|
楼主 |
发表于 2017-12-28 12:10:42
|
显示全部楼层
CreationTime: 2016-03-11T09:04:44.000000000Z
1a0.303c: LastWriteTime: 2016-08-01T22:49:30.000000000Z
1a0.303c: ChangeTime: 2017-12-25T03:55:02.836052400Z
1a0.303c: FileAttributes: 0x20
1a0.303c: Size: 0x55528
1a0.303c: NT Headers: 0xe8
1a0.303c: Timestamp: 0x571a4a46
1a0.303c: Machine: 0x8664 - amd64
1a0.303c: Timestamp: 0x571a4a46
1a0.303c: Image Version: 0.0
1a0.303c: SizeOfImage: 0x57000 (356352)
1a0.303c: Resource Dir: 0x55000 LB 0x758
1a0.303c: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
1a0.303c: [Raw version resource data: 0x55110 LB 0x334, codepage 0x0 (reserved 0x0)]
1a0.303c: ProductName: SYSCORE
1a0.303c: ProductVersion: 15.4.0.822
1a0.303c: FileVersion: SYSCORE.15.4.0.822
1a0.303c: PrivateBuild: SYSCORE.15.4.0.822 F15,F16,F19
1a0.303c: FileDescription: Anti-Virus File System Filter Driver
1a0.303c: \SystemRoot\System32\drivers\mfefirek.sys:
1a0.303c: CreationTime: 2016-03-11T09:04:44.000000000Z
1a0.303c: LastWriteTime: 2016-08-01T22:49:30.000000000Z
1a0.303c: ChangeTime: 2017-12-25T03:55:02.836052400Z
1a0.303c: FileAttributes: 0x20
1a0.303c: Size: 0x78728
1a0.303c: NT Headers: 0xe8
1a0.303c: Timestamp: 0x571a4a87
1a0.303c: Machine: 0x8664 - amd64
1a0.303c: Timestamp: 0x571a4a87
1a0.303c: Image Version: 0.0
1a0.303c: SizeOfImage: 0x7b000 (503808)
1a0.303c: Resource Dir: 0x77000 LB 0x388
1a0.303c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
1a0.303c: [Raw version resource data: 0x77060 LB 0x328, codepage 0x0 (reserved 0x0)]
1a0.303c: ProductName: SYSCORE
1a0.303c: ProductVersion: 15.4.0.822
1a0.303c: FileVersion: SYSCORE.15.4.0.822
1a0.303c: PrivateBuild: SYSCORE.15.4.0.822 F17,F18
1a0.303c: FileDescription: McAfee Core Firewall Engine Driver
1a0.303c: \SystemRoot\System32\drivers\mfehidk.sys:
1a0.303c: CreationTime: 2016-03-11T09:04:44.000000000Z
1a0.303c: LastWriteTime: 2016-08-01T22:49:30.000000000Z
1a0.303c: ChangeTime: 2017-12-25T03:55:02.836052400Z
1a0.303c: FileAttributes: 0x20
1a0.303c: Size: 0xcdd28
1a0.303c: NT Headers: 0x100
1a0.303c: Timestamp: 0x571a49df
1a0.303c: Machine: 0x8664 - amd64
1a0.303c: Timestamp: 0x571a49df
1a0.303c: Image Version: 0.0
1a0.303c: SizeOfImage: 0xd9000 (888832)
1a0.303c: Resource Dir: 0xd5000 LB 0x758
1a0.303c: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
1a0.303c: [Raw version resource data: 0xd5110 LB 0x320, codepage 0x0 (reserved 0x0)]
1a0.303c: ProductName: SYSCORE
1a0.303c: ProductVersion: 15.4.0.822
1a0.303c: FileVersion: SYSCORE.15.4.0.822
1a0.303c: PrivateBuild: SYSCORE.15.4.0.822 F14,F15,F16,F18,F20
1a0.303c: FileDescription: McAfee Link Driver
1a0.303c: \SystemRoot\System32\drivers\mfewfpk.sys:
1a0.303c: CreationTime: 2016-03-11T09:04:44.000000000Z
1a0.303c: LastWriteTime: 2016-08-01T22:49:30.000000000Z
1a0.303c: ChangeTime: 2017-12-25T03:55:02.836052400Z
1a0.303c: FileAttributes: 0x20
1a0.303c: Size: 0x3b728
1a0.303c: NT Headers: 0xf0
1a0.303c: Timestamp: 0x571a49f1
1a0.303c: Machine: 0x8664 - amd64
1a0.303c: Timestamp: 0x571a49f1
1a0.303c: Image Version: 0.0
1a0.303c: SizeOfImage: 0x59000 (364544)
1a0.303c: Resource Dir: 0x57000 LB 0x380
1a0.303c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
1a0.303c: [Raw version resource data: 0x57060 LB 0x320, codepage 0x0 (reserved 0x0)]
1a0.303c: ProductName: SYSCORE
1a0.303c: ProductVersion: 15.4.0.822
1a0.303c: FileVersion: SYSCORE.15.4.0.822
1a0.303c: PrivateBuild: SYSCORE.15.4.0.822 F17,F18
1a0.303c: FileDescription: Anti-Virus Mini-Firewall Driver
1a0.303c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
