2009-4-25 2:37:48 | \Device\HarddiskVolume1\WINDOWS\system32\rundll32.exe | Modify File | \Device\NamedPipe\lsarpc |
2009-4-25 2:37:48 | \Device\HarddiskVolume1\WINDOWS\system32\rundll32.exe | Modify File | \Device\NamedPipe\lsarpc |
2009-4-25 2:37:48 | \Device\HarddiskVolume1\WINDOWS\system32\rundll32.exe | Direct Disk Access | \??\G: |
2009-4-25 2:37:48 | \Device\HarddiskVolume1\WINDOWS\system32\rundll32.exe | Direct Disk Access | \??\Q: |
2009-4-25 2:37:48 | \Device\HarddiskVolume1\WINDOWS\system32\rundll32.exe | Direct Disk Access | \??\C: |
2009-4-25 2:37:49 | \Device\HarddiskVolume2\360安全卫士V5.0正式版\360safe\uninst.exe | Modify File | \Device\NamedPipe\lsarpc |
2009-4-25 2:37:49 | \Device\HarddiskVolume2\360安全卫士V5.0正式版\360safe\uninst.exe | Modify File | \Device\NamedPipe\lsarpc |
2009-4-25 2:37:49 | \Device\HarddiskVolume2\360安全卫士V5.0正式版\360safe\uninst.exe | Modify File | \Device\NamedPipe\lsarpc |
2009-4-25 2:37:49 | \Device\HarddiskVolume2\360安全卫士V5.0正式版\360safe\uninst.exe | Modify File | \Device\NamedPipe\lsarpc |
2009-4-25 2:37:49 | \Device\HarddiskVolume1\WINDOWS\system32\rundll32.exe | Modify File | \Device\NamedPipe\lsarpc |
2009-4-25 2:37:49 | \Device\HarddiskVolume2\360安全卫士V5.0正式版\360safe\360Safe.exe | Modify Key | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe\Path |
2009-4-25 2:37:49 | \Device\HarddiskVolume2\360安全卫士V5.0正式版\360safe\safemon\360tray.exe | Modify Key | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup |
2009-4-25 2:37:49 | \Device\HarddiskVolume2\360安全卫士V5.0正式版\360safe\safemon\360tray.exe | Access Memory | \Device\HarddiskVolume1\WINDOWS\system32\smss.exe |
2009-4-25 2:37:50 | \Device\HarddiskVolume1\WINDOWS\explorer.exe | Modify Key | HKUS\S-1-5-21-484763869-842925246-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup |
2009-4-25 2:37:50 | \Device\HarddiskVolume2\360安全卫士V5.0正式版\360safe\uninst.exe | Modify File | \Device\NamedPipe\lsarpc |