文件行为 |
行为描述: | 创建文件 |
详细信息: | C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe |
| C:\ Program Files \ Microsoft \ px3.tmp |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe |
| C:\ Program Files \ Internet Explorer \ dmlconf.dat |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ RecoveryStore。{C6E44272-60E4-11E9-91C0-7B **** 28} .dat |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \〜DF267.tmp |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ {C6E44273-60E4-11E9-91C0-7B **** 28} .dat |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \〜DFFEB.tmp |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Internet临时文件\ Content.IE5 \ C1OS62RY \ yixun_com [1] |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Internet临时文件\ Content.IE5 \ C1OS62RY \ favicon [1] .ico |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Services \ search_ {0633EE93-D776-472f-A0FF-E1416B8B2E3A} .ico |
行为描述: | 修改原系统的EXE文件 |
详细信息: | C:\ Documents and Settings \ Administrator \ Application Data \ SogouExplorer \ Extension \ com.sogou.snapTaker \ 0.4.2 \ npprintscreen.dll |
行为描述: | 创建重新文件 |
详细信息: | C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Services \ search_ {0633EE93-D776-472f-A0FF-E1416B8B2E3A} .ico |
行为描述: | 覆盖现有文件 |
详细信息: | C:\ Program Files \ Microsoft \ px3.tmp |
| C:\ Program Files \ Internet Explorer \ dmlconf.dat |
行为描述: | 复制文件 |
详细信息: | C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe ---> C:\ Program Files \ Microsoft \ DesktopLayer.exe |
行为描述: | 内存映射方式修改重组文件 |
详细信息: | C:\ Documents and Settings \ Administrator \ Application Data \ SogouExplorer \ Extension \ com.sogou.snapTaker \ 0.4.2 \ npprintscreen.dll |
行为描述: | 删除文件 |
详细信息: | C:\ Program Files \ Microsoft \ px3.tmp |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \〜DF267.tmp |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \〜DFFEB.tmp |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Internet临时文件\ Content.IE5 \ C1OS62RY \ favicon [1] .ico |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Services \ search_ {0633EE93-D776-472f-A0FF-E1416B8B2E3A} .ico |
行为描述: | 发现文件 |
详细信息: | FileName = C:\ Documents and Settings \ Administrator \ Local Settings \ Temp |
| FileName = C:\ Documents and Settings \ Administrator \ Local Settings \%temp% |
| FileName = C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe |
| FileName = C:\ Program Files \ Internet Explorer \ IEXPLORE.EXE |
| FileName = C:\ Program Files \ Internet Explorer \ iexplore.exe |
| FileName = C:\ *。* |
| 文件名= C:\ 222c25ed \ *。* |
| 文件名= C:\ 222c25ed \ IE8-Setup-Full \ *。* |
| FileName = C:\ 222c25ed \ IE8-Setup-Full \ log \ *。* |
| FileName = C:\ AnalyzeControl \ *。* |
| FileName = C:\ DiskD \ *。* |
| FileName = C:\ DiskX \ *。* |
| FileName = C:\ DiskX \ RECYCLER \ *。* |
| FileName = C:\ Documents and Settings \ *。* |
| FileName = C:\ Documents and Settings \ Administrator \ *。* |
行为描述: | 设置特殊文件夹属性 |
详细信息: | C:\ DiskX \ RECYCLER |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Internet临时文件 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Internet临时文件\ Content.IE5 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ History |
| C:\ Documents and Settings \ Administrator \ Local Settings \ History \ History.IE5 |
| C:\ Documents and Settings \ Administrator \ Cookies |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Feeds \ {5588ACFD-6436-411B-A5CE-666AE6A92D3D}〜\ WebSlices〜 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Feed \ {5588ACFD-6436-411B-A5CE-666AE6A92D3D}〜 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Feeds缓存 |
| C:\ Documents and Settings \ Administrator \ IECompatCache |
行为描述: | 修改文件内容 |
详细信息: | C:\ Documents and Settings \ Administrator \ Local Settings \%temp%\ 996ESrv.exe --->偏移= 0 |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe --->偏移= 0 |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe --->偏移= 4096 |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe --->偏移= 8192 |
| C:\ Program Files \ Microsoft \ DesktopLayer.exe --->偏移= 12288 |
| C:\ Program Files \ Internet Explorer \ dmlconf.dat --->偏移= 0 |
| C:\ Documents and Settings \ Administrator \ Application Data \ SogouExplorer \ Extension \ com.sogou.privateSurf \ 0.0.0.1 \ backgroundpage.html --->偏移= 2787 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ RecoveryStore。{C6E44272-60E4-11E9-91C0-7B **** 28} .dat --->偏移= 512 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ RecoveryStore。{C6E44272-60E4-11E9-91C0-7B **** 28} .dat --->偏移= 0 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \〜DF267.tmp --->偏移= 16383 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Temp \〜DF267.tmp --->偏移= 12288 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ RecoveryStore。{C6E44272-60E4-11E9-91C0-7B **** 28} .dat --->偏移= 3072 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ RecoveryStore。{C6E44272-60E4-11E9-91C0-7B **** 28} .dat --->偏移= 1536 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ {C6E44273-60E4-11E9-91C0-7B **** 28} .dat ---> Offset = 512 |
| C:\ Documents and Settings \ Administrator \ Local Settings \ Application Data \ Microsoft \ Internet Explorer \ Recovery \ Active \ {C6E44273-60E4-11E9-91C0-7B **** 28} .dat --->偏移= 0 |