DefenseWall log file
05.15.2012 20:54:18, 模块 C:\WINDOWS\system32\taskkill.exe, Attempt to open process C:\WINDOWS\explorer.exe (进程)
05.15.2012 20:54:17, 模块 C:\WINDOWS\system32\conime.exe, Attempt to attach to the thread input of the C:\WINDOWS\system32\csrss.exe (粉碎)
05.15.2012 20:54:17, 模块 C:\WINDOWS\system32\conime.exe, Attempt to detach from the thread input of the C:\WINDOWS\system32\csrss.exe (粉碎)
05.15.2012 20:54:17, 模块 C:\Documents and Settings\A\桌面\请打开\双击我.exe, 1:Attempt to create global windows hook with module C:\Documents and Settings\A\桌面\请打开\双击我.exe (Hook)
05.15.2012 20:54:17, 模块 C:\Documents and Settings\A\桌面\请打开\双击我.exe, Attempt to set value S133121174 within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ (注册表)
05.15.2012 20:54:17, 模块 C:\Documents and Settings\A\桌面\请打开\双击我.exe, Attempt to set value Shell within the key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ (注册表)
05.15.2012 20:54:17, 模块 C:\Documents and Settings\A\桌面\请打开\双击我.exe, 1:Attempt to hide/show window of the process C:\WINDOWS\explorer.exe. (屏幕)
05.15.2012 20:54:17, 模块 C:\WINDOWS\system32\conime.exe, 1:Process is running untrusted now (进程)
05.15.2012 20:54:17, 模块 C:\Documents and Settings\A\桌面\请打开\双击我.exe, 2:Duplicate handle TOCTTOU (TOCTTOU)
05.15.2012 20:54:17, 模块 C:\WINDOWS\system32\taskkill.exe, 1:Process is running untrusted now (进程)
05.15.2012 20:54:16, 模块 C:\Documents and Settings\A\桌面\请打开\双击我.exe, 1:Attempt to bring window of the process C:\Documents and Settings\A\桌面\请打开\双击我.exe to the top (屏幕)
05.15.2012 20:54:15, 模块 C:\Documents and Settings\A\桌面\请打开\双击我.exe, 1:Process is running untrusted now (进程)
|