对DW来说,小菜一碟。
DefenseWall log file
03.03.2012 00:38:22, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 1:Process is running untrusted now (进程)
03.03.2012 00:38:22, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Cache within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:38:22, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Directory within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\ (注册表)
03.03.2012 00:38:22, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Cookies within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:38:22, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value History within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:38:22, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 1:Process is running untrusted now (进程)
03.03.2012 00:38:22, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 10:Attempt to open protected file C:\Documents and Settings\china\Cookies\ (资源隔离)
03.03.2012 00:38:22, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 10:Attempt to open protected file C:\Documents and Settings\china\Cookies\ (资源隔离)
03.03.2012 00:38:22, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 8:Attempt to open protected file C:\Documents and Settings\china\Cookies\index.dat (资源隔离)
03.03.2012 00:38:23, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Cache within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:38:23, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Directory within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\ (注册表)
03.03.2012 00:38:23, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Cookies within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:38:23, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value History within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:38:23, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 10:Attempt to open protected file C:\Documents and Settings\china\Cookies\ (资源隔离)
03.03.2012 00:38:23, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 10:Attempt to open protected file C:\Documents and Settings\china\Cookies\ (资源隔离)
03.03.2012 00:38:23, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 8:Attempt to open protected file C:\Documents and Settings\china\Cookies\index.dat (资源隔离)
03.03.2012 00:38:20, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Cache within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:38:20, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Directory within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\ (注册表)
03.03.2012 00:38:20, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Cookies within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:38:20, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value History within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:38:20, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 10:Attempt to open protected file C:\Documents and Settings\china\Cookies\ (资源隔离)
03.03.2012 00:38:20, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 10:Attempt to open protected file C:\Documents and Settings\china\Cookies\ (资源隔离)
03.03.2012 00:38:20, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 8:Attempt to open protected file C:\Documents and Settings\china\Cookies\index.dat (资源隔离)
03.03.2012 00:38:19, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 1:Process is running untrusted now (进程)
03.03.2012 00:37:56, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Cache within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:37:56, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Directory within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\ (注册表)
03.03.2012 00:37:56, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Cookies within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:37:56, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value History within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:37:56, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 10:Attempt to open protected file C:\Documents and Settings\china\Cookies\ (资源隔离)
03.03.2012 00:37:56, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 10:Attempt to open protected file C:\Documents and Settings\china\Cookies\ (资源隔离)
03.03.2012 00:37:56, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 8:Attempt to open protected file C:\Documents and Settings\china\Cookies\index.dat (资源隔离)
03.03.2012 00:37:56, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 1:Process is running untrusted now (进程)
03.03.2012 00:37:07, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Directory within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\ (注册表)
03.03.2012 00:37:07, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Cookies within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:37:07, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value History within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
03.03.2012 00:37:07, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 10:Attempt to open protected file C:\Documents and Settings\china\Cookies\ (资源隔离)
03.03.2012 00:37:07, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 10:Attempt to open protected file C:\Documents and Settings\china\Cookies\ (资源隔离)
03.03.2012 00:37:07, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, 8:Attempt to open protected file C:\Documents and Settings\china\Cookies\index.dat (资源隔离)
03.03.2012 00:37:07, 模块 C:\Documents and Settings\*\桌面\xh\xh.exe, Attempt to set value Cache within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
|