楼主: tiancun
收起左侧

[病毒样本] 卡巴不报!MD5: FCC8C6

[复制链接]
SONGBOWEN
发表于 2007-11-6 13:45:09 | 显示全部楼层
  1. 2007-11-06 13:32:30    创建注册表值      操作:允许
  2. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  3. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.exe
  4. 注册表名称:[Key]
  5. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  6. 2007-11-06 13:32:30    创建注册表值      操作:允许
  7. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  8. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.exe
  9. 注册表名称:Debugger
  10. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  11. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  12. 2007-11-06 13:32:30    创建注册表值      操作:允许
  13. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  14. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isPwdSvc.exe
  15. 注册表名称:[Key]
  16. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  17. 2007-11-06 13:32:30    创建注册表值      操作:允许
  18. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  19. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isPwdSvc.exe
  20. 注册表名称:Debugger
  21. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  22. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  23. 2007-11-06 13:32:31    创建注册表值      操作:允许
  24. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  25. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kabaload.exe
  26. 注册表名称:[Key]
  27. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  28. 2007-11-06 13:32:31    创建注册表值      操作:允许
  29. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  30. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kabaload.exe
  31. 注册表名称:Debugger
  32. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  33. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  34. 2007-11-06 13:32:31    创建注册表值      操作:允许
  35. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  36. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KaScrScn.SCR
  37. 注册表名称:[Key]
  38. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  39. 2007-11-06 13:32:31    创建注册表值      操作:允许
  40. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  41. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KaScrScn.SCR
  42. 注册表名称:Debugger
  43. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  44. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  45. 2007-11-06 13:32:32    创建注册表值      操作:允许
  46. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  47. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASMain.exe
  48. 注册表名称:[Key]
  49. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  50. 2007-11-06 13:32:32    创建注册表值      操作:允许
  51. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  52. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASMain.exe
  53. 注册表名称:Debugger
  54. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  55. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  56. 2007-11-06 13:32:32    创建注册表值      操作:允许
  57. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  58. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASTask.exe
  59. 注册表名称:[Key]
  60. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  61. 2007-11-06 13:32:32    创建注册表值      操作:允许
  62. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  63. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASTask.exe
  64. 注册表名称:Debugger
  65. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  66. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  67. 2007-11-06 13:32:33    创建注册表值      操作:允许
  68. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  69. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAV32.exe
  70. 注册表名称:[Key]
  71. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  72. 2007-11-06 13:32:33    创建注册表值      操作:允许
  73. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  74. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAV32.exe
  75. 注册表名称:Debugger
  76. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  77. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  78. 2007-11-06 13:32:33    创建注册表值      操作:允许
  79. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  80. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVDX.exe
  81. 注册表名称:[Key]
  82. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  83. 2007-11-06 13:32:34    创建注册表值      操作:允许
  84. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  85. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVDX.exe
  86. 注册表名称:Debugger
  87. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  88. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  89. 2007-11-06 13:32:34    创建注册表值      操作:允许
  90. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  91. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPFW.exe
  92. 注册表名称:[Key]
  93. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  94. 2007-11-06 13:32:34    创建注册表值      操作:允许
  95. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  96. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPFW.exe
  97. 注册表名称:Debugger
  98. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  99. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  100. 2007-11-06 13:32:34    创建注册表值      操作:允许
  101. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  102. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVSetup.exe
  103. 注册表名称:[Key]
  104. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  105. 2007-11-06 13:32:35    创建注册表值      操作:允许
  106. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  107. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVSetup.exe
  108. 注册表名称:Debugger
  109. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  110. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  111. 2007-11-06 13:32:35    创建注册表值      操作:允许
  112. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  113. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVStart.exe
  114. 注册表名称:[Key]
  115. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  116. 2007-11-06 13:32:35    创建注册表值      操作:允许
  117. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  118. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVStart.exe
  119. 注册表名称:Debugger
  120. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  121. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  122. 2007-11-06 13:32:35    创建注册表值      操作:允许
  123. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  124. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KISLnchr.exe
  125. 注册表名称:[Key]
  126. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*
复制代码
SONGBOWEN
发表于 2007-11-6 13:45:30 | 显示全部楼层
  1. 2007-11-06 13:32:35    创建注册表值      操作:允许
  2. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  3. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KISLnchr.exe
  4. 注册表名称:Debugger
  5. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  6. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  7. 2007-11-06 13:32:36    创建注册表值      操作:允许
  8. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  9. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMailMon.exe
