2008-2-4 12:48:58 C:\Program Files\Sandboxie\Start.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe (Default) 65 00 78 00 65 00 66 00 69 00 6c 00 65 00 00 未结束的Unicode字符串 读 检测到
2008-2-4 12:48:58 C:\Program Files\Sandboxie\Start.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32 (Default) shell32.dll 未结束的Unicode字符串 读 被允许
2008-2-4 12:48:58 C:\Program Files\Sandboxie\Start.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32 (Default) shell32.dll 未结束的Unicode字符串 读 检测到
2008-2-4 12:48:58 C:\Program Files\Sandboxie\Start.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe (Default) 65 00 78 00 65 00 66 00 69 00 6c 00 65 00 00 未结束的Unicode字符串 读 被允许
2008-2-4 12:48:58 C:\Program Files\Sandboxie\Start.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe (Default) 65 00 78 00 65 00 66 00 69 00 6c 00 65 00 00 未结束的Unicode字符串 读 检测到
2008-2-4 12:48:58 C:\Program Files\Sandboxie\Start.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 (Default) %SystemRoot%\system32\SHELL32.dll 未结束的Unicode字符串(带有环境变量参数) 读 被允许
2008-2-4 12:48:58 C:\Program Files\Sandboxie\Start.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 (Default) %SystemRoot%\system32\SHELL32.dll 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:48:51 C:\Program Files\Sandboxie\Start.exe HKEY_USERS\SANDBOX_JEHOVAH_KING_DEFAULTBOX\machine\software\microsoft\windows nt\currentversion\winlogon Shell x 未结束的Unicode字符串 创建 被允许
2008-2-4 12:48:51 C:\Program Files\Sandboxie\Start.exe HKEY_USERS\SANDBOX_JEHOVAH_KING_DEFAULTBOX\machine\software\microsoft\windows nt\currentversion\winlogon Shell x 未结束的Unicode字符串 创建 检测到
2008-2-4 12:50:49 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon (Default) %SystemRoot%\Explorer.exe,0 未结束的Unicode字符串(带有环境变量参数) 读 被允许
2008-2-4 12:50:49 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon (Default) %SystemRoot%\Explorer.exe,0 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:50:49 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon (Default) %SystemRoot%\Explorer.exe,0 未结束的Unicode字符串(带有环境变量参数) 读 被允许
2008-2-4 12:50:49 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon (Default) %SystemRoot%\Explorer.exe,0 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:50:49 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon (Default) %SystemRoot%\Explorer.exe,0 未结束的Unicode字符串(带有环境变量参数) 读 被允许
2008-2-4 12:50:49 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon (Default) %SystemRoot%\Explorer.exe,0 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:50:49 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon (Default) %SystemRoot%\Explorer.exe,0 未结束的Unicode字符串(带有环境变量参数) 读 被允许
2008-2-4 12:50:49 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon (Default) %SystemRoot%\Explorer.exe,0 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\DefaultIcon (Default) %SystemRoot%\system32\SHELL32.dll,17 未结束的Unicode字符串(带有环境变量参数) 读 被允许
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\DefaultIcon (Default) %SystemRoot%\system32\SHELL32.dll,17 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\DefaultIcon (Default) %SystemRoot%\system32\SHELL32.dll,17 未结束的Unicode字符串(带有环境变量参数) 读 被允许
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\DefaultIcon (Default) %SystemRoot%\system32\SHELL32.dll,17 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\d\DefaultIcon (Default) C:\WINDOWS\Resources\Themes\VistaDrv\25.ico 未结束的Unicode字符串 读 被允许
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\d\DefaultIcon (Default) C:\WINDOWS\Resources\Themes\VistaDrv\25.ico 未结束的Unicode字符串 读 检测到
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\d\DefaultIcon (Default) C:\WINDOWS\Resources\Themes\VistaDrv\25.ico 未结束的Unicode字符串 读 被允许
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\d\DefaultIcon (Default) C:\WINDOWS\Resources\Themes\VistaDrv\25.ico 未结束的Unicode字符串 读 检测到
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c\DefaultIcon (Default) C:\WINDOWS\Resources\Themes\VistaDrv\s50.ico 未结束的Unicode字符串 读 被允许
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c\DefaultIcon (Default) C:\WINDOWS\Resources\Themes\VistaDrv\s50.ico 未结束的Unicode字符串 读 检测到
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c\DefaultIcon (Default) C:\WINDOWS\Resources\Themes\VistaDrv\s50.ico 未结束的Unicode字符串 读 被允许
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c\DefaultIcon (Default) C:\WINDOWS\Resources\Themes\VistaDrv\s50.ico 未结束的Unicode字符串 读 检测到
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon (Default) %SystemRoot%\Explorer.exe,0 未结束的Unicode字符串(带有环境变量参数) 读 被允许
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon (Default) %SystemRoot%\Explorer.exe,0 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon (Default) %SystemRoot%\Explorer.exe,0 未结束的Unicode字符串(带有环境变量参数) 读 被允许
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon (Default) %SystemRoot%\Explorer.exe,0 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60664caf-af0d-0004-a300-5c7d25ff22a0}\InProcServer32 (Default) C:\WINDOWS\system32\shgina.dll 未结束的Unicode字符串(带有环境变量参数) 读 被允许
2008-2-4 12:50:48 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60664caf-af0d-0004-a300-5c7d25ff22a0}\InProcServer32 (Default) C:\WINDOWS\system32\shgina.dll 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:50:47 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60664caf-af0d-0004-a300-5c7d25ff22a0}\InProcServer32 (Default) C:\WINDOWS\system32\shgina.dll 未结束的Unicode字符串(带有环境变量参数) 读 被允许
2008-2-4 12:50:47 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60664caf-af0d-0004-a300-5c7d25ff22a0}\InProcServer32 (Default) C:\WINDOWS\system32\shgina.dll 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:50:47 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60664caf-af0d-0004-a300-5c7d25ff22a0}\InProcServer32 (Default) C:\WINDOWS\system32\shgina.dll 未结束的Unicode字符串(带有环境变量参数) 读 被允许
2008-2-4 12:50:47 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60664caf-af0d-0004-a300-5c7d25ff22a0}\InProcServer32 (Default) C:\WINDOWS\system32\shgina.dll 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:50:47 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\Controls (Default) {21EC2020-3AEA-1069-A2DD-08002B30309D} 未结束的Unicode字符串 读 被允许
2008-2-4 12:50:47 C:\Program Files\Sandboxie\SbieCtrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\Controls (Default) {21EC2020-3AEA-1069-A2DD-08002B30309D} 未结束的Unicode字符串 读 检测到
2008-2-4 12:49:01 C:\Documents and Settings\jehovah_king\桌面\Setup.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mailto\shell\open\command (Default) "%ProgramFiles%\Outlook Express\msimn.exe" /mailurl:%1 未结束的Unicode字符串(带有环境变量参数) 读 检测到
2008-2-4 12:49:01 C:\Documents and Settings\jehovah_king\桌面\Setup.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mailto\shell\open\command (Default) "%ProgramFiles%\Outlook Express\msimn.exe" /mailurl:%1 未结束的Unicode字符串(带有环境变量参数) 读 被允许 |