楼主: tiancun
收起左侧

[病毒样本] 卡巴不报!MD5: FCC8C6

[复制链接]
cy6266812
发表于 2007-11-6 13:32:23 | 显示全部楼层
咖啡又被过了
SONGBOWEN
发表于 2007-11-6 13:40:48 | 显示全部楼层
EQ的监控日志:
  1. 2007-11-06 13:31:47    运行应用程序      操作:允许
  2. 进程路径:C:\WINDOWS\Explorer.EXE
  3. 文件路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  4. 触发规则:所有程序规则->*


  5. 2007-11-06 13:31:50    删除注册表      操作:允许
  6. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  7. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  8. 注册表名称:otcujrh
  9. 触发规则:所有程序规则->系统自动运行->*\SOFTWARE\Microsoft\Windows\CurrentVersion\Run*


  10. 2007-11-06 13:31:52    删除注册表      操作:允许
  11. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  12. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  13. 注册表名称:rommabp
  14. 触发规则:所有程序规则->系统自动运行->*\SOFTWARE\Microsoft\Windows\CurrentVersion\Run*


  15. 2007-11-06 13:31:52    运行应用程序      操作:允许
  16. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  17. 文件路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  18. 触发规则:所有程序规则->*


  19. 2007-11-06 13:31:52    运行应用程序      操作:允许
  20. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  21. 文件路径:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  22. 触发规则:所有程序规则->*


  23. 2007-11-06 13:31:52    运行应用程序      操作:允许
  24. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  25. 文件路径:C:\WINDOWS\system32\cmd.exe
  26. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  27. 触发规则:所有程序规则->*


  28. 2007-11-06 13:31:52    运行应用程序      操作:允许
  29. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  30. 文件路径:C:\WINDOWS\system32\cmd.exe
  31. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  32. 触发规则:所有程序规则->*


  33. 2007-11-06 13:31:52    运行应用程序      操作:允许
  34. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  35. 文件路径:C:\WINDOWS\system32\cmd.exe
  36. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  37. 触发规则:所有程序规则->*


  38. 2007-11-06 13:31:53    运行应用程序      操作:允许
  39. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  40. 文件路径:C:\WINDOWS\system32\cmd.exe
  41. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  42. 触发规则:所有程序规则->*


  43. 2007-11-06 13:31:53    运行应用程序      操作:允许
  44. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  45. 文件路径:C:\WINDOWS\system32\cmd.exe
  46. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  47. 触发规则:所有程序规则->*


  48. 2007-11-06 13:31:53    运行应用程序      操作:允许
  49. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  50. 文件路径:C:\WINDOWS\system32\cmd.exe
  51. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  52. 触发规则:所有程序规则->*


  53. 2007-11-06 13:31:53    创建注册表值      操作:允许
  54. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  55. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ras.exe
  56. 注册表名称:[Key]
  57. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  58. 2007-11-06 13:31:53    运行应用程序      操作:允许
  59. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  60. 文件路径:C:\WINDOWS\system32\cmd.exe
  61. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  62. 触发规则:所有程序规则->*


  63. 2007-11-06 13:31:53    运行应用程序      操作:允许
  64. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  65. 文件路径:C:\WINDOWS\system32\cmd.exe
  66. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  67. 触发规则:所有程序规则->*


  68. 2007-11-06 13:31:53    运行应用程序      操作:允许
  69. 进程路径:C:\WINDOWS\system32\cmd.exe
  70. 文件路径:C:\WINDOWS\system32\conime.exe
  71. 触发规则:所有程序规则->*


  72. 2007-11-06 13:31:53    运行应用程序      操作:允许
  73. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  74. 文件路径:C:\WINDOWS\system32\cmd.exe
  75. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  76. 触发规则:所有程序规则->*


