我擦 神奇啊 我系统墙都拦截了一下呢我去 是不是之前写注册表把墙搞坏了?
2014/3/14 18:29:14,C:\Program Files\Java\jre7\bin\javaw.exe,53,Allowed ;Execution of an application (C:\Users\A\AppData\Local\Temp\143592.exe)
2014/3/14 18:29:17,C:\Users\A\AppData\Local\Temp\143592.exe,53,Allowed ;Execution of an application (C:\Users\A\AppData\Local\Temp\143592.exe)
2014/3/14 18:29:20,C:\Users\A\AppData\Local\Temp\143592.exe,36,Allowed ;Injecting dll (143592.exe(pid=3332))
2014/3/14 18:29:47,C:\Users\A\AppData\Local\Temp\143592.exe,26,Blocked ;Modifying protected registry key (HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jerlobw,Impersonate)
2014/3/14 18:30:06,C:\Users\A\AppData\Local\Temp\143592.exe,26,Blocked ;Modifying protected registry key (HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jerlobw,Asynchronous)
2014/3/14 18:30:18,C:\Users\A\AppData\Local\Temp\143592.exe,26,Blocked ;Modifying protected registry key (HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jerlobw,MaxWait)
2014/3/14 18:30:34,C:\Users\A\AppData\Local\Temp\143592.exe,26,Blocked ;Modifying protected registry key (HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jerlobw,koehsnwt)
2014/3/14 18:30:37,C:\Users\A\AppData\Local\Temp\143592.exe,26,Blocked ;Modifying protected registry key (HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jerlobw,DllName)
2014/3/14 18:30:43,C:\Users\A\AppData\Local\Temp\143592.exe,26,Blocked ;Modifying protected registry key (HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jerlobw,Startup)
2014/3/14 18:30:56,C:\Users\A\AppData\Local\Temp\143592.exe,26,Blocked ;Modifying protected registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,jerlobw)
2014/3/14 18:31:43,C:\Users\A\AppData\Local\Temp\143592.exe,54,Allowed ;Receiving incoming network packets
2014/3/14 18:32:09,C:\Users\A\AppData\Local\Temp\143592.exe,54,Allowed ;Receiving incoming network packets
2014/3/14 18:32:12,C:\Users\A\AppData\Local\Temp\143592.exe,50,Allowed ;Accessing the network via DNSResolver service
2014/3/14 18:32:26,C:\Users\A\AppData\Local\Temp\143592.exe,48,Allowed ;Outgoing network access
|