| Time & API |
Arguments |
Status |
Return |
Repeated |
1619134510.552119
WriteConsoleA
|
buffer:
Usage:
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619134510.552119
WriteConsoleA
|
buffer:
DRkill [-help] [-quiet] [-pid n] [-exe name] [-underdr] [-v]
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619135819.898001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135819.898001
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135819.898001
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135819.992001
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.023001
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619135820.054001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.054001
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.054001
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.054001
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.054001
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.086001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.086001
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.086001
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.133001
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.148001
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619135820.164001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.164001
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.179001
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.179001
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.179001
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.226001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.242001
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.242001
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.289001
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.289001
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619135820.304001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.320001
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.320001
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.336001
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.336001
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.367001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.367001
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.383001
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.414001
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.414001
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619135820.429001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.445001
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.445001
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.445001
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.445001
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.476001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.476001
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.508001
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.586001
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.601001
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619135820.617001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.617001
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619135820.617001
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\IsbWmc.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|