[mw_shl_code=css,true]
2016/1/12 11:07:00,C:\Windows\explorer.exe,53,Allowed ;执行应用程序 ("C:\Users\AA\Desktop\1\020356457e95f7607c1941e03294b4c16e23daa402d7e79cfd2ba91b23969480.exe" )
2016/1/12 11:07:11,C:\Users\AA\Desktop\1\020356457e95f7607c1941e03294b4c16e23daa402d7e79cfd2ba91b23969480.exe,53,Allowed ;执行应用程序 ("C:\Windows\System32\cscript.exe" C:\Users\AA\AppData\Local\Temp\vgyzdlxcbrwzhckmnhbfggat.vbs)
2016/1/12 11:07:13,C:\Users\AA\Desktop\1\020356457e95f7607c1941e03294b4c16e23daa402d7e79cfd2ba91b23969480.exe,53,Allowed ;执行应用程序 (C:\Users\AA\AppData\Roaming\Microsoft\Rgdakepog\rgdakepo.exe)
2016/1/12 11:07:16,C:\Users\AA\AppData\Roaming\Microsoft\Rgdakepog\rgdakepo.exe,53,Allowed ;执行应用程序 (C:\windows\SysWOW64\explorer.exe)
2016/1/12 11:07:18,C:\Windows\SysWOW64\explorer.exe,40,Blocked ;以修改权限打开进程或线程 (esif_assist.exe(pid=2076))
2016/1/12 11:07:20,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,YpnPack)
2016/1/12 11:07:22,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,ShadowsocksR_1829439101)
2016/1/12 11:07:23,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,IDMan)
2016/1/12 11:07:24,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,hzungzx)
2016/1/12 11:08:05,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,YpnPack)
2016/1/12 11:08:07,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,ShadowsocksR_1829439101)
2016/1/12 11:08:08,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,IDMan)
2016/1/12 11:08:09,C:\Windows\SysWOW64\explorer.exe,26,Blocked ;修改受保护的注册表键 (HKCU\Software\Microsoft\Windows\CurrentVersion\Run,tjdw)
[/mw_shl_code] |