日期 | 应用程序 | 标志 | 目标 |
04/04/10 18:37:31 | C:\Program Files\Tencent\QQSoftMgr\1.0.338.203\TencentUpdateSvc.exe | 修改文件 | \Device\Afd\Endpoint |
04/04/10 18:41:25 | F:\Program Files\Thunder Network\Thunder\Program\XMPBoot.exe | 访问COM接口 | C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.71\ThunderService.exe |
04/04/10 18:41:35 | C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.71\ThunderService.exe | 创建进程 | C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.71\ThunderLiveUD.exe |
04/04/10 18:41:38 | C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.71\ThunderService.exe | 修改文件 | \Device\Afd\Endpoint |
04/04/10 18:41:40 | C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.71\ThunderLiveUD.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 18:43:13 | C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.71\ThunderService.exe | 修改文件 | \Device\Afd\Endpoint |
04/04/10 18:43:43 | E:\多益网络\逍遥传说\xy.exe | 创建进程 | E:\多益网络\逍遥传说\patch\xy.bin |
04/04/10 18:43:57 | E:\多益网络\逍遥传说\patch\xy.bin | 访问COM接口 | Shell.Explorer.2 |
04/04/10 18:44:27 | F:\Program Files\Thunder Network\Thunder\Program\XMPBoot.exe | 创建进程 | C:\Documents and Settings\Administrator\Local Settings\Temp\XMPSetup3.exe |
04/04/10 18:44:27 | C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.71\ThunderService.exe | 创建进程 | C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.71\upnp.exe |
04/04/10 18:44:33 | C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.71\upnp.exe | 修改文件 | \Device\Afd\Endpoint |
04/04/10 18:59:07 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYWizard.exe | Sandbox中运行 | 低权限级别 |
04/04/10 18:59:07 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYWizard.exe | DNS/RPC 客户端访问 | |
04/04/10 19:01:32 | F:\Program Files\SogouExplorer\setask.exe | 访问COM接口 | Shell.Explorer.2 |
04/04/10 19:01:39 | F:\Program Files\SogouExplorer\SogouExplorer.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:01:39 | \Device\HarddiskVolume4\Program Files\SogouExplorer\SogouExplorer.exe | DNS/RPC 客户端访问 | |
04/04/10 19:01:39 | F:\Program Files\SogouExplorer\SogouExplorer.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:01:39 | F:\Program Files\SogouExplorer\setask.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:01:39 | F:\Program Files\SogouExplorer\SogouExplorer.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:01:39 | F:\Program Files\SogouExplorer\SogouExplorer.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:01:39 | F:\Program Files\SogouExplorer\setask.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:01:44 | F:\Program Files\SogouExplorer\setask.exe | 修改注册表项 | HKUS\S-1-5-21-2000478354-842925246-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aedb0b44-3e48-11df-8992-806d6172696f}\BaseClass |
04/04/10 19:01:44 | F:\Program Files\SogouExplorer\setask.exe | 修改注册表项 | HKUS\S-1-5-21-2000478354-842925246-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aedb0b44-3e48-11df-8992-806d6172696f}\BaseClass |
04/04/10 19:01:53 | F:\Program Files\SogouExplorer\SogouExplorer.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:01:53 | F:\Program Files\SogouExplorer\SogouExplorer.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:01:59 | F:\Program Files\SogouExplorer\SogouExplorer.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:05:58 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:05:58 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | DNS/RPC 客户端访问 | |
04/04/10 19:05:58 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:06:17 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:06:17 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:07:03 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYStrokesHelper.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:07:03 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYStrokesHelper.exe | DNS/RPC 客户端访问 | |
04/04/10 19:07:28 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYStrokesHelper.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:07:28 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYStrokesHelper.exe | DNS/RPC 客户端访问 | |
04/04/10 19:07:47 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:07:47 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | DNS/RPC 客户端访问 | |
04/04/10 19:07:47 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:08:50 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:08:50 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | DNS/RPC 客户端访问 | |
04/04/10 19:08:50 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYClipboard.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:08:53 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYDict.exe | 访问COM接口 | Shell.Explorer.2 |
04/04/10 19:08:59 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYClipboard.exe | DNS/RPC 客户端访问 | |
04/04/10 19:08:59 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYDict.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:09:00 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYDict.exe | DNS/RPC 客户端访问 | |
04/04/10 19:09:06 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYDict.exe | 修改注册表项 | HKUS\S-1-5-21-2000478354-842925246-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aedb0b44-3e48-11df-8992-806d6172696f}\BaseClass |
04/04/10 19:09:32 | C:\WINDOWS\Explorer.EXE | 修改文件 | C:\WINDOWS\system.ini |
04/04/10 19:10:08 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYStrokesHelper.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:10:08 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYStrokesHelper.exe | DNS/RPC 客户端访问 | |
04/04/10 19:10:08 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYTrayBar.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:10:08 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYDict.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:10:14 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYWizard.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:10:14 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYWizard.exe | 修改注册表项 | HKUS\S-1-5-21-2000478354-842925246-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aedb0b44-3e48-11df-8992-806d6172696f}\BaseClass |
