你还是真让人捉急呢
2014/10/27 17:00:25,C:\ProgramData\CreativeAudio\iuznffnsd.exe,47,Blocked ;Creating alternate
data stream (C:\ProgramData\CreativeAudio\iuznffnsd.exe:Zone.Identifier)
2014/10/27 17:00:26,C:\ProgramData\CreativeAudio\iuznffnsd.exe,53,Blocked ;Execution of an
application ("C:\Windows\System32\schtasks.exe" /CREATE /SC ONLOGON /TN "Windows
Update Check - 0x0E7302EC" /TR "C:\ProgramData\CreativeAudio\iuznffnsd.exe" /RL HIGHEST)
2014/10/27 17:00:28,C:\ProgramData\CreativeAudio\iuznffnsd.exe,26,Blocked ;Modifying
protected registry key (HKCU\Software\Classes\CLSID\{A30675C2-6BF9-E946-9379-
4BC67D8BB26D}\0E7302EC\CG1)
2014/10/27 17:00:30,C:\ProgramData\CreativeAudio\iuznffnsd.exe,26,Blocked ;Modifying
protected registry key (HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File
Execution Options\iuznffnsd.exe,DisableExceptionChainValidation)
2014/10/27 17:00:35,C:\ProgramData\CreativeAudio\iuznffnsd.exe,53,Allowed ;Execution of an
application ("C:\Windows\SysWOW64\WerFault.exe")
2014/10/27 17:00:37,C:\Windows\SysWOW64\WerFault.exe,26,Blocked ;Modifying protected
registry key (HKCU\Software\Microsoft\Internet Explorer\Main,Isolation)
2014/10/27 17:00:37,C:\Windows\SysWOW64\WerFault.exe,26,Blocked ;Modifying protected
registry key (HKCU\Software\Classes\CLSID\{A30675C2-6BF9-E946-9379-
4BC67D8BB26D}\0E7302EC\CS1)
2014/10/27 17:00:38,C:\Windows\SysWOW64\WerFault.exe,26,Blocked ;Modifying protected
registry key (HKCU\Software\Classes\CLSID\{A30675C2-6BF9-E946-9379-
4BC67D8BB26D}\0E7302EC\CS1)
2014/10/27 17:00:39,C:\Windows\SysWOW64\WerFault.exe,26,Blocked ;Modifying protected
registry key (HKCU\Software\Classes\CLSID\{A30675C2-6BF9-E946-9379-
4BC67D8BB26D}\0E7302EC\CS1)
2014/10/27 17:00:40,C:\Windows\SysWOW64\WerFault.exe,26,Blocked ;Modifying protected
registry key (HKCU\Software\Classes\CLSID\{A30675C2-6BF9-E946-9379-
4BC67D8BB26D}\0E7302EC\CS1)
2014/10/27 17:00:41,C:\Windows\SysWOW64\WerFault.exe,26,Blocked ;Modifying protected
registry key (HKCU\Software\Classes\CLSID\{A30675C2-6BF9-E946-9379-
4BC67D8BB26D}\0E7302EC\CW1)
2014/10/27 17:00:42,C:\Windows\SysWOW64\WerFault.exe,26,Blocked ;Modifying protected
registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2014/10/27 17:00:44,C:\Windows\SysWOW64\WerFault.exe,40,Blocked ;Opening process or
thread for modify access (wininit.exe(pid=576))
2014/10/27 17:00:47,C:\Windows\SysWOW64\WerFault.exe,26,Blocked ;Modifying protected
registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2014/10/27 17:00:48,C:\Windows\SysWOW64\WerFault.exe,50,Blocked ;Accessing the network
via DNSResolver service
2014/10/27 17:00:49,C:\Windows\SysWOW64\WerFault.exe,48,Blocked ;Outgoing network access
2014/10/27 17:00:51,C:\Windows\SysWOW64\WerFault.exe,26,Blocked ;Modifying protected
registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
2014/10/27 17:00:53,C:\Windows\SysWOW64\WerFault.exe,47,Blocked ;Creating alternate data
stream (C:\ProgramData\CreativeAudio\iuznffnsd.exe:Zone.Identifier)
2014/10/27 17:00:58,C:\Windows\SysWOW64\WerFault.exe,26,Terminated ;Modifying protected
registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,CreativeAudio)
|