  10. 注册表名称:[Key]
  11. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  12. 2007-11-06 13:32:36    创建注册表值      操作:允许
  13. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  14. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMailMon.exe
  15. 注册表名称:Debugger
  16. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  17. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  18. 2007-11-06 13:32:36    创建注册表值      操作:允许
  19. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  20. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMFilter.exe
  21. 注册表名称:[Key]
  22. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  23. 2007-11-06 13:32:36    创建注册表值      操作:允许
  24. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  25. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMFilter.exe
  26. 注册表名称:Debugger
  27. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  28. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  29. 2007-11-06 13:32:37    修改注册表内容      操作:允许
  30. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  31. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe
  32. 注册表名称:Debugger
  33. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  34. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  35. 2007-11-06 13:32:37    创建注册表值      操作:允许
  36. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  37. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32X.exe
  38. 注册表名称:[Key]
  39. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  40. 2007-11-06 13:32:37    创建注册表值      操作:允许
  41. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  42. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32X.exe
  43. 注册表名称:Debugger
  44. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  45. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  46. 2007-11-06 13:32:37    修改注册表内容      操作:允许
  47. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  48. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPfwSvc.exe
  49. 注册表名称:Debugger
  50. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  51. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  52. 2007-11-06 13:32:38    创建注册表值      操作:允许
  53. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  54. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.exe
  55. 注册表名称:[Key]
  56. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  57. 2007-11-06 13:32:38    创建注册表值      操作:允许
  58. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  59. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.exe
  60. 注册表名称:Debugger
  61. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  62. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  63. 2007-11-06 13:32:38    创建注册表值      操作:允许
  64. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  65. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KsLoader.exe
  66. 注册表名称:[Key]
  67. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  68. 2007-11-06 13:32:38    创建注册表值      操作:允许
  69. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  70. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KsLoader.exe
  71. 注册表名称:Debugger
  72. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  73. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  74. 2007-11-06 13:32:38    创建注册表值      操作:允许
  75. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  76. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVCenter.kxp
  77. 注册表名称:[Key]
  78. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  79. 2007-11-06 13:32:39    创建注册表值      操作:允许
  80. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  81. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVCenter.kxp
  82. 注册表名称:Debugger
  83. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  84. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  85. 2007-11-06 13:32:39    创建注册表值      操作:允许
  86. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  87. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvDetect.exe
  88. 注册表名称:[Key]
  89. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  90. 2007-11-06 13:32:39    创建注册表值      操作:允许
  91. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  92. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvDetect.exe
  93. 注册表名称:Debugger
  94. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  95. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  96. 2007-11-06 13:32:39    创建注册表值      操作:允许
  97. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  98. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvfwMcl.exe
  99. 注册表名称:[Key]
  100. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  101. 2007-11-06 13:32:39    创建注册表值      操作:允许
  102. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  103. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvfwMcl.exe
  104. 注册表名称:Debugger
  105. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  106. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  107. 2007-11-06 13:32:40    创建注册表值      操作:允许
  108. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  109. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP.kxp
  110. 注册表名称:[Key]
  111. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  112. 2007-11-06 13:32:40    创建注册表值      操作:允许
  113. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  114. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP.kxp
  115. 注册表名称:Debugger
  116. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  117. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  118. 2007-11-06 13:32:40    创建注册表值      操作:允许
  119. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  120. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP_1.kxp
  121. 注册表名称:[Key]
  122. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  123. 2007-11-06 13:32:40    创建注册表值      操作:允许
  124. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  125. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP_1.kxp
  126. 注册表名称:Debugger
  127. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  128. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  129. 2007-11-06 13:32:40    创建注册表值      操作:允许
  130. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  131. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvol.exe
  132. 注册表名称:[Key]
  133. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  134. 2007-11-06 13:32:41    创建注册表值      操作:允许
  135. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  136. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvol.exe
  137. 注册表名称:Debugger
  138. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  139. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*
复制代码
SONGBOWEN
发表于 2007-11-6 13:46:00 | 显示全部楼层
  1. 2007-11-06 13:32:41    创建注册表值      操作:允许
  2. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  3. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvolself.exe
  4. 注册表名称:[Key]
  5. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  6. 2007-11-06 13:32:41    创建注册表值      操作:允许
  7. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  8. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvolself.exe