  77. 2007-11-06 13:31:53    运行应用程序      操作:允许
  78. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  79. 文件路径:C:\WINDOWS\system32\cmd.exe
  80. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  81. 触发规则:所有程序规则->*
复制代码
SONGBOWEN
发表于 2007-11-6 13:41:21 | 显示全部楼层
  1. 2007-11-06 13:31:53    运行应用程序      操作:允许
  2. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  3. 文件路径:C:\WINDOWS\system32\cmd.exe
  4. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  5. 触发规则:所有程序规则->*


  6. 2007-11-06 13:31:53    运行应用程序      操作:允许
  7. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  8. 文件路径:C:\WINDOWS\system32\cmd.exe
  9. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  10. 触发规则:所有程序规则->*


  11. 2007-11-06 13:31:53    运行应用程序      操作:允许
  12. 进程路径:C:\WINDOWS\system32\cmd.exe
  13. 文件路径:C:\WINDOWS\system32\conime.exe
  14. 触发规则:所有程序规则->*


  15. 2007-11-06 13:31:54    创建文件      操作:允许
  16. 进程路径:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  17. 文件路径:C:\WINDOWS\system32\verclsids.exe
  18. 触发规则:所有程序规则->系统文件->%WinDir%\system32\*.exe


  19. 2007-11-06 13:31:54    运行应用程序      操作:允许
  20. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  21. 文件路径:C:\WINDOWS\system32\cmd.exe
  22. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  23. 触发规则:所有程序规则->*


  24. 2007-11-06 13:31:54    运行应用程序      操作:允许
  25. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  26. 文件路径:C:\WINDOWS\system32\cmd.exe
  27. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  28. 触发规则:所有程序规则->*


  29. 2007-11-06 13:31:54    运行应用程序      操作:允许
  30. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  31. 文件路径:C:\WINDOWS\system32\cmd.exe
  32. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  33. 触发规则:所有程序规则->*


  34. 2007-11-06 13:31:54    运行应用程序      操作:允许
  35. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  36. 文件路径:C:\WINDOWS\system32\cmd.exe
  37. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  38. 触发规则:所有程序规则->*


  39. 2007-11-06 13:31:54    运行应用程序      操作:允许
  40. 进程路径:C:\WINDOWS\system32\cmd.exe
  41. 文件路径:C:\WINDOWS\system32\conime.exe
  42. 触发规则:所有程序规则->*


  43. 2007-11-06 13:31:54    运行应用程序      操作:允许
  44. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  45. 文件路径:C:\WINDOWS\system32\cmd.exe
  46. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  47. 触发规则:所有程序规则->*


  48. 2007-11-06 13:31:54    运行应用程序      操作:允许
  49. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  50. 文件路径:C:\WINDOWS\system32\cmd.exe
  51. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  52. 触发规则:所有程序规则->*


  53. 2007-11-06 13:31:54    创建注册表值      操作:允许
  54. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  55. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ras.exe
  56. 注册表名称:Debugger
  57. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  58. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  59. 2007-11-06 13:31:54    运行应用程序      操作:允许
  60. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  61. 文件路径:C:\WINDOWS\system32\cmd.exe
  62. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  63. 触发规则:所有程序规则->*


  64. 2007-11-06 13:31:54    运行应用程序      操作:允许
  65. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  66. 文件路径:C:\WINDOWS\system32\cmd.exe
  67. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  68. 触发规则:所有程序规则->*


  69. 2007-11-06 13:31:54    运行应用程序      操作:允许
  70. 进程路径:C:\WINDOWS\system32\cmd.exe
  71. 文件路径:C:\WINDOWS\system32\conime.exe
  72. 触发规则:所有程序规则->*


  73. 2007-11-06 13:31:54    运行应用程序      操作:允许
  74. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  75. 文件路径:C:\WINDOWS\system32\cmd.exe
  76. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  77. 触发规则:所有程序规则->*


