这两个月我抽空对这个SEsecurityCenter做了个检测,Process Monitor监控显示在我上班的10小时内有20万条操作记录,包括文件创建访问和注册表键值读取写入关闭等操作。Wireshark显示该进程是不是有流量上传,截取数据包采用了rsa & aes 加密,发往北京的服务器,本人没有技术解密,所以只能到此为止,至于搜狗到底在发送什么,大家心里应该都有个数,下面这条是截取的发送数据。
Bi0Vxi8df4GIDGhUKNeZu4mMr0KfxWUKPkKUlgXLXlvaOWBVgLoKPMcXhAVpzc9nddwH3y/JG3qiAikyEtnSMBn69LnrPSFdQyFUAqPzTGXP5NQS8Z+SDdWasI7ipo6oI/aN6hwEhc9TDvP/NIYdQ9JVFPgrKGX3nila342qTQs=&v=hk7klUq9tkH/5IAOjFHn99LndrzTKabGGcsp1qmIVshKezk6eEDlnBoaPm52npU/iYAUeOlGz1v5iIiQ6fkdXmbjRCIPbai0mIXrOX5BMn9krtiVKlR9LgJx7D0++t1EgogyT95AJhVH8iEfkaxN21oHRusr7n1JdLvXfzDwKk8=&u=434B/3Xhjf7aZccgGi/lJ3D4sjlsSDFOoyUBNPBuckUuJqnuGaqQnd7vVATGgXoR&p=Kffmcma/+qqZt5N+jrOPJSDM2RH1ZsUe5CTqKXbdTGaN/6eJ1g+hvsYf7M8C/lJtehuZWFKzN15Wb8+CTERGJXQ8dBsTXBVQLkca8Dlew3bcjV8X++ZvKo9/DAuX+YtIh6juAAfxyVd6gTtztLUO1zg5T4hU6OKEvraJCd4qrRab3gve/85xvweaZ98eV7lQrduwlsBSPdv6uDNd7m1tolrjiu/t7Cnn7vLWiRtUkQ0=