  9. 注册表名称:Debugger
  10. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  11. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  12. 2007-11-06 13:32:41    创建注册表值      操作:允许
  13. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  14. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVScan.kxp
  15. 注册表名称:[Key]
  16. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  17. 2007-11-06 13:32:41    创建注册表值      操作:允许
  18. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  19. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVScan.kxp
  20. 注册表名称:Debugger
  21. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  22. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  23. 2007-11-06 13:32:42    创建注册表值      操作:允许
  24. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  25. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVSrvXP.exe
  26. 注册表名称:[Key]
  27. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  28. 2007-11-06 13:32:42    创建注册表值      操作:允许
  29. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  30. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVSrvXP.exe
  31. 注册表名称:Debugger
  32. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  33. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  34. 2007-11-06 13:32:42    创建注册表值      操作:允许
  35. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  36. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVStub.kxp
  37. 注册表名称:[Key]
  38. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  39. 2007-11-06 13:32:43    创建注册表值      操作:允许
  40. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  41. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVStub.kxp
  42. 注册表名称:Debugger
  43. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  44. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  45. 2007-11-06 13:32:43    创建注册表值      操作:允许
  46. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  47. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvupload.exe
  48. 注册表名称:[Key]
  49. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  50. 2007-11-06 13:32:43    创建注册表值      操作:允许
  51. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  52. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvupload.exe
  53. 注册表名称:Debugger
  54. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  55. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  56. 2007-11-06 13:32:43    创建注册表值      操作:允许
  57. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  58. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvwsc.exe
  59. 注册表名称:[Key]
  60. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  61. 2007-11-06 13:32:44    创建注册表值      操作:允许
  62. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  63. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvwsc.exe
  64. 注册表名称:Debugger
  65. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  66. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  67. 2007-11-06 13:32:45    创建注册表值      操作:允许
  68. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  69. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP.kxp
  70. 注册表名称:[Key]
  71. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  72. 2007-11-06 13:32:45    创建注册表值      操作:允许
  73. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  74. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP.kxp
  75. 注册表名称:Debugger
  76. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  77. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  78. 2007-11-06 13:32:45    创建注册表值      操作:允许
  79. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  80. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP_1.kxp
  81. 注册表名称:[Key]
  82. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  83. 2007-11-06 13:32:45    创建注册表值      操作:允许
  84. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  85. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP_1.kxp
  86. 注册表名称:Debugger
  87. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  88. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  89. 2007-11-06 13:32:45    创建注册表值      操作:允许
  90. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  91. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch.exe
  92. 注册表名称:[Key]
  93. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  94. 2007-11-06 13:32:46    创建注册表值      操作:允许
  95. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  96. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch.exe
  97. 注册表名称:Debugger
  98. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  99. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  100. 2007-11-06 13:32:46    创建注册表值      操作:允许
  101. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  102. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch9x.exe
  103. 注册表名称:[Key]
  104. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  105. 2007-11-06 13:32:46    创建注册表值      操作:允许
  106. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  107. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch9x.exe
  108. 注册表名称:Debugger
  109. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  110. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  111. 2007-11-06 13:32:46    创建注册表值      操作:允许
  112. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  113. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatchX.exe
  114. 注册表名称:[Key]
  115. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  116. 2007-11-06 13:32:46    创建注册表值      操作:允许
  117. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  118. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatchX.exe
  119. 注册表名称:Debugger
  120. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  121. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  122. 2007-11-06 13:32:47    创建注册表值      操作:允许
  123. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  124. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\loaddll.exe
  125. 注册表名称:[Key]
  126. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  127. 2007-11-06 13:32:47    创建注册表值      操作:允许
  128. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  129. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\loaddll.exe
  130. 注册表名称:Debugger
  131. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  132. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  133. 2007-11-06 13:32:47    创建注册表值      操作:允许
  134. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  135. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MagicSet.exe
  136. 注册表名称:[Key]
  137. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  138. 2007-11-06 13:32:47    创建注册表值      操作:允许
  139. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  140. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MagicSet.exe
  141. 注册表名称:Debugger
  142. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  143. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  144. 2007-11-06 13:32:47    创建注册表值      操作:允许
