| Time & API |
Arguments |
Status |
Return |
Repeated |
1620026950.85475
WriteConsoleW
|
buffer:
描述:
在注册表和服务数据库中修改服务项。
用法:
sc <server> config [service name] <option1> <option2>...
选项:
注意: 选项名称包括等号。
等号和值之间需要一个空格。
type= <own|share|interact|kernel|filesys|rec|adapt>
start= <boot|system|auto|demand|disabled|delayed-auto>
error= <normal|severe|critical|ignore>
binPath= <BinaryPathName>
group= <LoadOrderGroup>
tag= <yes|no>
depend= <依存关系(以 / (斜杠) 分隔)>
obj= <AccountName|ObjectName>
DisplayName= <显示名称>
password= <密码>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026950.948502
WriteConsoleW
|
buffer:
[SC] DeleteService 成功
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026951.838375
WriteConsoleW
|
buffer:
发生系统错误 1726。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1620026951.838375
WriteConsoleW
|
buffer:
远程过程调用失败。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1620026951.83925
WriteConsoleW
|
buffer:
[SC] OpenService 失败 1060:
指定的服务未安装。
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026951.917
WriteConsoleW
|
buffer:
服务名无效。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1620026951.949
WriteConsoleW
|
buffer:
请键入 NET HELPMSG 2185 以获得更多的帮助。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1620026953.573502
WriteConsoleW
|
buffer:
[SC] OpenService 失败 1060:
指定的服务未安装。
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026955.058125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026955.058125
WriteConsoleW
|
buffer:
sc
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026955.089125
WriteConsoleW
|
buffer:
config Schedule start= auto
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026958.636125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026958.636125
WriteConsoleW
|
buffer:
sc
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026958.636125
WriteConsoleW
|
buffer:
start Schedule
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026959.683125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026959.683125
WriteConsoleW
|
buffer:
schtasks
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026959.699125
WriteConsoleW
|
buffer:
/delete /tn AutoKMSK /f
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026962.417125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026962.417125
WriteConsoleW
|
buffer:
schtasks
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026962.417125
WriteConsoleW
|
buffer:
/delete /tn AutoKMSKK /f
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026963.730125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026963.730125
WriteConsoleW
|
buffer:
schtasks
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026963.730125
WriteConsoleW
|
buffer:
/delete /tn "Adobe Flash Player Updaters" /f
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026965.808125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026965.824125
WriteConsoleW
|
buffer:
schtasks
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026965.824125
WriteConsoleW
|
buffer:
/create /sc minute /mo 10 /tn "\Microsoft\Windows\UPnP\AutoKMSK" /tr "C:\Windows\Installer\conhost.exe" /ru "system" /f
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026970.542125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026970.558125
WriteConsoleW
|
buffer:
schtasks
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026970.558125
WriteConsoleW
|
buffer:
/run /tn "\Microsoft\Windows\UPnP\AutoKMSK"
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026972.042125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026972.042125
WriteConsoleW
|
buffer:
schtasks
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026972.042125
WriteConsoleW
|
buffer:
/create /sc minute /mo 35 /tn "\Microsoft\Windows\UPnP\AutoKMSKK" /tr "C:\Windows\Installer\free.bat" /ru "system" /f
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026974.480125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026974.480125
WriteConsoleW
|
buffer:
sc
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026974.480125
WriteConsoleW
|
buffer:
start PolicyAgent
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026975.496125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026975.496125
WriteConsoleW
|
buffer:
sc
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026975.496125
WriteConsoleW
|
buffer:
config PolicyAgent start= AUTO
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026976.355125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026976.355125
WriteConsoleW
|
buffer:
netsh
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026976.355125
WriteConsoleW
|
buffer:
ipsec static add policy name=Aliyun
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026980.964125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026980.964125
WriteConsoleW
|
buffer:
netsh
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026980.964125
WriteConsoleW
|
buffer:
ipsec static add filterlist name=Allowlist
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026984.417125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026984.417125
WriteConsoleW
|
buffer:
netsh
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026984.417125
WriteConsoleW
|
buffer:
ipsec static add filterlist name=denylist
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026987.917125
WriteConsoleW
|
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp>
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026987.949125
WriteConsoleW
|
buffer:
netsh
console_handle:
0x00000007
|
success
|
1 |
0
|
1620026987.964125
WriteConsoleW
|
buffer:
ipsec static add filter filterlist=denylist srcaddr=any dstaddr=me description=not protocol=tcp mirrored=yes dstport=135
console_handle:
0x00000007
|
success
|
1 |
0
|