不是啥好东西,杀掉算了
[mw_shl_code=css,true]2015/6/7 1:02:42,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\as98e4f\Desktop\Xmiqfk012.exe" )
2015/6/7 1:02:50,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\as98e4f\Desktop\Xmiqfk012.exe" )
2015/6/7 1:03:40,C:\Users\as98e4f\Desktop\Xmiqfk012.exe,53,Allowed ;执行应用程序 (C:\Users\as98e4f\AppData\Local\Temp\~zFavUrl.Ex_ -y -o"C:\Users\as98e4f\Favorites")
2015/6/7 1:03:41,C:\Windows\System32\SearchIndexer.exe,53,Allowed ;执行应用程序 ("C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microso)
2015/6/7 1:03:41,C:\Windows\System32\SearchIndexer.exe,53,Allowed ;执行应用程序 ("C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532 )
2015/6/7 1:04:21,C:\Users\as98e4f\Desktop\Xmiqfk012.exe,53,Allowed ;执行应用程序 (C:\Windows\system32\cmd.exe /c C:\Users\as98e4f\AppData\Local\Temp\fbinst.dll "C:\Windows\Xmiqfk\SUPPORT.IM_" output IMG/* %~nx)
2015/6/7 1:04:21,C:\Windows\System32\csrss.exe,53,Allowed ;执行应用程序 (\??\C:\Windows\system32\conhost.exe)
2015/6/7 1:04:23,C:\Windows\System32\conhost.exe,52,Allowed ;修改属于其它进程的窗口的属性 (cmd.exe(pid=3548))
2015/6/7 1:04:24,C:\Windows\System32\conhost.exe,52,Allowed ;修改属于其它进程的窗口的属性 (cmd.exe(pid=3548))
2015/6/7 1:05:45,C:\Windows\System32\cmd.exe,53,Allowed ;执行应用程序 (C:\Users\as98e4f\AppData\Local\Temp\fbinst.dll "C:\Windows\Xmiqfk\SUPPORT.IM_" output IMG/* %~nx)
2015/6/7 1:06:28,C:\Users\as98e4f\Desktop\Xmiqfk012.exe,53,Allowed ;执行应用程序 (C:\Windows\system32\cmd.exe /c ping 127.1 -n 50® add "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /d "www.hao123.com.sg" /f® delete "HKCU\Software\Policies\Microsoft\Internet Explorer\Main" /v "Start Page" /f® delete "HKCU\Softwar)
2015/6/7 1:06:30,C:\Windows\System32\conhost.exe,52,Allowed ;修改属于其它进程的窗口的属性 (cmd.exe(pid=2760))
2015/6/7 1:06:31,C:\Windows\System32\conhost.exe,52,Allowed ;修改属于其它进程的窗口的属性 (cmd.exe(pid=2760))
2015/6/7 1:06:37,C:\Windows\System32\cmd.exe,53,Allowed ;执行应用程序 (ping 127.1 -n 50)
2015/6/7 1:06:41,C:\Windows\System32\PING.EXE,48,Allowed ;出站网络访问
2015/6/7 1:07:22,C:\Users\as98e4f\Desktop\Xmiqfk012.exe,26,Allowed ;修改受保护的注册表键 (HKCU\Software\Microsoft\Internet Explorer\Main,Start Page)
2015/6/7 1:07:45,C:\Users\as98e4f\Desktop\Xmiqfk012.exe,53,Allowed ;执行应用程序 (C:\Windows\system32\cmd.exe /c ping 127.1 -n 3&del /q "C:\Users\as98e4f\Desktop\Xmiqfk012.exe")
2015/6/7 1:07:54,C:\Windows\System32\cmd.exe,53,Allowed ;执行应用程序 (reg add "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /d "www.hao123.com.sg" /f)
2015/6/7 1:07:56,C:\Windows\System32\conhost.exe,52,Allowed ;修改属于其它进程的窗口的属性 (cmd.exe(pid=1620))
2015/6/7 1:07:59,C:\Windows\System32\reg.exe,26,Allowed ;修改受保护的注册表键 (HKCU\Software\Microsoft\Internet Explorer\Main,Start Page)
2015/6/7 1:08:00,C:\Windows\System32\conhost.exe,52,Allowed ;修改属于其它进程的窗口的属性 (cmd.exe(pid=1620))
2015/6/7 1:08:09,C:\Windows\System32\cmd.exe,53,Allowed ;执行应用程序 (reg delete "HKCU\Software\Policies\Microsoft\Internet Explorer\Main" /v "Start Page" /f)
2015/6/7 1:08:14,C:\Windows\System32\cmd.exe,53,Allowed ;执行应用程序 (ping 127.1 -n 3)
2015/6/7 1:08:19,C:\Windows\System32\cmd.exe,53,Allowed ;执行应用程序 (reg delete "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v "HomePage" /f)
2015/6/7 1:08:22,C:\Windows\System32\PING.EXE,48,Allowed ;出站网络访问
[/mw_shl_code]
|