| Time & API |
Arguments |
Status |
Return |
Repeated |
1619861115.409605
WriteConsoleA
|
buffer:
Usage:
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619861115.409605
WriteConsoleA
|
buffer:
DRkill [-help] [-quiet] [-pid n] [-exe name] [-underdr] [-v]
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619867623.497626
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.497626
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.497626
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.544626
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.559626
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619867623.575626
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.575626
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.575626
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.591626
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.591626
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.653626
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.653626
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.653626
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.684626
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.684626
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619867623.684626
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.684626
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.684626
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.684626
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.684626
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.700626
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.700626
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.700626
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.716626
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.716626
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619867623.731626
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.731626
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.747626
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.747626
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.747626
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.778626
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.778626
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.794626
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.809626
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.809626
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619867623.856626
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.872626
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.872626
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.888626
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.888626
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.919626
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.919626
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.934626
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.966626
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.966626
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619867623.981626
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.997626
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619867623.997626
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\lKJQWC.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|