| Time & API |
Arguments |
Status |
Return |
Repeated |
1619910853.530372
WriteConsoleA
|
buffer:
Usage:
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619910853.530372
WriteConsoleA
|
buffer:
DRview [-help] [-pid n] [-exe name] [-listdr] [-listall] [-listdlls] [-showdlls] [-nopid] [-no32] [-out file] [-cmdline] [-showmem] [-showtime] [-nobuildnum] [-qname strip] [-noqnames] [-hot_patch] [-s n] [-tillidle] [-idlecpu c] [-showmemfreq f] [-idleafter s] [-v]
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619935750.662625
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.662625
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.662625
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.725625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.756625
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619935750.756625
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.772625
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.772625
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.772625
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.772625
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.803625
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.803625
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.803625
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.819625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.834625
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619935750.834625
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.834625
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.834625
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.834625
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.834625
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.850625
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.850625
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.850625
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.865625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.865625
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619935750.865625
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.881625
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.881625
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.881625
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.881625
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.881625
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.881625
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.881625
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.897625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.912625
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619935750.912625
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.928625
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.928625
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.928625
WriteConsoleW
|
buffer:
goto
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.928625
WriteConsoleW
|
buffer:
:DELFILE
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.944625
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.944625
WriteConsoleW
|
buffer:
del
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.959625
WriteConsoleW
|
buffer:
"C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.990625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935750.990625
WriteConsoleW
|
buffer:
拒绝访问。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1619935751.006625
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935751.006625
WriteConsoleW
|
buffer:
if
console_handle:
0x00000007
|
success
|
1 |
0
|
1619935751.006625
WriteConsoleW
|
buffer:
exist "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\FTngrh.exe"
console_handle:
0x00000007
|
success
|
1 |
0
|