好友
阅读权限10
听众
最后登录1970-1-1
|
楼主|
吾爱及我爱
发表于 2020-3-17 12:43
哈勃的也查了下
关键行为
行为描述: 常规加载驱动
详情信息:
\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~1457785686673182650\kerneld.x32
\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AIDA64Driver.sys
行为描述: 直接获取CPU时钟
详情信息:
EAX = 0xf4ad6c13, EDX = 0x000000c7
EAX = 0x7da98323, EDX = 0x000000c8
行为描述: 获取TickCount值
详情信息:
TickCount = 223501, SleepMilliseconds = 1.
TickCount = 223516, SleepMilliseconds = 1.
TickCount = 241329, SleepMilliseconds = 1.
TickCount = 241360, SleepMilliseconds = 1.
TickCount = 241422, SleepMilliseconds = 1.
TickCount = 241438, SleepMilliseconds = 1.
TickCount = 242219, SleepMilliseconds = 1.
TickCount = 243219, SleepMilliseconds = 1.
TickCount = 244219, SleepMilliseconds = 1.
TickCount = 245235, SleepMilliseconds = 1.
TickCount = 246251, SleepMilliseconds = 1.
TickCount = 247251, SleepMilliseconds = 1.
TickCount = 248266, SleepMilliseconds = 1.
TickCount = 249282, SleepMilliseconds = 1.
TickCount = 250297, SleepMilliseconds = 1.
行为描述: 设置特殊文件夹属性
详情信息:
C:\Documents and Settings\Administrator\Local Settings\Temp\~8780002509039237184~
行为描述: 直接调用系统关键API
详情信息:
Index = 0x0000009A, Name: NtQueryInformationProcess, Instruction Address = 0x00404A46
行为描述: 创建系统服务
详情信息:
[服务创建成功]: AIDA64Driver, C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~1457785686673182650\kerneld.x32
[服务创建成功]: AIDA64Driver, C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AIDA64Driver.sys
看不太懂啊 能给解析下吗 |
|