \ Ext \ Stats \ {18DF081C-E8AD-4283-A596-FA578C2EBDC3} \ iexplore \ Time |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ Windows \ CurrentVersion \ Ext \ Stats \ {18DF081C-E8AD-4283-A596-FA578C2EBDC3} \ iexplore \ LoadTime |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ Windows \ CurrentVersion \ Ext \ Stats \ {18DF081C-E8AD-4283-A596-FA578C2EBDC3} \ iexplore \ LoadTimeCount |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ Windows \ CurrentVersion \ Ext \ Stats \ {DBC80044-A445-435B-BC74-9C25C1C588A9} \ iexplore \ Count |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ Windows \ CurrentVersion \ Ext \ Stats \ {DBC80044-A445-435B-BC74-9C25C1C588A9} \ iexplore \ Time |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} \ InprocServer32 \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} \ InprocServer32 \ ThreadingModel |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBB} \ |
行为描述: | 删除删除键值 |
详细信息: | \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet设置\ ProxyServer |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet设置\ ProxyOverride |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet设置\ AutoConfigURL |
行为描述: | 删除删除键 |
详细信息: | \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ CTF \ TIP \ {1188450c-fdab-47ae-80d8-c9633f71be64} \ LanguageProfile \ 0x00000000 \ {63800dac-e7ca-4df9-9a5c-20765055488d} \ |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ CTF \ TIP \ {1188450c-fdab-47ae-80d8-c9633f71be64} \ LanguageProfile \ 0x00000000 \ |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ CTF \ TIP \ {1188450c-fdab-47ae-80d8-c9633f71be64} \ LanguageProfile \ |
| \ REGISTRY \ USER \ S-* \ Software \ Microsoft \ CTF \ TIP \ {1188450c-fdab-47ae-80d8-c9633f71be64} \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} \ InprocServer32 \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBB} \ InprocServer32 \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBB} \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBC} \ InprocServer32 \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBC} \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA} \ InprocServer32 \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA} \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {8AD9C840-044E-11D1-B3E9-00805F499D93} \ InprocServer32 \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ CLSID \ {8AD9C840-044E-11D1-B3E9-00805F499D93} \ |
| \ REGISTRY \ USER \ S-* _ CLASSES \ JavaPlugin.1000 \ CLSID \ |
行为描述: | 修改注册表_启动项 |
详细信息: | \ REGISTRY \ MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Userinit |
其他行为 |
行为描述: | 创建互斥体 |
详细信息: | KyUffThOkYwRRtgPP |
| CTF.LBES.MutexDefaultS- * |
| CTF.Compart.MutexDefaultS- * |
| CTF.Asm.MutexDefaultS- * |
| CTF.Layouts.MutexDefaultS- * |
| CTF.TMD.MutexDefaultS- * |
| CTF.TimListCache.FMPDefaultS- * MUTEX.DefaultS- * |
| 本地\!浏览器仿真!共享内存!Mutex |
| Local \ ZoneAttributeCacheCounterMutex |
| 本地\ ZonesCacheCounterMutex |
| 本地\ ZonesLockedCacheCounterMutex |
| RasPb文件 |
| ConnHashTable <2772> _HashTable_Mutex |
| oleacc-msaa加载 |
| Local \ ZonesCounterMutex |
行为描述: | 隐藏指定窗口 |
详细信息: | [Window,Class] = [,BrowserFrameGripperClass] |
| [Window,Class] = [缩放等级,ToolbarWindow32] |
| [Window,Class] = [,msctls_progress32] |
| [Window,Class] = [,SysLink] |
| [Window,Class] = [,Static] |
| [Window,Class] = [文件大小未知,静态] |