04/04/10 19:10:14 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYWizard.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:10:14 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYWizard.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:10:14 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYWizard.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:10:25 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYTrayBar.exe | DNS/RPC 客户端访问 | |
04/04/10 19:10:27 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYWizard.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:10:27 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYWizard.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:10:27 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYWizard.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:10:30 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYWizard.exe | DNS/RPC 客户端访问 | |
04/04/10 19:10:43 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | 修改文件 | C:\Documents and Settings\Administrator\Application Data\Tencent\QQPinyin\unuseime.txt |
04/04/10 19:10:48 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | 修改文件 | \Device\NamedPipe\lsarpc |
04/04/10 19:11:51 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | 创建进程, 执行镜像 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe |
04/04/10 19:12:08 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYLevel.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:12:08 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYLevel.exe | DNS/RPC 客户端访问 | |
04/04/10 19:12:08 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYLevel.exe | 访问内存 | C:\WINDOWS\Explorer.EXE |
04/04/10 19:12:08 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:12:08 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:12:28 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:12:35 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:12:40 | F:\Program Files\SogouExplorer\SogouExplorer.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:12:40 | \Device\HarddiskVolume4\Program Files\SogouExplorer\SogouExplorer.exe | DNS/RPC 客户端访问 | |
04/04/10 19:12:40 | F:\Program Files\SogouExplorer\SogouExplorer.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:12:40 | F:\Program Files\SogouExplorer\setask.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:12:40 | F:\Program Files\SogouExplorer\setask.exe | 修改注册表项 | HKUS\S-1-5-21-2000478354-842925246-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aedb0b44-3e48-11df-8992-806d6172696f}\BaseClass |
04/04/10 19:12:40 | F:\Program Files\SogouExplorer\setask.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:12:40 | F:\Program Files\SogouExplorer\setask.exe | 修改注册表项 | HKUS\S-1-5-21-2000478354-842925246-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aedb0b44-3e48-11df-8992-806d6172696f}\BaseClass |
04/04/10 19:12:46 | F:\Program Files\SogouExplorer\SogouExplorer.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:12:46 | F:\Program Files\SogouExplorer\SogouExplorer.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:12:51 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:12:51 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:12:59 | F:\Program Files\SogouExplorer\SogouExplorer.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:13:01 | \Device\HarddiskVolume1\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | DNS/RPC 客户端访问 | |
04/04/10 19:13:05 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:13:05 | F:\Program Files\SogouExplorer\SogouExplorer.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:13:05 | F:\Program Files\SogouExplorer\setask.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:13:18 | F:\Program Files\SogouExplorer\SogouExplorer.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:13:18 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:13:18 | F:\Program Files\SogouExplorer\SogouExplorer.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:13:23 | F:\Program Files\SogouExplorer\SogouExplorer.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:13:23 | F:\Program Files\SogouExplorer\setask.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:13:36 | F:\Program Files\SogouExplorer\SogouExplorer.exe | Sandbox中运行 | 低权限级别 |
04/04/10 19:13:36 | F:\Program Files\SogouExplorer\SogouExplorer.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:13:36 | F:\Program Files\SogouExplorer\setask.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:13:36 | F:\Program Files\SogouExplorer\SogouExplorer.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:13:36 | F:\Program Files\SogouExplorer\SogouExplorer.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:13:36 | C:\Program Files\Tencent\QQPinyin\3.1.730.201\QQPYConfig.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:13:47 | F:\Program Files\SogouExplorer\SogouExplorer.exe | 访问内存 | C:\WINDOWS\System32\ctfmon.exe |
04/04/10 19:13:47 | F:\Program Files\SogouExplorer\setask.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
04/04/10 19:32:39 | F:\Program Files\SogouExplorer\setask.exe | 访问COM接口 | {9BA05972-F6A8-11CF-A442-00A0C90A8F39} |
04/04/10 19:32:48 | F:\Program Files\SogouExplorer\SogouExplorer.exe | 直接磁盘访问 | PhysicalDrive0 |
04/04/10 19:32:48 | F:\Program Files\SogouExplorer\setask.exe | 直接磁盘访问 | PhysicalDrive0 |
04/04/10 19:32:48 | F:\Program Files\SogouExplorer\setask.exe | 直接磁盘访问 | PhysicalDrive0 |
04/04/10 19:38:51 | F:\Program Files\SogouExplorer\setask.exe | 发送消息 | F:\Program Files\SogouExplorer\SogouExplorer.exe |
04/04/10 19:38:51 | F:\Program Files\SogouExplorer\SogouExplorer.exe | 直接显示器访问 | |
04/04/10 19:38:52 | E:\多益网络\逍遥传说\patch\xy.bin | 访问COM接口 | Shell.Explorer.2 |
04/04/10 19:38:59 | E:\多益网络\逍遥传说\patch\xy.bin | 修改文件 | \Device\Tcp |
04/04/10 19:39:36 | E:\多益网络\逍遥传说\xymain.dll | Sandbox中运行 | 低权限级别 |
04/04/10 19:39:37 | \Device\HarddiskVolume3\多益网络\逍遥传说\xymain.dll | DNS/RPC 客户端访问 | |