File behavior |
Behavior description: | 写权限映射文件 |
details: | CiceroSharedMemDefaultS-* |
Behavior description: | 创建可执行文件 |
details: | C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM.exe |
Behavior description: | 修改文件内容 |
details: | C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\Acer.xrm-ms---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\Advent.XRM-MS---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\ALWARE.XRM-MS---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\ASUS.XRM-MS---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\Benq.xrm-ms---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\DELL.XRM-MS---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\FOUNDER.XRM-MS---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\FSC.XRM-MS---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\FUJITSU.XRM-MS---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\GIGABYTE.XRM-MS---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\HAIER.XRM-MS---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\HASEE.XRM-MS---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\HP.xrm-ms---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\LENOVO.xrm-ms---> Offset = 0 |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\LGE.xrm-ms---> Offset = 0 |
Behavior description: | 查找文件 |
details: | FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\1446029345.268934.exe_7zdump\Win7_OEMzsdrgj_veryhuo.com\Win7_OEM_Cert&SLP_Key_Importing_tools_v2.6.exe |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\Acer.xrm-ms |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\Advent.XRM-MS |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\ALWARE.XRM-MS |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\ASUS.XRM-MS |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\Benq.xrm-ms |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\DELL.XRM-MS |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\FOUNDER.XRM-MS |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\FSC.XRM-MS |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\FUJITSU.XRM-MS |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\GIGABYTE.XRM-MS |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\HAIER.XRM-MS |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\HASEE.XRM-MS |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7zS4.tmp\OEM\HP.xrm-ms |