2015/12/14 10:59:31,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\w\Infinity Crypter - Cracked by 0x42.exe" )
2015/12/14 10:59:40,C:\Users\AA\Desktop\w\Infinity Crypter - Cracked by 0x42.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon,shell)
2015/12/14 10:59:43,C:\Users\AA\Desktop\w\Infinity Crypter - Cracked by 0x42.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\w\Infinity Crypter - Cracked by 0x42.exe")
2015/12/14 10:59:45,C:\Users\AA\Desktop\w\Infinity Crypter - Cracked by 0x42.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Local\Temp\INFINITY CRYPTER - CRACKED BY 0X42.EXE" )
2015/12/14 11:00:22,C:\Users\AA\Desktop\w\Infinity Crypter - Cracked by 0x42.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\AppData\Local\Temp\STUB NORMAL.EXE" )
2015/12/14 11:00:26,C:\Users\AA\AppData\Local\Temp\STUB NORMAL.EXE,11,Blocked ;记录键盘输入
2015/12/14 11:00:28,C:\Users\AA\AppData\Local\Temp\STUB NORMAL.EXE,50,Allowed ;使用 DNS 解析服务访问网络
2015/12/14 11:00:35,C:\Users\AA\AppData\Local\Temp\STUB NORMAL.EXE,48,Blocked ;出站网络访问
建立 出站 网络连接 (TCP)
远程地址=rspsevolution.no-ip.org(24.55.207.15) 远程端口=1604 |