  78. 2007-11-06 13:31:54    运行应用程序      操作:允许
  79. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  80. 文件路径:C:\WINDOWS\system32\cmd.exe
  81. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  82. 触发规则:所有程序规则->*
复制代码
SONGBOWEN
发表于 2007-11-6 13:41:50 | 显示全部楼层
  1. 2007-11-06 13:31:54    运行应用程序      操作:允许
  2. 进程路径:C:\Documents and Settings\Administrator\桌面\rommabp.exe
  3. 文件路径:C:\WINDOWS\system32\cmd.exe
  4. 命令行:/c del "C:\Documents and Settings\Administrator\桌面\rommabp.exe"
  5. 触发规则:所有程序规则->*


  6. 2007-11-06 13:31:55    运行应用程序      操作:允许
  7. 进程路径:C:\WINDOWS\system32\cmd.exe
  8. 文件路径:C:\WINDOWS\system32\conime.exe
  9. 触发规则:所有程序规则->*


  10. 2007-11-06 13:31:55    删除文件      操作:允许
  11. 进程路径:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  12. 文件路径:C:\WINDOWS\system32\verclsid.exe
  13. 触发规则:所有程序规则->系统文件->%WinDir%\system32\*.exe


  14. 2007-11-06 13:31:55    运行应用程序      操作:允许
  15. 进程路径:C:\WINDOWS\system32\cmd.exe
  16. 文件路径:C:\WINDOWS\system32\conime.exe
  17. 触发规则:所有程序规则->*


  18. 2007-11-06 13:31:55    运行应用程序      操作:允许
  19. 进程路径:C:\WINDOWS\system32\cmd.exe
  20. 文件路径:C:\WINDOWS\system32\conime.exe
  21. 触发规则:所有程序规则->*


  22. 2007-11-06 13:31:55    创建注册表值      操作:允许
  23. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  24. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com
  25. 注册表名称:[Key]
  26. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  27. 2007-11-06 13:31:55    运行应用程序      操作:允许
  28. 进程路径:C:\WINDOWS\system32\cmd.exe
  29. 文件路径:C:\WINDOWS\system32\conime.exe
  30. 触发规则:所有程序规则->*


  31. 2007-11-06 13:31:56    运行应用程序      操作:允许
  32. 进程路径:C:\WINDOWS\system32\cmd.exe
  33. 文件路径:C:\WINDOWS\system32\conime.exe
  34. 触发规则:所有程序规则->*


  35. 2007-11-06 13:31:56    创建文件      操作:允许
  36. 进程路径:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  37. 文件路径:C:\WINDOWS\system32\verclsids.exe
  38. 触发规则:所有程序规则->系统文件->%WinDir%\system32\*.exe


  39. 2007-11-06 13:31:56    运行应用程序      操作:允许
  40. 进程路径:C:\WINDOWS\system32\cmd.exe
  41. 文件路径:C:\WINDOWS\system32\conime.exe
  42. 触发规则:所有程序规则->*


  43. 2007-11-06 13:31:56    运行应用程序      操作:允许
  44. 进程路径:C:\WINDOWS\system32\cmd.exe
  45. 文件路径:C:\WINDOWS\system32\conime.exe
  46. 触发规则:所有程序规则->*


  47. 2007-11-06 13:31:56    运行应用程序      操作:允许
  48. 进程路径:C:\WINDOWS\system32\cmd.exe
  49. 文件路径:C:\WINDOWS\system32\conime.exe
  50. 触发规则:所有程序规则->*


  51. 2007-11-06 13:31:56    创建注册表值      操作:允许
  52. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  53. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com
  54. 注册表名称:Debugger
  55. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  56. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  57. 2007-11-06 13:31:57    运行应用程序      操作:允许
  58. 进程路径:C:\WINDOWS\system32\cmd.exe
  59. 文件路径:C:\WINDOWS\system32\conime.exe
  60. 触发规则:所有程序规则->*


  61. 2007-11-06 13:31:57    运行应用程序      操作:允许
  62. 进程路径:C:\WINDOWS\system32\cmd.exe
  63. 文件路径:C:\WINDOWS\system32\conime.exe
  64. 触发规则:所有程序规则->*


