17. • 快 能 ⼼心
• Registry Key - AutoRuns
• Process - Process Explorer / Process Monitor
• Network - TCPView / TCPLogView / WireShark
• File system - AutoRuns / Process Explorer
18. • 快 能 ⼼心
• Registry Key - AutoRuns
• Process - Process Explorer / Process Monitor
• Network - TCPView / TCPLogView / WireShark
• File system - AutoRuns / Process Explorer
22. • 快 能 ⼼心
• Registry Key - AutoRuns
• Process - Process Explorer / Process Monitor
• Network - TCPView / TCPLogView / WireShark
• File system - AutoRuns / Process Explorer
80. 6F PB A
kr F PSB I S BP
#F PSB I S BP pV 7 ( () )(
Wireshark
81. p
v d V R@ P BTB
( R@ P BTB 75h # bki
) 1( A P v 1( A P
S @ R@ BTB v S @ R@ BTB
BI l ACA ) BD
ACA ) BD v ACA ) BD
q 7 ( () )(
. A F PSB I S BP pV 7 h( () )(
Wireshark
82. p
v d V R@ P BTB
( R@ P BTB 75h # bki
) 1( A P v 1( A P
S @ R@ BTB v S @ R@ BTB
BI l ACA ) BD
ACA ) BD v ACA ) BD
q 7 ( () )(
. A F PSB I S BP pV 7 h( () )(
4$@2.dat ~dfds3.reg
87. CaptureBAT
~dfds3.reg
p
v d V R@ P BTB
( R@ P BTB 75h # bki
) 1( A P v 1( A P
S @ R@ BTB v S @ R@ BTB
BI l ACA ) BD
ACA ) BDv ACA ) BD
ACA ) BD h e t~
8 7 B RB BTB
q 7 ( () )(
. A F PSB I S BP pV 7 h( () )(
89. CaptureBAT
wscsvc.exe
p
v d V R@ P BTB
( R@ P BTB 75h # bki
) 1( A P v 1( A P
1( A P h V S @ R@ BTB
S @ R@ BTB v S @ R@ BTB
BI l ACA ) BD
ACA ) BDv ACA ) BD
ACA ) BD h e t~
8 7 B RB BTB
q 7 ( () )(
. A F PSB I S BP pV 7 h( () )(
92. p
v d V R@ P BTB
( R@ P BTB 75h # bki
) 1( A P v 1( A P
1( A P h V S @ R@ BTB
S @ R@ BTB v S @ R@ BTB
BI l ACA ) BD
ACA ) BDv ACA ) BD
ACA ) BD h e t~
8 7 B RB BTB
q 7 ( () )(
. A F PSB I S BP pV 7 h( () )(