日期/时间 | 程序 | 行为 | 目标[/td] |
03/04/10 19:08:34 | C:\test\Ctr.exe | 修改文件 | C:\Documents and Settings\Administrator\Local Settings\Temp\~DF47AE.tmp |
03/04/10 19:08:55 | C:\test\Ctr.exe | 修改文件 | C:\test\Ctr.exe |
03/04/10 19:09:15 | C:\test\Ctr.exe | 修改文件 | C:\WINDOWS\system32\wybho.dll |
03/04/10 19:09:21 | C:\test\Ctr.exe | 创建进程 | C:\windows\System32\regsvr32.exe |
03/04/10 19:09:25 | C:\test\Ctr.exe | 修改文件 | C:\WINDOWS\system32\Thunder.dll |
03/04/10 19:09:29 | C:\test\Ctr.exe | 创建进程 | C:\windows\System32\regsvr32.exe |
03/04/10 19:09:33 | C:\test\Ctr.exe | 修改文件 | \Device\MountPointManager |
03/04/10 19:09:35 | C:\test\Ctr.exe | 修改注册表键 | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Start Menu |
03/04/10 19:09:38 | C:\test\Ctr.exe | 修改注册表键 | HKUS\S-1-5-21-515967899-839522115-1343024091-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Start Menu |
03/04/10 19:09:42 | C:\test\Ctr.exe | 发送消息 | C:\windows\Explorer.EXE |
03/04/10 19:09:44 | C:\test\Ctr.exe | 修改文件 | C:\Documents and Settings\All Users\桌面\Internet Explorer.lnk |
03/04/10 19:09:47 | C:\test\Ctr.exe | 修改文件 | C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\启动 Internet Explorer 浏览器.lnk |
03/04/10 19:09:49 | C:\test\Ctr.exe | 修改文件 | C:\Documents and Settings\Administrator\桌面\Firefox.lnk |
03/04/10 19:09:51 | C:\test\Ctr.exe | 修改文件 | C:\Program Files\Internet Explorer\Ctr.exe |
03/04/10 19:10:10 | C:\test\Ctr.exe | 修改文件 | C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\TM.lnk |
03/04/10 19:10:14 | C:\test\Ctr.exe | 修改文件 | C:\Documents and Settings\Administrator\Local Settings\Temp\123.txt |