文件行為 |
行為描述: | 创建文件 |
詳細信息: | C:\Users\Administrator\AppData\Local\Temp\WAX7A3B.tmp |
| C:\Users\Administrator\AppData\Local\Temp\WER7A4C.tmp |
| C:\Users\Administrator\AppData\Local\Temp\WER7A4C.tmp.appcompat.txt |
| C:\Users\Administrator\AppData\Local\Temp\WER7BF3.tmp |
| C:\Users\Administrator\AppData\Local\Temp\WER7BF3.tmp.WERInternalMetadata.xml |
| C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_DllLoader.exe_cd3634eb20f2ce5be1371a777149d7b62dd23bc_b3295a47_cab_04f77c6e\WER7A4C.tmp.appcompat.txt |
| C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_DllLoader.exe_cd3634eb20f2ce5be1371a777149d7b62dd23bc_b3295a47_cab_04f77c6e\WER7BF3.tmp.WERInternalMetadata.xml |
| C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_DllLoader.exe_cd3634eb20f2ce5be1371a777149d7b62dd23bc_b3295a47_cab_04f77c6e\memory.hdmp |
| C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_DllLoader.exe_cd3634eb20f2ce5be1371a777149d7b62dd23bc_b3295a47_cab_04f77c6e\Report.wer |
行為描述: | 覆盖已有文件 |
詳細信息: | C:\Users\Administrator\AppData\Local\Temp\WAX7A3B.tmp |
| C:\Users\Administrator\AppData\Local\Temp\WER7BF3.tmp.WERInternalMetadata.xml |
行為描述: | 复制文件 |
詳細信息: | C:\Users\Administrator\AppData\Local\Temp\WER7A4C.tmp.appcompat.txt ---> C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_DllLoader.exe_cd3634eb20f2ce5be1371a777149d7b62dd23bc_b3295a47_cab_04f77c6e\WER7A4C.tmp.appcompat.txt |
| C:\Users\Administrator\AppData\Local\Temp\WER7BF3.tmp.WERInternalMetadata.xml ---> C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_DllLoader.exe_cd3634eb20f2ce5be1371a777149d7b62dd23bc_b3295a47_cab_04f77c6e\WER7BF3.tmp.WERInternalMetadata.xml |
行為描述: | 删除文件 |
詳細信息: | C:\Users\Administrator\AppData\Local\Temp\WAX7A3B.tmp |
| C:\Users\Administrator\AppData\Local\Temp\WER7A4C.tmp |
| C:\Users\Administrator\AppData\Local\Temp\WER7A4C.tmp.appcompat.txt |
| C:\Users\Administrator\AppData\Local\Temp\WER7BF3.tmp |
| C:\Users\Administrator\AppData\Local\Temp\WER7BF3.tmp.WERInternalMetadata.xml |
行為描述: | 查找文件 |
詳細信息: | FileName = C:\Users
|
| FileName = C:\Users\ADMINI~1
|
| FileName = C:\Users\ADMINI~1\AppData
|
| FileName = C:\Users\ADMINI~1\AppData\Local
|
| FileName = C:\Users\ADMINI~1\AppData\Local\Temp
|
| FileName = C:\Users\Administrator\AppData
|
| FileName = C:\Users\Administrator\AppData\Local
|
| FileName = C:\Users\Administrator\AppData\Local\Temp
|
| FileName = C:\Windows\system32\kernel32.dll
|
| FileName = C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_*_cd3634eb20f2ce5be1371a777149d7b62dd23bc_*_cab_*
|
| FileName = C:\ProgramData\Microsoft\Windows\WER\ReportArchive\*_*_*_b3295a47_cab_*
|
| FileName = C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_*_cd3634eb20f2ce5be1371a777149d7b62dd23bc_*_cab_*
|
| FileName = C:\ProgramData\Microsoft\Windows\WER\ReportQueue\*_*_*_b3295a47_cab_*
|
| FileName = C:\Windows\system32\drivers\*.mrk
|
| FileName = C:\ProgramData\Microsoft\Windows\WER\ReportQueue\*_*_*_*_*
|
行為描述: | 修改文件内容 |
詳細信息: | C:\Users\Administrator\AppData\Local\Temp\WAX7A3B.tmp ---> Offset = 0
|
| C:\Users\Administrator\AppData\Local\Temp\WAX7A3B.tmp ---> Offset = 4096
|
| C:\Users\Administrator\AppData\Local\Temp\WAX7A3B.tmp ---> Offset = 28672
|
| C:\Users\Administrator\AppData\Local\Temp\WAX7A3B.tmp ---> Offset = 32768
|
| C:\Users\Administrator\AppData\Local\Temp\WAX7A3B.tmp ---> Offset = 53248
|
| C:\Users\Administrator\AppData\Local\Temp\WER7A4C.tmp.appcompat.txt ---> Offset = 0
|
| C:\Users\Administrator\AppData\Local\Temp\WER7A4C.tmp.appcompat.txt ---> Offset = 2
|
| C:\Users\Administrator\AppData\Local\Temp\WER7A4C.tmp.appcompat.txt ---> Offset = 108
|
| C:\Users\Administrator\AppData\Local\Temp\WER7A4C.tmp.appcompat.txt ---> Offset = 228
|
| C:\Users\Administrator\AppData\Local\Temp\WER7A4C.tmp.appcompat.txt ---> Offset = 2248
|
| C:\Users\Administrator\AppData\Local\Temp\WER7BF3.tmp.WERInternalMetadata.xml ---> Offset = 0
|
| C:\Users\Administrator\AppData\Local\Temp\WER7BF3.tmp.WERInternalMetadata.xml ---> Offset = 2
|
| C:\Users\Administrator\AppData\Local\Temp\WER7BF3.tmp.WERInternalMetadata.xml ---> Offset = 80
|
| C:\Users\Administrator\AppData\Local\Temp\WER7BF3.tmp.WERInternalMetadata.xml ---> Offset = 84
|
| C:\Users\Administrator\AppData\Local\Temp\WER7BF3.tmp.WERInternalMetadata.xml ---> Offset = 122
|