  145. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  146. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcconsol.exe
  147. 注册表名称:[Key]
  148. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  149. 2007-11-06 13:32:48    创建注册表值      操作:允许
  150. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  151. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcconsol.exe
  152. 注册表名称:Debugger
  153. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  154. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  155. 2007-11-06 13:32:48    创建注册表值      操作:允许
  156. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  157. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmqczj.exe
  158. 注册表名称:[Key]
  159. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  160. 2007-11-06 13:32:48    创建注册表值      操作:允许
  161. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  162. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmqczj.exe
  163. 注册表名称:Debugger
  164. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  165. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  166. 2007-11-06 13:32:48    创建注册表值      操作:允许
  167. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  168. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.exe
  169. 注册表名称:[Key]
  170. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  171. 2007-11-06 13:32:48    创建注册表值      操作:允许
  172. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  173. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.exe
  174. 注册表名称:Debugger
  175. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  176. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*
复制代码
SONGBOWEN
发表于 2007-11-6 13:46:20 | 显示全部楼层
  1. 2007-11-06 13:32:49    创建注册表值      操作:允许
  2. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  3. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.exe
  4. 注册表名称:[Key]
  5. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  6. 2007-11-06 13:32:49    创建注册表值      操作:允许
  7. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  8. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.exe
  9. 注册表名称:Debugger
  10. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  11. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  12. 2007-11-06 13:32:49    创建注册表值      操作:允许
  13. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  14. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QHSET.exe
  15. 注册表名称:[Key]
  16. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  17. 2007-11-06 13:32:49    创建注册表值      操作:允许
  18. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  19. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QHSET.exe
  20. 注册表名称:Debugger
  21. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  22. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  23. 2007-11-06 13:32:49    创建注册表值      操作:允许
  24. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  25. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe
  26. 注册表名称:[Key]
  27. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  28. 2007-11-06 13:32:50    创建注册表值      操作:允许
  29. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  30. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe
  31. 注册表名称:Debugger
  32. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  33. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  34. 2007-11-06 13:32:50    创建注册表值      操作:允许
  35. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  36. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe
  37. 注册表名称:[Key]
  38. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  39. 2007-11-06 13:32:50    创建注册表值      操作:允许
  40. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  41. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe
  42. 注册表名称:Debugger
  43. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  44. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  45. 2007-11-06 13:32:50    创建注册表值      操作:允许
  46. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  47. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegClean.exe
  48. 注册表名称:[Key]
  49. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  50. 2007-11-06 13:32:50    创建注册表值      操作:允许
  51. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  52. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegClean.exe
  53. 注册表名称:Debugger
  54. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  55. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  56. 2007-11-06 13:32:51    创建注册表值      操作:允许
  57. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  58. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe
  59. 注册表名称:[Key]
  60. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  61. 2007-11-06 13:32:51    创建注册表值      操作:允许
  62. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  63. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe
  64. 注册表名称:Debugger
  65. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  66. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  67. 2007-11-06 13:32:51    修改注册表内容      操作:允许
  68. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  69. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe
  70. 注册表名称:Debugger
  71. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  72. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  73. 2007-11-06 13:32:51    创建注册表值      操作:允许
  74. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  75. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsAgent.exe
  76. 注册表名称:[Key]
  77. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  78. 2007-11-06 13:32:51    创建注册表值      操作:允许
  79. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  80. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsAgent.exe
  81. 注册表名称:Debugger
  82. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  83. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  84. 2007-11-06 13:32:52    创建注册表值      操作:允许
  85. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  86. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rsaupd.exe
  87. 注册表名称:[Key]
  88. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  89. 2007-11-06 13:32:52    创建注册表值      操作:允许
  90. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  91. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rsaupd.exe
  92. 注册表名称:Debugger
  93. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  94. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  95. 2007-11-06 13:32:52    创建注册表值      操作:允许
  96. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  97. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safelive.exe
  98. 注册表名称:[Key]
  99. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  100. 2007-11-06 13:32:52    创建注册表值      操作:允许
  101. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  102. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safelive.exe
  103. 注册表名称:Debugger
  104. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  105. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  106. 2007-11-06 13:32:52    创建注册表值      操作:允许