  65. 2007-11-06 13:31:57    创建注册表值      操作:允许
  66. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  67. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe
  68. 注册表名称:[Key]
  69. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  70. 2007-11-06 13:31:57    运行应用程序      操作:允许
  71. 进程路径:C:\WINDOWS\system32\cmd.exe
  72. 文件路径:C:\WINDOWS\system32\conime.exe
  73. 触发规则:所有程序规则->*


  74. 2007-11-06 13:31:57    运行应用程序      操作:允许
  75. 进程路径:C:\WINDOWS\system32\cmd.exe
  76. 文件路径:C:\WINDOWS\system32\conime.exe
  77. 触发规则:所有程序规则->*


  78. 2007-11-06 13:31:57    运行应用程序      操作:允许
  79. 进程路径:C:\WINDOWS\system32\cmd.exe
  80. 文件路径:C:\WINDOWS\system32\conime.exe
  81. 触发规则:所有程序规则->*
复制代码
SONGBOWEN
发表于 2007-11-6 13:42:19 | 显示全部楼层
  1. 2007-11-06 13:31:58    运行应用程序      操作:允许
  2. 进程路径:C:\WINDOWS\system32\cmd.exe
  3. 文件路径:C:\WINDOWS\system32\conime.exe
  4. 触发规则:所有程序规则->*


  5. 2007-11-06 13:31:58    运行应用程序      操作:允许
  6. 进程路径:C:\WINDOWS\system32\cmd.exe
  7. 文件路径:C:\WINDOWS\system32\conime.exe
  8. 触发规则:所有程序规则->*


  9. 2007-11-06 13:31:58    创建注册表值      操作:允许
  10. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  11. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe
  12. 注册表名称:Debugger
  13. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  14. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  15. 2007-11-06 13:31:58    运行应用程序      操作:允许
  16. 进程路径:C:\WINDOWS\system32\cmd.exe
  17. 文件路径:C:\WINDOWS\system32\conime.exe
  18. 触发规则:所有程序规则->*


  19. 2007-11-06 13:31:58    运行应用程序      操作:允许
  20. 进程路径:C:\WINDOWS\system32\cmd.exe
  21. 文件路径:C:\WINDOWS\system32\conime.exe
  22. 触发规则:所有程序规则->*


  23. 2007-11-06 13:31:59    创建注册表值      操作:允许
  24. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  25. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe
  26. 注册表名称:[Key]
  27. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  28. 2007-11-06 13:32:00    创建注册表值      操作:允许
  29. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  30. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe
  31. 注册表名称:Debugger
  32. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  33. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  34. 2007-11-06 13:32:01    创建注册表值      操作:允许
  35. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  36. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe
  37. 注册表名称:[Key]
  38. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  39. 2007-11-06 13:32:02    创建注册表值      操作:允许
  40. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  41. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe
  42. 注册表名称:Debugger
  43. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  44. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  45. 2007-11-06 13:32:03    创建注册表值      操作:允许
  46. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  47. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FYFireWall.exe
  48. 注册表名称:[Key]
  49. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  50. 2007-11-06 13:32:04    创建注册表值      操作:允许
  51. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  52. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FYFireWall.exe
  53. 注册表名称:Debugger
  54. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  55. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  56. 2007-11-06 13:32:05    创建注册表值      操作:允许
  57. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  58. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe
  59. 注册表名称:[Key]
  60. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  61. 2007-11-06 13:32:06    创建注册表值      操作:允许
  62. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  63. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe
  64. 注册表名称:Debugger
  65. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  66. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  67. 2007-11-06 13:32:07    创建注册表值      操作:允许
  68. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  69. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe
  70. 注册表名称:[Key]
  71. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  72. 2007-11-06 13:32:08    创建注册表值      操作:允许
  73. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  74. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe
  75. 注册表名称:Debugger
  76. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  77. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  78. 2007-11-06 13:32:09    创建注册表值      操作:允许
  79. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  80. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPF.exe
  81. 注册表名称:[Key]
  82. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  83. 2007-11-06 13:32:10    创建注册表值      操作:允许
  84. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  85. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPF.exe
  86. 注册表名称:Debugger
  87. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  88. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*
复制代码
SONGBOWEN
发表于 2007-11-6 13:42:43 | 显示全部楼层
  1. 2007-11-06 13:32:11    创建注册表值      操作:允许
  2. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  3. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe
  4. 注册表名称:[Key]
  5. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  6. 2007-11-06 13:32:12    修改注册表内容      操作:允许
  7. 进程路径:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  8. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  9. 注册表名称:*
  10. 触发规则:所有程序规则->系统自动运行->*\SOFTWARE\Microsoft\Windows\CurrentVersion\Run*


