真心为某些粉丝呕吐了
2015/12/12 13:46:53,C:\Users\AA\Desktop\q\840bea7f6da6bfcc6e24fcded6526ae4.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\q\840bea7f6da6bfcc6e24fcded6526ae4.exe" )
2015/12/12 13:46:57,C:\Users\AA\Desktop\q\840bea7f6da6bfcc6e24fcded6526ae4.exe,47,Allowed ;创建交换数据流 (C:\Users\AA\Desktop\q\840bea7f6da6bfcc6e24fcded6526ae4.exe:Zone.Identifier)
2015/12/12 13:47:04,C:\Users\AA\Desktop\q\840bea7f6da6bfcc6e24fcded6526ae4.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Roaming\ptoovacroic.exe)
2015/12/12 13:47:07,C:\Users\AA\Desktop\q\840bea7f6da6bfcc6e24fcded6526ae4.exe,53,Allowed ;执行应用程序 ("C:\windows\system32\cmd.exe" /c DEL C:\Users\AA\Desktop\q\840BEA~1.EXE)
2015/12/12 13:47:40,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Roaming\ptoovacroic.exe)
2015/12/12 13:47:42,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,47,Allowed ;创建交换数据流 (C:\Users\AA\AppData\Roaming\ptoovacroic.exe:Zone.Identifier)
2015/12/12 13:47:50,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,Acrndtd)
2015/12/12 13:48:01,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,53,Blocked ;执行应用程序 (bcdedit.exe /set {current} bootems off)
2015/12/12 13:48:02,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,53,Blocked ;执行应用程序 ("C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet )
2015/12/12 13:48:04,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,53,Blocked ;执行应用程序 (bcdedit.exe /set {current} advancedoptions off)
2015/12/12 13:48:06,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,53,Blocked ;执行应用程序 (bcdedit.exe /set {current} optionsedit off)
2015/12/12 13:48:09,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,53,Blocked ;执行应用程序 (bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures)
2015/12/12 13:48:11,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,53,Blocked ;执行应用程序 ("C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet )
2015/12/12 13:48:13,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,53,Blocked ;执行应用程序 (bcdedit.exe /set {current} recoveryenabled off)
2015/12/12 13:48:16,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,40,Blocked ;以修改权限打开进程或线程 (esif_assist.exe(pid=4048))
2015/12/12 13:48:18,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/12 13:48:20,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,48,Blocked ;出站网络访问
2015/12/12 13:48:24,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,53,Blocked ;执行应用程序 ("C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet )
2015/12/12 13:48:29,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,53,Blocked ;执行应用程序 ("C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet )
2015/12/12 13:48:35,C:\Users\AA\AppData\Roaming\ptoovacroic.exe,53,Terminated ;执行应用程序 ("C:\Windows\System32\vssadmin.exe" delete shadows /all /Quiet )
|