| Time & API |
Arguments |
Status |
Return |
Repeated |
1619366951.332751
WriteConsoleW
|
buffer:
成功: 成功创建计划任务 "Updates\hzJupOEjGnFo"。
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.050001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.050001
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.050001
WriteConsoleW
|
buffer:
"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.082001
WriteConsoleW
|
buffer:
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.207001
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619366992.207001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.207001
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.207001
WriteConsoleW
|
buffer:
exist "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.207001
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.207001
WriteConsoleW
|
buffer:
ktk
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.222001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.222001
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.222001
WriteConsoleW
|
buffer:
"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.238001
WriteConsoleW
|
buffer:
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.238001
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619366992.238001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.238001
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.238001
WriteConsoleW
|
buffer:
exist "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.238001
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.238001
WriteConsoleW
|
buffer:
ktk
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.253001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.253001
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.253001
WriteConsoleW
|
buffer:
"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.253001
WriteConsoleW
|
buffer:
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.253001
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619366992.253001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.253001
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.253001
WriteConsoleW
|
buffer:
exist "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.253001
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.253001
WriteConsoleW
|
buffer:
ktk
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
exist "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
ktk
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.269001
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619366992.285001
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.285001
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.285001
WriteConsoleW
|
buffer:
exist "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619366992.285001
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|