動作
非法入侵 #683
已結束TPHQ6WKS324
開始日期:
2024-02-19
完成日期:
2024-02-29
完成百分比:
100%
預估工時:
概述
Description
A suspicious process injected into another process in an unusual way. Investigate the process trees for the injector and injectee.
Command line
"C:\WINDOWS\system32\rundll32.exe" D:\Users\ProgramData\Lenovo\Vantage\Addins\LenovoBatteryGaugeAddin\1.0.3.12\x64\LenovoBatteryGaugePackage.dll UnloadBatteryGaugeFromExplorer
動作