得瑟,不用查杀,双击试试看,搞死你
2014-3-15 18:43:05,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:18,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:20,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:21,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:22,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:22,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:23,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:24,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:24,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:25,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:26,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:26,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:27,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:28,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:28,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:29,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:30,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:30,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:30,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:31,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:31,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:31,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:33,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (iexplore.exe(pid=2628))
2014-3-15 18:43:33,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,36,Allowed ;Injecting dll (iexplore.exe(pid=2628))
2014-3-15 18:43:34,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,29,Allowed ;Modifing process memory (svchost.exe(pid=3408))
2014-3-15 18:43:34,C:\Documents and Settings\Administrator\桌面\3.12\Pro.exe,30,Allowed ;Creating remote thread (svchost.exe(pid=3408))
2014-3-15 18:43:41,C:\Program Files\Internet Explorer\iexplore.exe,29,Allowed ;Modifing process memory (svchost.exe(pid=2576))
2014-3-15 18:43:46,C:\WINDOWS\system32\notepad.exe,11,Blocked ;Recording keyboard input
2014-3-15 18:43:48,C:\WINDOWS\system32\svchost.exe,26,Blocked ;Modifying protected registry key (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,HKLM)
2014-3-15 18:43:51,C:\Program Files\Internet Explorer\iexplore.exe,29,Allowed ;Modifing process memory (svchost.exe(pid=2576))
2014-3-15 18:43:53,C:\WINDOWS\system32\notepad.exe,24,Blocked ;Monitoring clipboard changes
2014-3-15 18:43:58,C:\WINDOWS\system32\svchost.exe,26,Blocked ;Modifying protected registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,HKCU)
2014-3-15 18:44:01,C:\Program Files\Internet Explorer\iexplore.exe,29,Allowed ;Modifing process memory (svchost.exe(pid=2576))
2014-3-15 18:44:04,C:\WINDOWS\system32\svchost.exe,26,Blocked ;Modifying protected registry key (HKLM\Software\Microsoft\Active Setup\Installed Components\{Q74711R2-I784-OF3E-0MB4-VH42KYQJ4D83})
2014-3-15 18:44:06,C:\Program Files\Internet Explorer\iexplore.exe,30,Allowed ;Creating remote thread (svchost.exe(pid=2576))
2014-3-15 18:44:09,C:\WINDOWS\system32\svchost.exe,26,Blocked ;Modifying protected registry key (HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components)
2014-3-15 18:44:10,C:\Program Files\Internet Explorer\iexplore.exe,29,Allowed ;Modifing process memory (notepad.exe(pid=1604))
2014-3-15 18:44:17,C:\Program Files\Internet Explorer\iexplore.exe,29,Allowed ;Modifing process memory (notepad.exe(pid=1604))
2014-3-15 18:44:19,C:\WINDOWS\system32\svchost.exe,26,Blocked ;Modifying protected registry key (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,HKLM)
2014-3-15 18:44:22,C:\Program Files\Internet Explorer\iexplore.exe,29,Allowed ;Modifing process memory (notepad.exe(pid=1604))
2014-3-15 18:44:24,C:\WINDOWS\system32\svchost.exe,26,Blocked ;Modifying protected registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,HKCU)
2014-3-15 18:44:28,C:\Program Files\Internet Explorer\iexplore.exe,30,Allowed ;Creating remote thread (notepad.exe(pid=1604))
2014-3-15 18:44:33,C:\WINDOWS\system32\svchost.exe,26,Blocked ;Modifying protected registry key (HKLM\Software\Microsoft\Active Setup\Installed Components\{Q74711R2-I784-OF3E-0MB4-VH42KYQJ4D83})
2014-3-15 18:44:34,C:\WINDOWS\system32\svchost.exe,26,Blocked ;Modifying protected registry key (HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components)
2014-3-15 18:44:42,C:\WINDOWS\system32\svchost.exe,26,Terminated ;Modifying protected registry key (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,HKLM) |