就是一个重装工具吗?
文件信息
安全评分 :75
基本信息
MD5: 5024fb6d1587cdc29766bd33199cecc6
文件类型: EXE
出品公司:
www.wuyouxitong.com版本: 6.3.0.0---6.3.0.0
壳或编译器信息: PACKER:UPolyX v0.5
关键行为
行为描述: 获取TickCount值
详情信息: TickCount = 5360131, SleepMilliseconds = 100.
TickCount = 5360162, SleepMilliseconds = 100.
TickCount = 5360193, SleepMilliseconds = 100.
TickCount = 5360240, SleepMilliseconds = 100.
TickCount = 5360412, SleepMilliseconds = 100.
TickCount = 5360428, SleepMilliseconds = 100.
TickCount = 5360475, SleepMilliseconds = 100.
TickCount = 5360521, SleepMilliseconds = 100.
TickCount = 5360537, SleepMilliseconds = 100.
TickCount = 5360631, SleepMilliseconds = 100.
TickCount = 5360646, SleepMilliseconds = 100.
TickCount = 5360693, SleepMilliseconds = 100.
TickCount = 5360709, SleepMilliseconds = 100.
TickCount = 5360740, SleepMilliseconds = 100.
TickCount = 5360756, SleepMilliseconds = 100.
行为描述: 在桌面创建快捷方式
详情信息: C:\Documents and Settings\Administrator\桌面\无忧系统助手一键重装系统.lnk
行为描述: 设置特殊文件属性
详情信息: C:\wySysAss\dsptw.exe
行为描述: 查找PE资源信息
详情信息: (FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User4, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User17, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User5, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User6, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User7, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User8, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User10, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User11, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User12, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User13, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User14, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User15, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User16, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User19, ResType: XBGhostFile
(FindResourceA) hModule = 0x00400000, ResName: XBGhost_RES_User20, ResType: XBGhostFile
行为描述: 修改注册表_系统防火墙可信进程列表
详情信息: \REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\wySysAss\download\MiniThunderPlatform.exe
行为描述: 设置特殊文件夹属性
详情信息: C:\wySysAss
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies