日期/时间 | 程序 | 行为 | 目标 |
01/07/10 22:42:12 | D:\Program Files\China Mobile\Fetion\Fetion.exe | 创建进程 | D:\Program Files\China Mobile\Fetion\VMDotNet\v2.0.50727\FetionVM.exe |
01/07/10 22:42:43 | C:\Program Files\COMODO\COMODO Internet Security\cfp.exe | 改变Defense+模式 | 禁用 |
01/07/10 23:00:07 | C:\Program Files\COMODO\COMODO Internet Security\cfp.exe | 改变Defense+模式 | 安全模式 |
01/07/10 23:00:46 | D:\Program Files\China Mobile\Fetion\VMDotNet\v2.0.50727\FetionVM.exe | 修改文件 | C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SYXMN70D\editShowType[1].htm |
01/07/10 23:00:48 | D:\Program Files\China Mobile\Fetion\VMDotNet\v2.0.50727\FetionVM.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
01/07/10 23:00:53 | D:\Program Files\China Mobile\Fetion\VMDotNet\v2.0.50727\FetionVM.exe | 修改文件 | \Device\NamedPipe\lsarpc |
01/07/10 23:01:08 | D:\Program Files\China Mobile\Fetion\VMDotNet\v2.0.50727\FetionVM.exe | 修改文件 | \Device\NamedPipe\lsarpc |
01/07/10 23:01:10 | D:\Program Files\China Mobile\Fetion\VMDotNet\v2.0.50727\FetionVM.exe | 修改文件 | \Device\NamedPipe\lsarpc |
01/07/10 23:01:12 | D:\Program Files\China Mobile\Fetion\VMDotNet\v2.0.50727\FetionVM.exe | 修改文件 | \Device\NamedPipe\lsarpc |
01/07/10 23:01:14 | D:\Program Files\China Mobile\Fetion\VMDotNet\v2.0.50727\FetionVM.exe | 修改文件 | \Device\NamedPipe\ROUTER |
01/07/10 23:01:16 | D:\Program Files\China Mobile\Fetion\VMDotNet\v2.0.50727\FetionVM.exe | 修改文件 | \Device\Tcp |
01/07/10 23:01:21 | D:\Program Files\China Mobile\Fetion\VMDotNet\v2.0.50727\FetionVM.exe | 修改文件 | \Device\Tcp |
01/07/10 23:01:34 | C:\Program Files\COMODO\COMODO Internet Security\cfp.exe | 改变Defense+模式 | 禁用 |