17:32:36:042, mstscccc.exe, 3700:0, 3700, EXEC_create, C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\mstscccc.exe, parent_pid:3560 cmdline:'"C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\mstscccc.exe"' image_base:0x00400000 , 0x00000000 [操作成功完成。 ],
17:32:36:042, mstscccc.exe, 3700:0, 3700, EXEC_create, C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\mstscccc.exe, parent_pid:3560 cmdline:'"C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\mstscccc.exe"' image_base:0x00400000 , 0x00000000 [操作成功完成。 ],
17:32:36:213, mstscccc.exe, 3700:0, 3700, EXEC_module_load, C:\WINDOWS\system32\guard32.dll, base:0x10000000 size:0x0004D000 , 0x00000000 [操作成功完成。 ],
17:32:36:042, mstscccc.exe, 3700:0, 3700, EXEC_create, C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\mstscccc.exe, parent_pid:3560 cmdline:'"C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\mstscccc.exe"' image_base:0x00400000 , 0x00000000 [操作成功完成。 ],
17:32:36:213, mstscccc.exe, 3700:0, 3700, EXEC_module_load, C:\WINDOWS\system32\guard32.dll, base:0x10000000 size:0x0004D000 , 0x00000000 [操作成功完成。 ],
17:32:36:213, mstscccc.exe, 3700:3696, 3700, FILE_open, C:\WINDOWS\system32\fltlib.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
17:32:36:042, mstscccc.exe, 3700:0, 3700, EXEC_create, C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\mstscccc.exe, parent_pid:3560 cmdline:'"C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\mstscccc.exe"' image_base:0x00400000 , 0x00000000 [操作成功完成。 ],
17:32:36:213, mstscccc.exe, 3700:0, 3700, EXEC_module_load, C:\WINDOWS\system32\guard32.dll, base:0x10000000 size:0x0004D000 , 0x00000000 [操作成功完成。 ],
17:32:36:213, mstscccc.exe, 3700:3696, 3700, FILE_open, C:\WINDOWS\system32\fltlib.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
17:32:36:213, mstscccc.exe, 3700:3696, 3700, SYS_opendev, \FileSystem\Filters\FltMgrMsg, devtype:64 access:0x00100003 share:0x00000000 , 0x00000000 [操作成功完成。 ],
17:32:36:042, mstscccc.exe, 3700:0, 3700, EXEC_create, C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\mstscccc.exe, parent_pid:3560 cmdline:'"C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\mstscccc.exe"' image_base:0x00400000 , 0x00000000 [操作成功完成。 ],
17:32:36:213, mstscccc.exe, 3700:0, 3700, EXEC_module_load, C:\WINDOWS\system32\guard32.dll, base:0x10000000 size:0x0004D000 , 0x00000000 [操作成功完成。 ],
17:32:36:213, mstscccc.exe, 3700:3696, 3700, FILE_open, C:\WINDOWS\system32\fltlib.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
17:32:36:213, mstscccc.exe, 3700:3696, 3700, SYS_opendev, \FileSystem\Filters\FltMgrMsg, devtype:64 access:0x00100003 share:0x00000000 , 0x00000000 [操作成功完成。 ],
17:32:36:229, mstscccc.exe, 3700:0, 3700, EXEC_destroy, C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\mstscccc.exe, parent_pid:3560 cmdline:'"C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\mstscccc.exe"' , 0x00000000 [操作成功完成。 ],
。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。。
说实话,是在不知道他在干嘛 |