zyx9 发表于 2012-6-21 21:17 
有效数字签名
动作?
15:49:09:468, test.exe, 2156:0, 2156, EXEC_create, C:\Documents and Settings\Administrator\桌面\test.exe, parent_pid:4060 cmdline:'"C:\Documents and Settings\Administrator\桌面\test.exe"' image_base:0x00400000 , 0x00000000 [操作成功完成。 ],
15:49:09:656, test.exe, 2156:0, 2156, EXEC_module_load, C:\WINDOWS\system32\guard32.dll, base:0x10000000 size:0x0004D000 , 0x00000000 [操作成功完成。 ],
15:49:09:656, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\fltlib.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:656, test.exe, 2156:2148, 2156, SYS_opendev, \FileSystem\Filters\FltMgrMsg, devtype:64 access:0x00100003 share:0x00000000 , 0x00000000 [操作成功完成。 ],
15:49:09:687, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\uxtheme.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:687, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\uxtheme.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:687, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\uxtheme.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:718, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\MSCTF.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:718, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\MSCTF.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:718, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\MSCTF.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:734, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\MSCTFIME.IME, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:734, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\MSCTFIME.IME, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:750, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\MSCTFIME.IME, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:750, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\ole32.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:750, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\ole32.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:750, test.exe, 2156:2148, 2156, FILE_open, C:\WINDOWS\system32\ole32.dll, access:0x00100020 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ],
15:49:09:781, test.exe, 2156:2148, 2156, W32_findwnd, , parent_hwnd:0x00000000 child_hwnd:0x00000000 clsname:'Shell_TrayWnd' wndname:'' , 0x00030056 [],
|