  107. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  108. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\irsetup.exe
  109. 注册表名称:[Key]
  110. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  111. 2007-11-06 13:32:53    创建注册表值      操作:允许
  112. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  113. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\irsetup.exe
  114. 注册表名称:Debugger
  115. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  116. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  117. 2007-11-06 13:32:53    创建注册表值      操作:允许
  118. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  119. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe
  120. 注册表名称:[Key]
  121. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  122. 2007-11-06 13:32:53    创建注册表值      操作:允许
  123. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  124. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe
  125. 注册表名称:Debugger
  126. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  127. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  128. 2007-11-06 13:32:53    创建注册表值      操作:允许
  129. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  130. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shcfg32.exe
  131. 注册表名称:[Key]
  132. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  133. 2007-11-06 13:32:53    创建注册表值      操作:允许
  134. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  135. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shcfg32.exe
  136. 注册表名称:Debugger
  137. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  138. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  139. 2007-11-06 13:32:54    创建注册表值      操作:允许
  140. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  141. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe
  142. 注册表名称:[Key]
  143. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  144. 2007-11-06 13:32:54    创建注册表值      操作:允许
  145. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  146. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe
  147. 注册表名称:Debugger
  148. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  149. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  150. 2007-11-06 13:32:54    创建注册表值      操作:允许
  151. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  152. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREng.EXE
  153. 注册表名称:[Key]
  154. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  155. 2007-11-06 13:32:54    创建注册表值      操作:允许
  156. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  157. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREng.EXE
  158. 注册表名称:Debugger
  159. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  160. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  161. 2007-11-06 13:32:55    创建注册表值      操作:允许
  162. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  163. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe
  164. 注册表名称:[Key]
  165. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  166. 2007-11-06 13:32:55    创建注册表值      操作:允许
  167. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  168. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe
  169. 注册表名称:Debugger
  170. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  171. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  172. 2007-11-06 13:32:55    创建注册表值      操作:允许
  173. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  174. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysSafe.exe
  175. 注册表名称:[Key]
  176. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  177. 2007-11-06 13:32:55    创建注册表值      操作:允许
  178. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  179. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysSafe.exe
  180. 注册表名称:Debugger
  181. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  182. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  183. 2007-11-06 13:32:55    创建注册表值      操作:允许
  184. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  185. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.exe
  186. 注册表名称:[Key]
  187. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  188. 2007-11-06 13:32:56    创建注册表值      操作:允许
  189. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  190. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.exe
  191. 注册表名称:Debugger
  192. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  193. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  194. 2007-11-06 13:32:56    创建注册表值      操作:允许
  195. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  196. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.exe
  197. 注册表名称:[Key]
  198. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  199. 2007-11-06 13:32:56    创建注册表值      操作:允许
  200. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  201. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.exe
  202. 注册表名称:Debugger
  203. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  204. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*
复制代码
SONGBOWEN
发表于 2007-11-6 13:46:44 | 显示全部楼层
  1. 2007-11-06 13:32:49    创建注册表值      操作:允许
  2. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  3. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.exe
  4. 注册表名称:[Key]
  5. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  6. 2007-11-06 13:32:49    创建注册表值      操作:允许
  7. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  8. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.exe
  9. 注册表名称:Debugger
  10. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  11. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  12. 2007-11-06 13:32:49    创建注册表值      操作:允许
  13. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  14. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QHSET.exe
  15. 注册表名称:[Key]
  16. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  17. 2007-11-06 13:32:49    创建注册表值      操作:允许
  18. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  19. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QHSET.exe
  20. 注册表名称:Debugger
  21. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  22. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  23. 2007-11-06 13:32:49    创建注册表值      操作:允许
  24. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  25. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe
  26. 注册表名称:[Key]
  27. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  28. 2007-11-06 13:32:50    创建注册表值      操作:允许
  29. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  30. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe
  31. 注册表名称:Debugger
  32. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  33. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  34. 2007-11-06 13:32:50    创建注册表值      操作:允许
  35. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  36. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe
  37. 注册表名称:[Key]
  38. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  39. 2007-11-06 13:32:50    创建注册表值      操作:允许
  40. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  41. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe
