| Time & API |
Arguments |
Status |
Return |
Repeated |
1619871198.7825
WriteConsoleA
|
buffer:
Usage:
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619871198.7825
WriteConsoleA
|
buffer:
DRkill [-help] [-quiet] [-pid n] [-exe name] [-underdr] [-v]
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619871214.39175
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.39175
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.39175
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.40775
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.42275
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619871214.42275
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.42275
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.42275
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.42275
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.42275
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.42275
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.42275
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.42275
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.42275
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.42275
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.43875
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.45475
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.45475
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.45475
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619871214.45475
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.45475
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.45475
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.45475
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.45475
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.45475
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.45475
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.45475
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.46975
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.46975
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619871214.46975
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.46975
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619871214.46975
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\QXLDHQ.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|