| [Window,Class] = [http://www.yixun.com/-Windows Internet Explorer,IEFrame] |
| [Window,Class] = [,UniversalSearchBand] |
| [Window,Class] = [,TravelBand] |
| [Window,Class] = [,CommandBarClass] |
| [Window,Class] = [,ReBarWindow32] |
| [Window,Class] = [,TabBandClass] |
| [Window,Class] = [打开此类文件前总是询问(&W),Button] |
| [Window,Class] = [发布者:,静态] |
行为描述: | 修改后的重组文件MD5 |
详细信息: | C:\ Documents and Settings \ Administrator \ Application Data \ SogouExplorer \ Extension \ com.sogou.snapTaker \ 0.4.2 \ npprintscreen.dll ---> 0966f2da1a04c41b0db8980ab29c7a62 |
行为描述: | 调整进程令牌权限 |
详细信息: | SE_LOAD_DRIVER_PRIVILEGE |
行为描述: | :事件 |
详细信息: | \ SECURITY \ LSA_AUTHENTICATION_INITIALIZED |
| 隔离信号注册表事件(C6E4426F-60E4-11E9-91C0-7B **** 28,0) |
| 全局\ SvcctrlStartEvent_A3752DX |
| \ INSTALLATION_SECURITY_HOLD |
| MSFT.VSA.COM.DISABLE.2772 |
| MSFT.VSA.IEC.STATUS.6c736db0 |
| 隔离信号注册表事件(C6E44270-60E4-11E9-91C0-7B **** 28,0) |
| IE_EarlyTabStart_0xad8 |
| _fCanRegisterWithShellService |
| MSFT.VSA.COM.DISABLE.2840 |
| 本地\ RSS事件事件事件00000ad4 |
| 全局\ crypt32LogoffEvent |
| 本地\ b18_29 |
| CTF.ThreadMIConnectionEvent.000007E8.00000000.00000010 |
| CTF.ThreadMarshalInterfaceEvent.000007E8.00000000.00000010 |
行为描述: | 修改后的重组文件签名信息 |
详细信息: | C:\ Documents and Settings \ Administrator \ Application Data \ SogouExplorer \ Extension \ com.sogou.snapTaker \ 0.4.2 \ npprintscreen.dll(签名验证:未通过) |
行为描述: | 初始文件签名信息 |
详细信息: | C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe(签名验证:未通过) |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe(签名验证:未通过) |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Services \ search_ {0633EE93-D776-472f-A0FF-E1416B8B2E3A} .ico(签名验证:未通过) |
行为描述: | 创建事件对象 |
详细信息: | EventName =隔离信号注册表事件(C6E4426F-60E4-11E9-91C0-7B **** 28,0) |
| EventName = IE_EarlyTabStart_0xad8 |
| EventName =隔离信号注册表事件(C6E44270-60E4-11E9-91C0-7B **** 28,0) |
| EventName = DINPUTWINMM |
| EventName = Global \ userenv:用户配置文件设置事件 |
| EventName = Local \ RSS事件事件事件00000ad4 |
| EventName =本地\ b18_29 |
| EventName = IEFrame.EventCheckDefaultBrowser |
| EventName =全局\ crypt32LogoffEvent |
行为描述: | 初始化文件MD5 |
详细信息: | C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe ---> ff5e1f27193ce51eec318714ef038bef |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe ---> ff5e1f27193ce51eec318714ef038bef |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Services \ search_ {0633EE93-D776-472f-A0FF-E1416B8B2E3A} .ico ---> fe1d0ee5901dd167ee9b28eece31786c |
行为描述: | :互斥体 |
详细信息: | ShimCacheMutex |
| 本地\ _!MSFTHISTORY!_ |
| 本地\ c :!文档和设置管理员本地设置临时Internet文件content.ie5! |
| 本地\ c:文档和设置管理员cookie。 |
| 本地\ c:文档和设置管理员本地设置历史记录history.ie5! |
| 本地\ WininetStartupMutex |
| 本地\ WininetConnectionMutex |
| 本地\ WininetProxyRegistryMutex |
| 本地\!浏览器仿真!共享内存!Mutex |
| 本地\!IETld!Mutex |
| RasPb文件 |
| CtfmonInstMutexDefaultS- * |
| 本地\ RSS事件连接数据库互斥量00000ad4 |
| 本地\ c:文档和设置管理员本地设置应用程序数据Microsoft提要缓存! |
| 本地\!IECompat!Mutex |
行为描述: | 发现指定窗口 |
详细信息: | NtUserFindWindowEx:[Class,Window] = [Static,] |
| NtUserFindWindowEx:[Class,Window] = [Shell_TrayWnd,] |
| NtUserFindWindowEx:[Class,Window] = [MS_AutodialMonitor,] |
| NtUserFindWindowEx:[Class,Window] = [MS_WebCheckMonitor,] |
行为描述: | 发现文件方式探测虚拟机 |
详细信息: | FindFirstFileEx:FileName = C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ VMware \ *。* |
| FindFirstFileEx:FileName = C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \ VMwareDnD \ *。* |