SSP10.6.1
- 2021/7/19 15:45:17,D:\$aa\1\WUDFHost.exe,57,Allowed ;正在以只读方式打开受保护的进程 (explorer.exe(pid=1668))
- 2021/7/19 15:45:18,D:\$aa\1\WUDFHost.exe,57,Allowed ;正在以只读方式打开受保护的进程 (explorer.exe(pid=1668))
- 2021/7/19 15:45:19,D:\$aa\1\WUDFHost.exe,57,Allowed ;正在以只读方式打开受保护的进程 (explorer.exe(pid=1668))
- 2021/7/19 15:45:23,D:\$aa\1\WUDFHost.exe,47,Allowed ;创建交换数据流 (C:\Windows\WUDFHost.exe:Zone.Identifier)
- 2021/7/19 15:45:26,D:\$aa\1\WUDFHost.exe,26,Blocked ;修改受保护的注册表键 (HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run,WUDFHost)
- 2021/7/19 15:45:28,D:\$aa\1\WUDFHost.exe,11,Allowed ;记录键盘输入
复制代码 |