2012/3/14 18:35:35,C:\Windows\explorer.exe,53,Allowed ;Execution of an application (C:\Users\dora\Desktop\样本\我的照片2012.x01.26.mac.love.xas\我的照片2012.x01.26.mac.love.xas.eXE)
2012/3/14 18:36:39,C:\Users\dora\Desktop\样本\我的照片2012.x01.26.mac.love.xas\我的照片2012.x01.26.mac.love.xas.eXE,26,Blocked ;改变关键注册表项目 (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce,wextract_cleanup0)
2012/3/14 18:36:48,C:\Users\dora\Desktop\样本\我的照片2012.x01.26.mac.love.xas\我的照片2012.x01.26.mac.love.xas.eXE,53,Allowed ;Execution of an application (C:\Users\dora\AppData\Local\Temp\IXP000.TMP\vchot.exe)
2012/3/14 18:36:55,C:\Users\dora\AppData\Local\Temp\IXP000.TMP\vchot.exe,53,Allowed ;Execution of an application (C:\Windows\System32\cmd.exe)
2012/3/14 18:36:55,C:\Windows\System32\cmd.exe,53,Allowed ;Execution of an application (C:\Windows\System32\net.exe)
2012/3/14 18:37:00,D:\TDDOWNLOAD\软件\VStart50\VStart.exe,48,Allowed ;Outgoing network access
2012/3/14 18:37:02,C:\Windows\System32\net.exe,53,Blocked ;Execution of an application (C:\Windows\System32\net1.exe)
2012/3/14 18:37:03,C:\Windows\System32\cmd.exe,53,Allowed ;Execution of an application (C:\Program Files\SogouExplorer\sogouexplorer.exe)
2012/3/14 18:37:03,C:\Windows\System32\cmd.exe,53,Allowed ;Execution of an application (C:\Program Files\SogouExplorer\sogouexplorer.exe)
2012/3/14 18:37:03,C:\Windows\System32\cmd.exe,53,Allowed ;Execution of an application (C:\Windows\System32\ftp.exe)
2012/3/14 18:37:11,C:\Windows\System32\ftp.exe,50,Blocked ;Accessing the network via DNSResolver service
2012/3/14 18:37:19,C:\Windows\System32\ftp.exe,48,Blocked ;Outgoing network access
2012/3/14 18:37:23,C:\Windows\System32\cmd.exe,53,Allowed ;Execution of an application (C:\Windows\System32\cmd.exe)
2012/3/14 18:37:45,C:\Windows\System32\cmd.exe,41,Blocked ;修改关键文件或位置 (C:\Windows\System32\zz.vbs)
2012/3/14 18:37:49,C:\Windows\System32\cmd.exe,53,Allowed ;Execution of an application (C:\Windows\System32\reg.exe)
2012/3/14 18:38:00,C:\Windows\System32\reg.exe,26,Blocked ;改变关键注册表项目 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,VVT)
2012/3/14 18:38:00,C:\Windows\System32\cmd.exe,53,Allowed ;Execution of an application (C:\Windows\System32\reg.exe)
2012/3/14 18:38:04,C:\Windows\System32\reg.exe,26,Blocked ;改变关键注册表项目 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,TINTSETP) |