  11. 2007-11-06 13:32:13    创建注册表值      操作:允许
  12. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  13. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe
  14. 注册表名称:Debugger
  15. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  16. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  17. 2007-11-06 13:32:13    创建注册表值      操作:允许
  18. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  19. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe
  20. 注册表名称:[Key]
  21. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  22. 2007-11-06 13:32:13    修改注册表内容      操作:允许
  23. 进程路径:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  24. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  25. 注册表名称:*
  26. 触发规则:所有程序规则->系统自动运行->*\SOFTWARE\Microsoft\Windows\CurrentVersion\Run*


  27. 2007-11-06 13:32:14    创建文件      操作:允许
  28. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  29. 文件路径:D:\autorun.inf
  30. 触发规则:所有程序规则->系统文件->?:\autorun.inf


  31. 2007-11-06 13:32:14    创建注册表值      操作:允许
  32. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  33. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe
  34. 注册表名称:Debugger
  35. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  36. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  37. 2007-11-06 13:32:14    创建注册表值      操作:允许
  38. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  39. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe
  40. 注册表名称:[Key]
  41. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  42. 2007-11-06 13:32:15    创建注册表值      操作:允许
  43. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  44. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe
  45. 注册表名称:Debugger
  46. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  47. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  48. 2007-11-06 13:32:16    创建注册表值      操作:允许
  49. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  50. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapsvc.exe
  51. 注册表名称:[Key]
  52. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  53. 2007-11-06 13:32:16    创建注册表值      操作:允许
  54. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  55. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapsvc.exe
  56. 注册表名称:Debugger
  57. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  58. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  59. 2007-11-06 13:32:16    创建注册表值      操作:允许
  60. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  61. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapw32.exe
  62. 注册表名称:[Key]
  63. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  64. 2007-11-06 13:32:16    创建注册表值      操作:允许
  65. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  66. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapw32.exe
  67. 注册表名称:Debugger
  68. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  69. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  70. 2007-11-06 13:32:16    创建注册表值      操作:允许
  71. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  72. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe
  73. 注册表名称:[Key]
  74. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  75. 2007-11-06 13:32:16    创建注册表值      操作:允许
  76. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  77. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe
  78. 注册表名称:Debugger
  79. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  80. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  81. 2007-11-06 13:32:17    创建注册表值      操作:允许
  82. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  83. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe
  84. 注册表名称:[Key]
  85. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*
复制代码
SONGBOWEN
发表于 2007-11-6 13:43:32 | 显示全部楼层
  1. 2007-11-06 13:32:17    创建注册表值      操作:允许
  2. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  3. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe
  4. 注册表名称:Debugger
  5. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  6. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  7. 2007-11-06 13:32:17    创建注册表值      操作:允许
  8. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  9. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPFMntor.exe
  10. 注册表名称:[Key]
  11. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  12. 2007-11-06 13:32:17    创建注册表值      操作:允许
  13. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  14. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPFMntor.exe
  15. 注册表名称:Debugger
  16. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  17. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  18. 2007-11-06 13:32:17    创建注册表值      操作:允许
  19. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  20. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe
  21. 注册表名称:[Key]
  22. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  23. 2007-11-06 13:32:18    创建注册表值      操作:允许
  24. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  25. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe
  26. 注册表名称:Debugger
  27. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  28. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  29. 2007-11-06 13:32:18    创建注册表值      操作:允许
  30. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  31. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zjb.exe
  32. 注册表名称:[Key]
  33. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  34. 2007-11-06 13:32:19    创建注册表值      操作:允许
  35. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  36. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zjb.exe
  37. 注册表名称:Debugger
  38. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  39. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  40. 2007-11-06 13:32:19    创建注册表值      操作:允许
  41. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  42. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPfwSvc.exe
  43. 注册表名称:[Key]
  44. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  45. 2007-11-06 13:32:19    创建注册表值      操作:允许
  46. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  47. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPfwSvc.exe
  48. 注册表名称:Debugger
  49. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  50. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  51. 2007-11-06 13:32:20    创建注册表值      操作:允许
  52. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  53. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe
  54. 注册表名称:[Key]
  55. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  56. 2007-11-06 13:32:20    创建注册表值      操作:允许
  57. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  58. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe
  59. 注册表名称:Debugger
  60. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  61. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  62. 2007-11-06 13:32:20    创建注册表值      操作:允许
  63. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  64. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe
  65. 注册表名称:[Key]
  66. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  67. 2007-11-06 13:32:20    创建注册表值      操作:允许
  68. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  69. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe
  70. 注册表名称:Debugger
  71. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  72. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  73. 2007-11-06 13:32:20    创建注册表值      操作:允许
  74. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  75. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe
  76. 注册表名称:[Key]
  77. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  78. 2007-11-06 13:32:20    创建注册表值      操作:允许
  79. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  80. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe
  81. 注册表名称:Debugger
  82. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  83. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  84. 2007-11-06 13:32:21    创建注册表值      操作:允许
  85. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  86. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmsk.exe
  87. 注册表名称:[Key]
  88. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*
复制代码
SONGBOWEN
发表于 2007-11-6 13:43:54 | 显示全部楼层
  1. 2007-11-06 13:32:21    创建注册表值      操作:允许
  2. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  3. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmsk.exe
  4. 注册表名称:Debugger
  5. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  6. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  7. 2007-11-06 13:32:21    创建注册表值      操作:允许
  8. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  9. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WoptiClean.exe
  10. 注册表名称:[Key]
  11. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  12. 2007-11-06 13:32:21    创建注册表值      操作:允许
  13. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  14. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WoptiClean.exe
  15. 注册表名称:Debugger
  16. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  17. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  18. 2007-11-06 13:32:22    创建注册表值      操作:允许
  19. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  20. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQKav.exe
  21. 注册表名称:[Key]
  22. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  23. 2007-11-06 13:32:22    创建注册表值      操作:允许
  24. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  25. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQKav.exe
  26. 注册表名称:Debugger
  27. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  28. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  29. 2007-11-06 13:32:22    创建注册表值      操作:允许
  30. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  31. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.exe
  32. 注册表名称:[Key]
  33. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  34. 2007-11-06 13:32:22    创建注册表值      操作:允许
  35. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  36. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.exe
  37. 注册表名称:Debugger
  38. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  39. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  40. 2007-11-06 13:32:22    创建注册表值      操作:允许
  41. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  42. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EGHOST.exe
  43. 注册表名称:[Key]
  44. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  45. 2007-11-06 13:32:23    创建注册表值      操作:允许
  46. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  47. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EGHOST.exe
  48. 注册表名称:Debugger
  49. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  50. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  51. 2007-11-06 13:32:23    创建注册表值      操作:允许
  52. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  53. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe
  54. 注册表名称:[Key]
  55. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  56. 2007-11-06 13:32:23    创建注册表值      操作:允许
  57. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  58. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe
  59. 注册表名称:Debugger
  60. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  61. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  62. 2007-11-06 13:32:23    创建注册表值      操作:允许
  63. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  64. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iparmo.exe
  65. 注册表名称:[Key]
  66. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  67. 2007-11-06 13:32:23    创建注册表值      操作:允许
  68. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  69. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iparmo.exe
  70. 注册表名称:Debugger
  71. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  72. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  73. 2007-11-06 13:32:24    创建注册表值      操作:允许
  74. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  75. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adam.exe
  76. 注册表名称:[Key]
  77. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  78. 2007-11-06 13:32:24    创建注册表值      操作:允许
  79. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  80. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adam.exe
  81. 注册表名称:Debugger
  82. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  83. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  84. 2007-11-06 13:32:24    创建注册表值      操作:允许
  85. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  86. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword.exe
  87. 注册表名称:[Key]
  88. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  89. 2007-11-06 13:32:24    创建注册表值      操作:允许
  90. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  91. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword.exe