  42. 注册表名称:Debugger
  43. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  44. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  45. 2007-11-06 13:32:50    创建注册表值      操作:允许
  46. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  47. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegClean.exe
  48. 注册表名称:[Key]
  49. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  50. 2007-11-06 13:32:50    创建注册表值      操作:允许
  51. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  52. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegClean.exe
  53. 注册表名称:Debugger
  54. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  55. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  56. 2007-11-06 13:32:51    创建注册表值      操作:允许
  57. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  58. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe
  59. 注册表名称:[Key]
  60. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  61. 2007-11-06 13:32:51    创建注册表值      操作:允许
  62. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  63. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe
  64. 注册表名称:Debugger
  65. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  66. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  67. 2007-11-06 13:32:51    修改注册表内容      操作:允许
  68. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  69. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe
  70. 注册表名称:Debugger
  71. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  72. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  73. 2007-11-06 13:32:51    创建注册表值      操作:允许
  74. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  75. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsAgent.exe
  76. 注册表名称:[Key]
  77. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  78. 2007-11-06 13:32:51    创建注册表值      操作:允许
  79. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  80. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsAgent.exe
  81. 注册表名称:Debugger
  82. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  83. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  84. 2007-11-06 13:32:52    创建注册表值      操作:允许
  85. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  86. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rsaupd.exe
  87. 注册表名称:[Key]
  88. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  89. 2007-11-06 13:32:52    创建注册表值      操作:允许
  90. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  91. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rsaupd.exe
  92. 注册表名称:Debugger
  93. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  94. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  95. 2007-11-06 13:32:52    创建注册表值      操作:允许
  96. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  97. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safelive.exe
  98. 注册表名称:[Key]
  99. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  100. 2007-11-06 13:32:52    创建注册表值      操作:允许
  101. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  102. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safelive.exe
  103. 注册表名称:Debugger
  104. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  105. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  106. 2007-11-06 13:32:52    创建注册表值      操作:允许
  107. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  108. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\irsetup.exe
  109. 注册表名称:[Key]
  110. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  111. 2007-11-06 13:32:53    创建注册表值      操作:允许
  112. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  113. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\irsetup.exe
  114. 注册表名称:Debugger
  115. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  116. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  117. 2007-11-06 13:32:53    创建注册表值      操作:允许
  118. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  119. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe
  120. 注册表名称:[Key]
  121. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  122. 2007-11-06 13:32:53    创建注册表值      操作:允许
  123. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  124. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe
  125. 注册表名称:Debugger
  126. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  127. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  128. 2007-11-06 13:32:53    创建注册表值      操作:允许
  129. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  130. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shcfg32.exe
  131. 注册表名称:[Key]
  132. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  133. 2007-11-06 13:32:53    创建注册表值      操作:允许
  134. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  135. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shcfg32.exe
  136. 注册表名称:Debugger
  137. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  138. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  139. 2007-11-06 13:32:54    创建注册表值      操作:允许
  140. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  141. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe
  142. 注册表名称:[Key]
  143. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  144. 2007-11-06 13:32:54    创建注册表值      操作:允许
  145. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  146. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe
  147. 注册表名称:Debugger
  148. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  149. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  150. 2007-11-06 13:32:54    创建注册表值      操作:允许
  151. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  152. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREng.EXE
  153. 注册表名称:[Key]
  154. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  155. 2007-11-06 13:32:54    创建注册表值      操作:允许
  156. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  157. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREng.EXE
  158. 注册表名称:Debugger
  159. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  160. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  161. 2007-11-06 13:32:55    创建注册表值      操作:允许
  162. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  163. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe
  164. 注册表名称:[Key]
  165. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  166. 2007-11-06 13:32:55    创建注册表值      操作:允许
  167. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  168. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe
  169. 注册表名称:Debugger
  170. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  171. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  172. 2007-11-06 13:32:55    创建注册表值      操作:允许
  173. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  174. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysSafe.exe
  175. 注册表名称:[Key]
  176. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  177. 2007-11-06 13:32:55    创建注册表值      操作:允许
  178. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  179. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysSafe.exe
