Date/Time | Application | Action | Target |
2009-2-3 7:59:05 | C:\WINDOWS\explorer.exe | Modify Key | HKUS\S-1-5-21-1614895754-1935655697-1417001333-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup |
2009-2-3 7:59:05 | C:\WINDOWS\explorer.exe | Access Memory | C:\WINDOWS\system32\svchost.exe |
2009-2-3 7:59:05 | C:\WINDOWS\explorer.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 7:59:05 | C:\WINDOWS\explorer.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 7:59:06 | C:\WINDOWS\explorer.exe | Direct Disk Access | B: |
2009-2-3 7:59:13 | C:\WINDOWS\explorer.exe | Access Memory | C:\WINDOWS\system32\svchost.exe |
2009-2-3 8:03:09 | D:\SogouInput\4.0.0.1959\userNetSchedule.exe | Modify Key | HKUS\S-1-5-21-1614895754-1935655697-1417001333-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
2009-2-3 8:04:25 | C:\WINDOWS\explorer.exe | Access Memory | C:\WINDOWS\system32\svchost.exe |
2009-2-3 8:04:34 | D:\AcooBrowser\AcooBrowser.exe | Modify Key | HKUS\S-1-5-21-1614895754-1935655697-1417001333-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
2009-2-3 8:05:02 | C:\Program Files\Comodo\COMODO Internet Security\cfp.exe | Changes Defense+ Mode | Training Mode |
2009-2-3 8:05:10 | C:\Program Files\Windows Media Player\wmplayer.exe | Modify Key | HKUS\S-1-5-21-1614895754-1935655697-1417001333-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
2009-2-3 8:05:44 | C:\Program Files\Comodo\COMODO Internet Security\cfp.exe | Changes Defense+ Mode | Safe Mode |
2009-2-3 8:08:09 | D:\SogouInput\4.0.0.1959\userNetSchedule.exe | Modify Key | HKUS\S-1-5-21-1614895754-1935655697-1417001333-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
2009-2-3 8:08:14 | D:\SogouInput\4.0.0.1959\userNetSchedule.exe | Access COM Interface | LocalSecurityAuthority.Backup |
2009-2-3 8:12:28 | C:\WINDOWS\explorer.exe | Access Memory | D:\AcooBrowser\AcooBrowser.exe |
2009-2-3 8:12:33 | C:\WINDOWS\explorer.exe | Access COM Interface | {9BA05972-F6A8-11CF-A442-00A0C90A8F39} |
2009-2-3 8:12:34 | C:\WINDOWS\explorer.exe | DNS/RPC Client Access | \RPC Control\DNSResolver |
2009-2-3 8:12:36 | C:\WINDOWS\explorer.exe | Direct Disk Access | H: |
2009-2-3 8:12:39 | C:\WINDOWS\explorer.exe | Access Memory | C:\WINDOWS\system32\svchost.exe |
2009-2-3 8:12:43 | C:\WINDOWS\explorer.exe | Create Process | C:\WINDOWS\hh.exe |
2009-2-3 8:13:06 | C:\WINDOWS\explorer.exe | Access Memory | C:\WINDOWS\system32\svchost.exe |
2009-2-3 8:13:27 | C:\WINDOWS\system32\rundll32.exe | Access COM Interface | LocalSecurityAuthority.SystemTime |
2009-2-3 8:14:27 | C:\Program Files\Comodo\COMODO Internet Security\cfplogvw.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 8:14:27 | C:\Program Files\Comodo\COMODO Internet Security\cfplogvw.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 8:14:27 | C:\Program Files\Comodo\COMODO Internet Security\cfplogvw.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 8:14:27 | C:\Program Files\Comodo\COMODO Internet Security\cfplogvw.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 8:14:31 | C:\Program Files\Comodo\COMODO Internet Security\cfplogvw.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 8:14:31 | C:\Program Files\Comodo\COMODO Internet Security\cfplogvw.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 8:14:31 | C:\Program Files\Comodo\COMODO Internet Security\cfplogvw.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 8:14:31 | C:\Program Files\Comodo\COMODO Internet Security\cfplogvw.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 8:14:47 | C:\WINDOWS\explorer.exe | Access Memory | C:\WINDOWS\system32\svchost.exe |
2009-2-3 8:14:49 | C:\WINDOWS\explorer.exe | Access COM Interface | {9BA05972-F6A8-11CF-A442-00A0C90A8F39} |
2009-2-3 8:14:52 | C:\WINDOWS\explorer.exe | Access Memory | C:\WINDOWS\system32\svchost.exe |
2009-2-3 8:14:54 | C:\WINDOWS\explorer.exe | Access COM Interface | {9BA05972-F6A8-11CF-A442-00A0C90A8F39} |
2009-2-3 8:14:59 | D:\QQ2008\QQ.exe | Modify File | D:\QQ2008\QQlog.txl |
2009-2-3 8:15:12 | D:\QQ2008\QQ.exe | Modify File | D:\QQ2008\QQ.tlg |
2009-2-3 8:18:02 | C:\WINDOWS\explorer.exe | Access Memory | D:\AcooBrowser\AcooBrowser.exe |
2009-2-3 8:18:05 | C:\WINDOWS\explorer.exe | Access Memory | C:\WINDOWS\system32\svchost.exe |
2009-2-3 8:18:34 | C:\WINDOWS\explorer.exe | Access Memory | C:\WINDOWS\system32\svchost.exe |
2009-2-3 8:18:35 | D:\AcooBrowser\AcooBrowser.exe | Modify Key | HKUS\S-1-5-21-1614895754-1935655697-1417001333-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
2009-2-3 8:21:33 | C:\WINDOWS\explorer.exe | Access COM Interface | {9BA05972-F6A8-11CF-A442-00A0C90A8F39} |
2009-2-3 8:21:36 | D:\QQ2008\QQ.exe | Modify File | D:\QQ2008\QQlog.txl |
2009-2-3 8:23:46 | D:\QQ2008\QQ.exe | Modify File | D:\QQ2008\QQ.tlg |
2009-2-3 8:23:53 | C:\WINDOWS\explorer.exe | Direct Disk Access | E: |
2009-2-3 8:24:10 | C:\WINDOWS\explorer.exe | Access Memory | C:\WINDOWS\system32\svchost.exe |
2009-2-3 8:24:44 | C:\WINDOWS\explorer.exe | Access Memory | C:\WINDOWS\system32\svchost.exe |
2009-2-3 8:27:08 | C:\WINDOWS\explorer.exe | Access Memory | C:\WINDOWS\system32\svchost.exe |
2009-2-3 8:27:32 | C:\Program Files\Comodo\COMODO Internet Security\cfplogvw.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 8:27:32 | C:\Program Files\Comodo\COMODO Internet Security\cfplogvw.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 8:27:32 | C:\Program Files\Comodo\COMODO Internet Security\cfplogvw.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |
2009-2-3 8:27:32 | C:\Program Files\Comodo\COMODO Internet Security\cfplogvw.exe | Block File | D:\SogouInput\4.0.0.1959\ImeUtil.exe |