  92. 注册表名称:Debugger
  93. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  94. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  95. 2007-11-06 13:32:25    创建注册表值      操作:允许
  96. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  97. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe
  98. 注册表名称:[Key]
  99. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  100. 2007-11-06 13:32:25    创建注册表值      操作:允许
  101. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  102. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe
  103. 注册表名称:Debugger
  104. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  105. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  106. 2007-11-06 13:32:25    创建注册表值      操作:允许
  107. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  108. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe
  109. 注册表名称:[Key]
  110. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*
复制代码
SONGBOWEN
发表于 2007-11-6 13:44:14 | 显示全部楼层
  1. 2007-11-06 13:32:25    创建注册表值      操作:允许
  2. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  3. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe
  4. 注册表名称:Debugger
  5. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  6. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  7. 2007-11-06 13:32:25    创建注册表值      操作:允许
  8. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  9. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AgentSvr.exe
  10. 注册表名称:[Key]
  11. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  12. 2007-11-06 13:32:26    创建注册表值      操作:允许
  13. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  14. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AgentSvr.exe
  15. 注册表名称:Debugger
  16. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  17. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  18. 2007-11-06 13:32:26    创建注册表值      操作:允许
  19. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  20. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe
  21. 注册表名称:[Key]
  22. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  23. 2007-11-06 13:32:26    创建注册表值      操作:允许
  24. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  25. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe
  26. 注册表名称:Debugger
  27. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  28. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  29. 2007-11-06 13:32:26    创建注册表值      操作:允许
  30. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  31. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe
  32. 注册表名称:[Key]
  33. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  34. 2007-11-06 13:32:27    创建注册表值      操作:允许
  35. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  36. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe
  37. 注册表名称:Debugger
  38. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  39. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  40. 2007-11-06 13:32:27    创建注册表值      操作:允许
  41. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  42. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe
  43. 注册表名称:[Key]
  44. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  45. 2007-11-06 13:32:27    创建注册表值      操作:允许
  46. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  47. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe
  48. 注册表名称:Debugger
  49. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  50. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  51. 2007-11-06 13:32:27    创建注册表值      操作:允许
  52. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  53. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe
  54. 注册表名称:[Key]
  55. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  56. 2007-11-06 13:32:27    创建注册表值      操作:允许
  57. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  58. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe
  59. 注册表名称:Debugger
  60. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  61. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  62. 2007-11-06 13:32:28    创建注册表值      操作:允许
  63. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  64. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe
  65. 注册表名称:[Key]
  66. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  67. 2007-11-06 13:32:28    创建注册表值      操作:允许
  68. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  69. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe
  70. 注册表名称:Debugger
  71. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  72. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  73. 2007-11-06 13:32:28    创建注册表值      操作:允许
  74. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  75. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe
  76. 注册表名称:[Key]
  77. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  78. 2007-11-06 13:32:28    创建注册表值      操作:允许
  79. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  80. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe
  81. 注册表名称:Debugger
  82. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  83. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  84. 2007-11-06 13:32:28    创建注册表值      操作:允许
  85. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  86. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileDsty.exe
  87. 注册表名称:[Key]
  88. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  89. 2007-11-06 13:32:29    创建注册表值      操作:允许
  90. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  91. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileDsty.exe
  92. 注册表名称:Debugger
  93. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  94. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  95. 2007-11-06 13:32:29    创建注册表值      操作:允许
  96. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  97. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.exe
  98. 注册表名称:[Key]
  99. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  100. 2007-11-06 13:32:29    创建注册表值      操作:允许
  101. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  102. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.exe
  103. 注册表名称:Debugger
  104. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  105. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  106. 2007-11-06 13:32:29    创建注册表值      操作:允许
  107. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  108. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe
  109. 注册表名称:[Key]
  110. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  111. 2007-11-06 13:32:30    创建注册表值      操作:允许
  112. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  113. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe
  114. 注册表名称:Debugger
  115. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  116. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*
复制代码
SONGBOWEN
发表于 2007-11-6 13:44:46 | 显示全部楼层
  1. 2007-11-06 13:32:25    创建注册表值      操作:允许
  2. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  3. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe
  4. 注册表名称:Debugger
  5. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  6. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  7. 2007-11-06 13:32:25    创建注册表值      操作:允许
  8. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  9. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AgentSvr.exe
  10. 注册表名称:[Key]
  11. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  12. 2007-11-06 13:32:26    创建注册表值      操作:允许
  13. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  14. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AgentSvr.exe
  15. 注册表名称:Debugger
  16. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  17. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  18. 2007-11-06 13:32:26    创建注册表值      操作:允许
  19. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  20. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe
  21. 注册表名称:[Key]
  22. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  23. 2007-11-06 13:32:26    创建注册表值      操作:允许
  24. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  25. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe
  26. 注册表名称:Debugger
  27. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  28. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  29. 2007-11-06 13:32:26    创建注册表值      操作:允许
  30. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  31. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe
  32. 注册表名称:[Key]
  33. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  34. 2007-11-06 13:32:27    创建注册表值      操作:允许
  35. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  36. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe
  37. 注册表名称:Debugger
  38. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  39. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  40. 2007-11-06 13:32:27    创建注册表值      操作:允许
  41. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  42. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe
  43. 注册表名称:[Key]
  44. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  45. 2007-11-06 13:32:27    创建注册表值      操作:允许
  46. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  47. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe
  48. 注册表名称:Debugger
  49. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  50. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  51. 2007-11-06 13:32:27    创建注册表值      操作:允许
  52. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  53. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe
  54. 注册表名称:[Key]
  55. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  56. 2007-11-06 13:32:27    创建注册表值      操作:允许
  57. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  58. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe
  59. 注册表名称:Debugger
  60. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  61. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  62. 2007-11-06 13:32:28    创建注册表值      操作:允许
  63. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  64. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe
  65. 注册表名称:[Key]
  66. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  67. 2007-11-06 13:32:28    创建注册表值      操作:允许
  68. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  69. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe
  70. 注册表名称:Debugger
  71. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  72. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  73. 2007-11-06 13:32:28    创建注册表值      操作:允许
  74. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  75. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe
  76. 注册表名称:[Key]
  77. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  78. 2007-11-06 13:32:28    创建注册表值      操作:允许
  79. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  80. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe
  81. 注册表名称:Debugger
  82. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  83. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  84. 2007-11-06 13:32:28    创建注册表值      操作:允许
  85. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  86. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileDsty.exe
  87. 注册表名称:[Key]
  88. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  89. 2007-11-06 13:32:29    创建注册表值      操作:允许
  90. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  91. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileDsty.exe
  92. 注册表名称:Debugger
  93. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  94. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  95. 2007-11-06 13:32:29    创建注册表值      操作:允许
  96. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  97. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.exe
  98. 注册表名称:[Key]
  99. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  100. 2007-11-06 13:32:29    创建注册表值      操作:允许
  101. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  102. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.exe
  103. 注册表名称:Debugger
  104. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  105. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  106. 2007-11-06 13:32:29    创建注册表值      操作:允许
  107. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  108. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe
  109. 注册表名称:[Key]
  110. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  111. 2007-11-06 13:32:30    创建注册表值      操作:允许
  112. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  113. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe
  114. 注册表名称:Debugger
  115. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  116. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*
复制代码
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-18 07:28 , Processed in 0.095705 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表