1a0.303c: Calling main()
1a0.303c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
1a0.303c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
1a0.303c: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
1a0.303c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe)
1a0.303c: SUPR3HardenedMain: Respawn #2
1a0.303c: supR3HardNtEnableThreadCreation:
1a0.303c: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
1a0.303c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntdll.dll)
1a0.303c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1a0.303c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
1a0.303c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff898100000 'C:\WINDOWS\System32\ntdll.dll'
1a0.303c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff8981791b0 pvNtTerminateThread=00007ff8981a0890
1a0.303c: supR3HardenedWinDoReSpawn(2): New child 28a8.22fc [kernel32].
1a0.303c: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
1a0.303c: supR3HardNtChildGatherData: PebBaseAddress=0000000000964000 cbPeb=0x388
1a0.303c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff898100000 uNtDllChildAddr=00007ff898100000
1a0.303c: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff8981791b0
1a0.303c: supR3HardenedWinSetupChildInit: Start child.
1a0.303c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 19 ms.
1a0.303c: supR3HardNtChildPurify: Startup delay kludge #1/0: 519 ms, 59 sleeps
1a0.303c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
1a0.303c: *0000000000000000-00000000006bffff 0x0001/0x0000 0x0000000
1a0.303c: *00000000006c0000-00000000006dffff 0x0004/0x0004 0x0020000
1a0.303c: *00000000006e0000-00000000006f8fff 0x0002/0x0002 0x0040000
1a0.303c: 00000000006f9000-00000000006fffff 0x0001/0x0000 0x0000000
1a0.303c: *0000000000700000-00000000007fafff 0x0000/0x0004 0x0020000
1a0.303c: 00000000007fb000-00000000007fdfff 0x0104/0x0004 0x0020000
1a0.303c: 00000000007fe000-00000000007fffff 0x0004/0x0004 0x0020000
1a0.303c: *0000000000800000-0000000000963fff 0x0000/0x0004 0x0020000
1a0.303c: 0000000000964000-0000000000966fff 0x0004/0x0004 0x0020000
1a0.303c: 0000000000967000-00000000009fffff 0x0000/0x0004 0x0020000
1a0.303c: *0000000000a00000-0000000000a03fff 0x0002/0x0002 0x0040000
1a0.303c: 0000000000a04000-0000000000a0ffff 0x0001/0x0000 0x0000000
1a0.303c: *0000000000a10000-0000000000a10fff 0x0004/0x0004 0x0020000
1a0.303c: 0000000000a11000-000000007ffdffff 0x0001/0x0000 0x0000000
1a0.303c: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
1a0.303c: *000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
1a0.303c: 000000007fff0000-00007ff742c8ffff 0x0001/0x0000 0x0000000
1a0.303c: *00007ff742c90000-00007ff742cc2fff 0x0002/0x0002 0x0040000
1a0.303c: 00007ff742cc3000-00007ff74383ffff 0x0001/0x0000 0x0000000
1a0.303c: *00007ff743840000-00007ff743840fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
1a0.303c: 00007ff743841000-00007ff7438b0fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
1a0.303c: 00007ff7438b1000-00007ff7438b1fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
1a0.303c: 00007ff7438b2000-00007ff7438f6fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
1a0.303c: 00007ff7438f7000-00007ff7438f7fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
1a0.303c: 00007ff7438f8000-00007ff7438f8fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
1a0.303c: 00007ff7438f9000-00007ff7438fdfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
1a0.303c: 00007ff7438fe000-00007ff7438fefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
1a0.303c: |
|