2015/12/2 9:44:29,C:\Windows\explorer.exe,53,Allowed ;Execution of an application ("C:\Users\AAAAA\Desktop\KB09883203\KB09883203.exe" )
2015/12/2 9:44:39,C:\Users\AAAAA\Desktop\KB09883203\KB09883203.exe,53,Allowed ;Execution of an application ("C:\windows\SysWOW64\explorer.exe")
2015/12/2 9:44:41,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;Modifying protected registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,KdjSaS011arbaaa1z)
2015/12/2 9:44:43,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;Modifying protected registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce,KdjSaS011arbaaa1z)
2015/12/2 9:45:05,C:\Windows\SysWOW64\explorer.exe,48,Allowed ;Outgoing network access
establish an outgoing network connection (TCP)
RemoteAddress=91.232.105.112 RemotePort=6600
|