本帖最后由 dljsxyls 于 2012-7-6 15:45 编辑
- 07.06.2012 15:33:50, 模块 C:\eeo\EUnpya.exe, Internet connections are blocked (网络)
- 07.06.2012 15:33:29, 模块 C:\eeo\EUnpya.exe, Attempt to set value Common AppData within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:29, 模块 C:\eeo\EUnpya.exe, Attempt to set value AppData within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:29, 模块 C:\eeo\EUnpya.exe, Attempt to set value MigrateProxy within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ (注册表)
- 07.06.2012 15:33:29, 模块 C:\eeo\EUnpya.exe, Attempt to set value ProxyEnable within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ (注册表)
- 07.06.2012 15:33:29, 模块 C:\eeo\EUnpya.exe, Attempt to set value SavedLegacySettings within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\ (注册表)
- 07.06.2012 15:33:28, 模块 C:\eeo\EUnpya.exe, Attempt to set value Directory within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\ (注册表)
- 07.06.2012 15:33:28, 模块 C:\eeo\EUnpya.exe, Attempt to set value Cookies within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:28, 模块 C:\eeo\EUnpya.exe, Attempt to set value History within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:28, 模块 C:\eeo\EUnpya.exe, Attempt to delete service (服务)
- 07.06.2012 15:33:28, 模块 C:\eeo\EUnpya.exe, Attempt to set value Cache within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:22, 模块 C:\eeo\EUnpya.exe, 1:Process is running untrusted now (进程)
- 07.06.2012 15:33:21, 模块 C:\WINDOWS\system32\rundll32.exe, Attempt to set value Cache within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:21, 模块 C:\WINDOWS\system32\rundll32.exe, Attempt to set value Cookies within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:20, 模块 C:\WINDOWS\system32\rundll32.exe, Attempt to delete service (服务)
- 07.06.2012 15:33:20, 模块 C:\WINDOWS\system32\rundll32.exe, Attempt to set value Common Documents within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:20, 模块 C:\WINDOWS\system32\rundll32.exe, Attempt to set value Desktop within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:20, 模块 C:\WINDOWS\system32\rundll32.exe, Attempt to set value Common Desktop within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:20, 模块 C:\WINDOWS\system32\rundll32.exe, Attempt to set value Personal within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:16, 模块 C:\WINDOWS\system32\rundll32.exe, 1:Process is running untrusted now (进程)
- 07.06.2012 15:33:09, 模块 C:\WINDOWS\system32\rundll32.exe, Attempt to delete service (服务)
- 07.06.2012 15:33:09, 模块 C:\Documents and Settings\Administrator\桌面\巨人密保卡资料\pjee7TGiHcBY8.exe, Attempt to set value Cookies within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:09, 模块 C:\Documents and Settings\Administrator\桌面\巨人密保卡资料\pjee7TGiHcBY8.exe, Attempt to set value Cache within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:06, 模块 C:\WINDOWS\system32\rundll32.exe, 1:Process is running untrusted now (进程)
- 07.06.2012 15:33:05, 模块 C:\Documents and Settings\Administrator\桌面\巨人密保卡资料\pjee7TGiHcBY8.exe, Attempt to delete service (服务)
- 07.06.2012 15:33:05, 模块 C:\Documents and Settings\Administrator\桌面\巨人密保卡资料\pjee7TGiHcBY8.exe, Attempt to set value Common Documents within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:05, 模块 C:\Documents and Settings\Administrator\桌面\巨人密保卡资料\pjee7TGiHcBY8.exe, Attempt to set value Desktop within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:05, 模块 C:\Documents and Settings\Administrator\桌面\巨人密保卡资料\pjee7TGiHcBY8.exe, Attempt to set value Common Desktop within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:05, 模块 C:\Documents and Settings\Administrator\桌面\巨人密保卡资料\pjee7TGiHcBY8.exe, Attempt to set value Personal within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
- 07.06.2012 15:33:04, 模块 C:\Documents and Settings\Administrator\桌面\巨人密保卡资料\pjee7TGiHcBY8.exe, 1:Process is running untrusted now (进程)
复制代码 |