:\Documents and Settings\Administrator\Local Settings\Temp\0.exe | 修改文件 | C:\Program Files\SogouInput\4.0.0.1959\ErrorReport.exe |
05/18/09 12:05:35 | C:\Documents and Settings\Administrator\Local Settings\Temp\0.exe | 修改文件 | C:\Program Files\SogouInput\4.0.0.1959\ErrorReport.exe |
05/18/09 12:05:44 | C:\Documents and Settings\Administrator\Local Settings\Temp\0.exe | 直接内存访问 | \device\physicalmemory |
05/18/09 12:05:48 | C:\Documents and Settings\Administrator\Local Settings\Temp\0.exe | 修改文件 | C:\WINDOWS\system32\test.tmp; |
05/18/09 12:05:54 | C:\Documents and Settings\Administrator\Local Settings\Temp\0.exe | 访问内存 | C:\WINDOWS\EXPLORER.EXE |
05/18/09 12:05:58 | C:\Documents and Settings\Administrator\Local Settings\Temp\0.exe | 修改注册表键 | HKUS\S-1-5-21-527237240-1645522239-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Start Menu |
05/18/09 12:06:01 | C:\Documents and Settings\Administrator\Local Settings\Temp\0.exe | 修改注册表键 | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Start Menu |
05/18/09 12:06:06 | C:\Documents and Settings\Administrator\Local Settings\Temp\0.exe | 修改注册表键 | HKUS\S-1-5-21-527237240-1645522239-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Run\OlympicExpress |