| Time & API |
Arguments |
Status |
Return |
Repeated |
1619812595.858501
WriteConsoleA
|
buffer:
Usage:
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619812595.858501
WriteConsoleA
|
buffer:
DRkill [-help] [-quiet] [-pid n] [-exe name] [-underdr] [-v]
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619812607.374499
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.374499
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.374499
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.421499
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.467499
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619812607.467499
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.467499
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.467499
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.467499
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.467499
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.467499
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.467499
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.467499
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.467499
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.467499
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619812607.483499
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.483499
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.483499
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.483499
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.483499
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.483499
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.483499
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.483499
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.483499
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.499499
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619812607.499499
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.499499
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.499499
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.499499
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.499499
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.499499
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.499499
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.499499
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.514499
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.514499
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619812607.514499
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.514499
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.514499
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.514499
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.514499
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.514499
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.514499
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.514499
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.530499
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.530499
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619812607.530499
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.530499
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619812607.530499
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXHUXV.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|