File behavior |
Behavior description: | 写权限映射文件 |
details: | CiceroSharedMemDefaultS-* |
| MSCTF.MarshalInterface.FileMap.MDC..KDDHH |
| MSCTF.MarshalInterface.FileMap.MDC.B.KDDHH |
| MSCTF.MarshalInterface.FileMap.MDC.C.KDDHH |
| MSCTF.MarshalInterface.FileMap.MDC.D.KDDHH |
| MSCTF.MarshalInterface.FileMap.MDC.E.KDDHH |
| MSCTF.MarshalInterface.FileMap.MDC.F.KDDHH |
| MSCTF.MarshalInterface.FileMap.MDC.G.KDDHH |
| MSCTF.Shared.SFM.MDC |
| MSCTF.MarshalInterface.FileMap.MDC.H.BGILH |
| MSCTF.MarshalInterface.FileMap.MDC.I.AHILH |
| MSCTF.MarshalInterface.FileMap.MDC.J.AHILH |
| MSCTF.MarshalInterface.FileMap.MDC.K.AHILH |
| MSCTF.MarshalInterface.FileMap.MDC.L.AIILH |
| MSCTF.MarshalInterface.FileMap.MDC.M.AIILH |
Behavior description: | 重命名文件 |
details: | C:\Program Files\KMSpico\is-GMG30.tmp ---> C:\Program Files\KMSpico\unins000.exe |
| C:\Program Files\KMSpico\is-VGEH8.tmp ---> C:\Program Files\KMSpico\AutoPico.exe |
| C:\Program Files\KMSpico\is-USB9K.tmp ---> C:\Program Files\KMSpico\DevComponents.DotNetBar2.dll |
| C:\Program Files\KMSpico\is-G3PPQ.tmp ---> C:\Program Files\KMSpico\Vestris.ResourceLib.dll |
| C:\WINDOWS\system32\is-533Q1.tmp ---> C:\WINDOWS\system32\Vestris.ResourceLib.dll |
| C:\Program Files\KMSpico\is-CP57D.tmp ---> C:\Program Files\KMSpico\KMSELDI.exe |
| C:\Program Files\KMSpico\is-CR17F.tmp ---> C:\Program Files\KMSpico\Service_KMS.exe |
| C:\Program Files\KMSpico\is-JBTQ3.tmp ---> C:\Program Files\KMSpico\UninsHs.exe |
| C:\Program Files\KMSpico\cert\is-Q07ID.tmp ---> C:\Program Files\KMSpico\cert\installAll.cmd |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-386K7.tmp ---> C:\Program Files\KMSpico\cert\kmscert2010\Access\AccessVLReg32.reg |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-KCH6H.tmp ---> C:\Program Files\KMSpico\cert\kmscert2010\Access\AccessVLReg64.reg |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-51QGC.tmp ---> C:\Program Files\KMSpico\cert\kmscert2010\Access\AccessVLRegWOW.reg |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-60N8R.tmp ---> C:\Program Files\KMSpico\cert\kmscert2010\Access\Access_KMS_Client.OOB.xrm-ms |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-OGM7E.tmp ---> C:\Program Files\KMSpico\cert\kmscert2010\Access\Access_KMS_Client.PL.xrm-ms |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-GO4LI.tmp ---> C:\Program Files\KMSpico\cert\kmscert2010\Access\Access_KMS_Client.PPDLIC.xrm-ms |
Behavior description: | 创建可执行文件 |
details: | C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-S2MC7.tmp\KMSpico_setup.tmp |
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-I579Q.tmp\_isetup\_shfoldr.dll |
| C:\Program Files\KMSpico\is-GMG30.tmp |
| C:\Program Files\KMSpico\is-VGEH8.tmp |
| C:\Program Files\KMSpico\is-USB9K.tmp |
| C:\Program Files\KMSpico\is-G3PPQ.tmp |
| C:\WINDOWS\system32\is-533Q1.tmp |
| C:\Program Files\KMSpico\is-CP57D.tmp |
| C:\Program Files\KMSpico\is-CR17F.tmp |
| C:\Program Files\KMSpico\is-JBTQ3.tmp |
Behavior description: | 修改文件内容 |
details: | C:\Program Files\KMSpico\cert\is-Q07ID.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-386K7.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-KCH6H.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-51QGC.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-60N8R.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-OGM7E.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-GO4LI.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-HGN6E.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Access\is-JUFE4.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Excel\is-RSQKO.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Excel\is-4SKN8.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Excel\is-FD9A0.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Excel\is-K6J6V.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Excel\is-JARK0.tmp---> Offset = 0 |
| C:\Program Files\KMSpico\cert\kmscert2010\Excel\is-A102E.tmp---> Offset = 0 |
Behavior description: | 查找文件 |
details: | FileName = C:\DOCUME~1 |
| FileName = C:\DOCUME~1\ADMINI~1 |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1 |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-S2MC7.tmp |
| FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-S2MC7.tmp\KMSpico_setup.tmp |
| FileName = C:\Documents and Settings |
| FileName = C:\Documents and Settings\Administrator |
| FileName = C:\Documents and Settings\Administrator\「开始」菜单 |
| FileName = C:\Documents and Settings\Administrator\「开始」菜单\程序 |
| FileName = C:\*.* |
| FileName = C:\Program Files\KMSpico\unins???.* |