  180. 注册表名称:Debugger
  181. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  182. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  183. 2007-11-06 13:32:55    创建注册表值      操作:允许
  184. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  185. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.exe
  186. 注册表名称:[Key]
  187. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  188. 2007-11-06 13:32:56    创建注册表值      操作:允许
  189. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  190. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.exe
  191. 注册表名称:Debugger
  192. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  193. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  194. 2007-11-06 13:32:56    创建注册表值      操作:允许
  195. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  196. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.exe
  197. 注册表名称:[Key]
  198. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  199. 2007-11-06 13:32:56    创建注册表值      操作:允许
  200. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  201. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.exe
  202. 注册表名称:Debugger
  203. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  204. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*
复制代码
SONGBOWEN
发表于 2007-11-6 13:48:19 | 显示全部楼层
  1. 2007-11-06 13:32:56    创建注册表值      操作:允许
  2. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  3. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.kxp
  4. 注册表名称:[Key]
  5. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  6. 2007-11-06 13:32:57    创建注册表值      操作:允许
  7. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  8. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.kxp
  9. 注册表名称:Debugger
  10. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  11. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  12. 2007-11-06 13:32:57    创建注册表值      操作:允许
  13. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  14. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UIHost.exe
  15. 注册表名称:[Key]
  16. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  17. 2007-11-06 13:32:57    创建注册表值      操作:允许
  18. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  19. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UIHost.exe
  20. 注册表名称:Debugger
  21. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  22. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  23. 2007-11-06 13:32:57    创建注册表值      操作:允许
  24. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  25. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAgent.exe
  26. 注册表名称:[Key]
  27. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  28. 2007-11-06 13:32:58    创建注册表值      操作:允许
  29. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  30. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAgent.exe
  31. 注册表名称:Debugger
  32. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  33. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  34. 2007-11-06 13:32:58    创建注册表值      操作:允许
  35. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  36. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAttachment.exe
  37. 注册表名称:[Key]
  38. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  39. 2007-11-06 13:32:58    创建注册表值      操作:允许
  40. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  41. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAttachment.exe
  42. 注册表名称:Debugger
  43. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  44. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  45. 2007-11-06 13:32:58    创建注册表值      操作:允许
  46. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  47. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxCfg.exe
  48. 注册表名称:[Key]
  49. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  50. 2007-11-06 13:32:58    创建注册表值      操作:允许
  51. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  52. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxCfg.exe
  53. 注册表名称:Debugger
  54. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  55. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  56. 2007-11-06 13:32:58    创建注册表值      操作:允许
  57. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  58. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxFwHlp.exe
  59. 注册表名称:[Key]
  60. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  61. 2007-11-06 13:32:59    创建注册表值      操作:允许
  62. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  63. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxFwHlp.exe
  64. 注册表名称:Debugger
  65. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  66. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  67. 2007-11-06 13:32:59    创建注册表值      操作:允许
  68. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  69. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxPol.exe
  70. 注册表名称:[Key]
  71. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  72. 2007-11-06 13:32:59    创建注册表值      操作:允许
  73. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  74. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxPol.exe
  75. 注册表名称:Debugger
  76. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  77. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  78. 2007-11-06 13:32:59    创建注册表值      操作:允许
  79. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  80. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpLive.exe
  81. 注册表名称:[Key]
  82. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  83. 2007-11-06 13:33:00    创建注册表值      操作:允许
  84. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  85. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpLive.exe
  86. 注册表名称:Debugger
  87. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  88. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  89. 2007-11-06 13:33:00    创建注册表值      操作:允许
  90. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  91. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\upiea.exe
  92. 注册表名称:[Key]
  93. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  94. 2007-11-06 13:33:00    创建注册表值      操作:允许
  95. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  96. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\upiea.exe
  97. 注册表名称:Debugger
  98. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  99. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  100. 2007-11-06 13:33:00    创建注册表值      操作:允许
  101. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  102. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AST.exe
  103. 注册表名称:[Key]
  104. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  105. 2007-11-06 13:33:00    创建注册表值      操作:允许
  106. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  107. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AST.exe
  108. 注册表名称:Debugger
  109. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  110. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  111. 2007-11-06 13:33:01    创建注册表值      操作:允许
  112. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  113. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp.exe
