| 文件名称: | setup.exe |
| MD5: | 8a5beb16c15f696c2a97769f25bcf217 |
| 文件类型: | EXE |
| 上传时间: | 2015-05-13 13:19:23 |
| 出品公司: | Microsoft Corporation |
| 版本: | 6.0.84.50---6.00.8450 |
| 壳或编译器信息: | COMPILER:Microsoft Visual C++ 5.0 |
| 行为描述: | 写权限映射文件 |
| 详情信息: | CiceroSharedMemDefaultS-1-5-21-1482476501-1645522239-1417001333-500 MSCTF.MarshalInterface.FileMap.EOJ..FFGFF MSCTF.MarshalInterface.FileMap.EOJ.B.FFGFF MSCTF.MarshalInterface.FileMap.EOJ.C.FFGFF MSCTF.MarshalInterface.FileMap.EOJ.D.FFGFF MSCTF.MarshalInterface.FileMap.EOJ.E.FFGFF MSCTF.MarshalInterface.FileMap.EOJ.F.FFGFF MSCTF.MarshalInterface.FileMap.EOJ.G.FFGFF |
| 行为描述: | 写权限映射文件 |
| 详情信息: | CiceroSharedMemDefaultS-1-5-21-1482476501-1645522239-1417001333-500 MSCTF.MarshalInterface.FileMap.EOJ..FFGFF MSCTF.MarshalInterface.FileMap.EOJ.B.FFGFF MSCTF.MarshalInterface.FileMap.EOJ.C.FFGFF MSCTF.MarshalInterface.FileMap.EOJ.D.FFGFF MSCTF.MarshalInterface.FileMap.EOJ.E.FFGFF MSCTF.MarshalInterface.FileMap.EOJ.F.FFGFF MSCTF.MarshalInterface.FileMap.EOJ.G.FFGFF |
| 行为描述: | 修改文件内容 |
| 详情信息: | C:\WINDOWS\ST6UNST.000---> Offset = 0 C:\WINDOWS\ST6UNST.000---> Offset = 166 C:\WINDOWS\ST6UNST.000---> Offset = 168 |
| 行为描述: | 创建互斥体 |
| 详情信息: | CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 CTF.Asm.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 CTF.xxx.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 CTF.TimListCache.FMPDefaultS-1-5-21-1482476501-1645522239-1417001333-500MUTEX.DefaultS-1-5-21-1482476501-1645522239-1417001333-500 MSCTF.Shared.MUTEX.AEH |
| 行为描述: | 查找指定窗口 |
| 详情信息: | NtUserFindWindowEx: [Class,Window] = [GVBSetupInit,] NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,] |
| 行为描述: | 窗口信息 |
| 详情信息: | Pid = 2528, Hwnd=0x10356, Text = 确定, ClassName = Button. Pid = 2528, Hwnd=0x1035a, Text = 安装程序不能找到 "c:\monitor\sample.LST"。安装中止..., ClassName = Static. Pid = 2528, Hwnd=0x10354, Text = 错误, ClassName = #32770. Pid = 2528, Hwnd=0x1034c, Text = 设置, ClassName = GVBSetupInit. |