返回目錄html
經過分析惡意代碼,我對前幾回的實驗也有了更多的認識與理解,咱們不該該再依賴殺軟,而是應該多去利用所學的知識進行分析。在對系統進行監控的期間,發現了一些流氓軟件會自動鏈接網絡,不只佔內存還會給電腦運行形成一些沒必要要的麻煩,因此仍是手動關掉的比較好~chrome
返回目錄shell
date /t >> c:\20165309.txt time /t >> c:\20165309.txt netstat -bn >> c:\20165309.txt
schtasks /create /TN netstat /sc MINUTE /MO 1 /TR "c:\20165309.bat"
,創建名爲netstat,以分鐘計時的記錄計算機聯網狀況的任務。<Sysmon schemaversion="3.10"> <!-- Capture all hashes --> <HashAlgorithms>*</HashAlgorithms> <EventFiltering> <!-- Log all drivers except if the signature --> <!-- contains Microsoft or Windows --> <DriverLoad onmatch="exclude"> <Signature condition="contains">microsoft</Signature> <Signature condition="contains">windows</Signature> </DriverLoad> <NetworkConnect onmatch="exclude"> <Image condition="end with">chrome.exe</Image> </NetworkConnect> <NetworkConnect onmatch="include"> <DestinationPort condition="is">80</DestinationPort> <DestinationPort condition="is">443</DestinationPort> <DestinationPort condition="is">5309</DestinationPort> </NetworkConnect> <CreateRemoteThread onmatch="include"> <TargetImage condition="end with">explorer.exe</TargetImage> <TargetImage condition="end with">svchost.exe</TargetImage> <TargetImage condition="end with">winlogon.exe</TargetImage> <SourceImage condition="end with">powershell.exe</SourceImage> </CreateRemoteThread> </EventFiltering> </Sysmon>
sysmon -accepteula -i -n
一鍵安裝:返回目錄windows