  114. 注册表名称:[Key]
  115. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  116. 2007-11-06 13:33:01    创建注册表值      操作:允许
  117. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  118. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp.exe
  119. 注册表名称:Debugger
  120. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  121. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  122. 2007-11-06 13:33:01    创建注册表值      操作:允许
  123. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  124. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USBCleaner.exe
  125. 注册表名称:[Key]
  126. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  127. 2007-11-06 13:33:01    创建注册表值      操作:允许
  128. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  129. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USBCleaner.exe
  130. 注册表名称:Debugger
  131. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  132. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  133. 2007-11-06 13:33:01    创建注册表值      操作:允许
  134. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  135. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe
  136. 注册表名称:[Key]
  137. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  138. 2007-11-06 13:33:02    创建注册表值      操作:允许
  139. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  140. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe
  141. 注册表名称:Debugger
  142. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  143. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  144. 2007-11-06 13:33:02    创建注册表值      操作:允许
  145. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  146. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvReport.kxp
  147. 注册表名称:[Key]
  148. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  149. 2007-11-06 13:33:02    创建注册表值      操作:允许
  150. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  151. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvReport.kxp
  152. 注册表名称:Debugger
  153. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  154. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  155. 2007-11-06 13:33:02    创建注册表值      操作:允许
  156. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  157. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQSC.exe
  158. 注册表名称:[Key]
  159. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  160. 2007-11-06 13:33:02    创建注册表值      操作:允许
  161. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  162. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQSC.exe
  163. 注册表名称:Debugger
  164. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  165. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  166. 2007-11-06 13:33:03    创建注册表值      操作:允许
  167. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  168. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ghost.exe
  169. 注册表名称:[Key]
  170. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  171. 2007-11-06 13:33:03    创建注册表值      操作:允许
  172. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  173. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ghost.exe
  174. 注册表名称:Debugger
  175. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  176. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  177. 2007-11-06 13:33:03    创建注册表值      操作:允许
  178. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  179. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastU3.exe
  180. 注册表名称:[Key]
  181. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  182. 2007-11-06 13:33:03    创建注册表值      操作:允许
  183. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  184. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastU3.exe
  185. 注册表名称:Debugger
  186. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  187. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  188. 2007-11-06 13:33:04    创建注册表值      操作:允许
  189. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  190. 注册表路径:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRepair.com
  191. 注册表名称:[Key]
  192. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  193. 2007-11-06 13:33:04    创建注册表值      操作:允许
  194. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  195. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRepair.com
  196. 注册表名称:Debugger
  197. 注册表数据:C:\Program Files\Common Files\Microsoft Shared\cmvrsaw.exe
  198. 触发规则:所有程序规则->系统设置->HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\*


  199. 2007-11-06 13:33:04    修改注册表内容      操作:允许
  200. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  201. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  202. 注册表名称:*
  203. 触发规则:所有程序规则->系统自动运行->*\SOFTWARE\Microsoft\Windows\CurrentVersion\Run*


  204. 2007-11-06 13:33:04    修改注册表内容      操作:允许
  205. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  206. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  207. 注册表名称:*
  208. 触发规则:所有程序规则->系统自动运行->*\SOFTWARE\Microsoft\Windows\CurrentVersion\Run*


  209. 2007-11-06 13:33:04    删除注册表      操作:允许
  210. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  211. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  212. 注册表名称:AVP
  213. 触发规则:所有程序规则->系统自动运行->*\SOFTWARE\Microsoft\Windows\CurrentVersion\Run*


  214. 2007-11-06 13:33:05    删除注册表      操作:允许
  215. 进程路径:C:\Program Files\Common Files\System\lxpbnfn.exe
  216. 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  217. 注册表名称:KVMON
  218. 触发规则:所有程序规则->系统自动运行->*\SOFTWARE\Microsoft\Windows\CurrentVersion\Run*
复制代码
以上就是全部的监控日志!
为了大家看得方便,另外上传日志文件!!!

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
驭龙
发表于 2007-11-6 14:02:05 | 显示全部楼层
A-Squared  Found nothing
AntiVir  Found TR/Delphi.Downloader.Gen  
ArcaVir  Found nothing
Avast  Found Win32:AutoRun-FI  
AVG Antivirus  Found Win32/PEMask  
BitDefender  Found Generic.Malware.SP!Pk!g.518BE9DB  
ClamAV  Found Trojan.Delf-818  
CPsecure  Found nothing
Dr.Web  Found DLOADER.Trojan (probable variant)  
F-Prot Antivirus  Found Possibly a new variant of W32/Threat-HLLPEM-based!Maximus  
F-Secure Anti-Virus  Found Worm:W32/Agent.BTQ, Virus.Win32.AutoRun.aat  
Fortinet  Found nothing
Kaspersky Anti-Virus  Found Virus.Win32.AutoRun.aat  
NOD32  Found probably a variant of Win32/Delf.NDF (probable variant)  
Norman Virus Control  Found nothing
Panda Antivirus  Found Generic  
Rising Antivirus  Found nothing
Sophos Antivirus  Found Mal/EncPk-AP  
VirusBuster  Found nothing
VBA32  Found nothing


我的卡巴7报告是已删除:病毒 Virus.Win32.AutoRun.aat        文件 : C:\TDDOWNLOAD\今天中的毒.rar/rommabp.exe//ASPack//PE_Patch.MaskPE

但我的nis08却没有报告
googlehack
发表于 2007-11-6 14:03:43 | 显示全部楼层
不错啊,是个avkiller,厉害!
秋叶濛濛
发表于 2007-11-6 14:10:45 | 显示全部楼层
F:\Virus\今天中的毒.rar » RAR » rommabp.exe - probably a variant of Win32/Delf.NDF worm
a256886572008
发表于 2007-11-6 14:27:04 | 显示全部楼层

回复 66楼 SONGBOWEN 的帖子

隱藏文件你沒測到嗎

[ 本帖最后由 a256886572008 于 2007-11-6 14:32 编辑 ]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-21 05:11 , Processed in 0.110330 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表