日期 | 应用程序 | 行为 | 目标 |
2010-09-12 00:05:04 | D:\hotel2009\HMIS6.exe | 终止进程 | D:\hotel2009\hmisdata.exe |
2010-09-12 00:05:25 | D:\program files\QQ\Bin\QQ.exe | 修改注册表项 | HKLM\SOFTWARE\Classes\Interface\{0360A34A-2C57-4222-985F-33FC442E207F}\TypeLib\ |
2010-09-12 00:05:37 | D:\program files\QQ\Bin\QQ.exe | 直接磁盘访问 | PhysicalDrive0 |
2010-09-12 00:05:58 | D:\hotel2009\HMIS6.exe | 终止进程 | D:\hotel2009\hmisdata.exe |
2010-09-12 00:06:55 | D:\hotel2009\HMIS6.exe | 终止进程 | D:\hotel2009\hmisdata.exe |
2010-09-12 00:09:23 | D:\program files\QQ\Bin\QQ.exe | 拦截文件 | C:\Autorun.inf |
2010-09-12 00:09:30 | D:\program files\QQ\Bin\QQ.exe | 拦截文件 | D:\Autorun.inf |
2010-09-12 00:09:30 | D:\program files\QQ\Bin\QQ.exe | 拦截文件 | E:\Autorun.inf |
2010-09-12 00:09:30 | D:\program files\QQ\Bin\QQ.exe | 拦截文件 | F:\Autorun.inf |
2010-09-12 00:09:30 | D:\program files\QQ\Bin\QQ.exe | 拦截文件 | G:\Autorun.inf |
2010-09-12 00:09:30 | D:\program files\QQ\Bin\QQ.exe | 修改注册表项 | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Start Menu |
2010-09-12 00:17:56 | D:\hotel2009\hmisdata.exe | 终止进程 | D:\hotel2009\HMIS6.exe |
2010-09-12 00:32:07 | D:\hotel2009\HMIS6.exe | 终止进程 | D:\hotel2009\hmisdata.exe |
2010-09-12 00:32:17 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | C:\Autorun.inf |
2010-09-12 00:32:17 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | D:\Autorun.inf |
2010-09-12 00:32:17 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | E:\Autorun.inf |
2010-09-12 00:32:17 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | F:\Autorun.inf |
2010-09-12 00:32:17 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | G:\Autorun.inf |
2010-09-12 08:44:27 | C:\Program Files\StormII\Storm.exe | 创建进程, 执行镜像 | C:\Program Files\StormII\Storm.exe |
2010-09-12 08:44:39 | C:\Program Files\StormII\Storm.exe | 访问COM接口 | \Windows\ApiPort |
2010-09-12 08:44:54 | C:\Program Files\StormII\Storm.exe | 创建进程, 执行镜像 | C:\Program Files\StormII\stormliv.exe |
2010-09-12 09:22:15 | D:\program files\QQ\Bin\QQ.exe | 修改注册表项 | HKLM\SOFTWARE\Classes\Interface\{0360A34A-2C57-4222-985F-33FC442E207F}\TypeLib\ |
2010-09-12 09:22:23 | D:\program files\QQ\Bin\QQ.exe | 直接磁盘访问 | PhysicalDrive0 |
2010-09-12 09:23:17 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | C:\Autorun.inf |
2010-09-12 09:23:25 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | D:\Autorun.inf |
2010-09-12 09:23:25 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | E:\Autorun.inf |
2010-09-12 09:23:25 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | F:\Autorun.inf |
2010-09-12 09:23:25 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | G:\Autorun.inf |
2010-09-12 09:25:02 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | C:\Autorun.inf |
2010-09-12 09:25:10 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | D:\Autorun.inf |
2010-09-12 09:25:10 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | E:\Autorun.inf |
2010-09-12 09:25:10 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | F:\Autorun.inf |
2010-09-12 09:25:10 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | G:\Autorun.inf |
2010-09-12 09:26:17 | D:\program files\QQ\Bin\QQ.exe | 拦截文件 | C:\Autorun.inf |
2010-09-12 09:26:17 | D:\program files\QQ\Bin\QQ.exe | 拦截文件 | D:\Autorun.inf |
2010-09-12 09:26:17 | D:\program files\QQ\Bin\QQ.exe | 拦截文件 | E:\Autorun.inf |
2010-09-12 09:26:17 | D:\program files\QQ\Bin\QQ.exe | 拦截文件 | F:\Autorun.inf |
2010-09-12 09:26:17 | D:\program files\QQ\Bin\QQ.exe | 拦截文件 | G:\Autorun.inf |
2010-09-12 09:26:17 | D:\program files\QQ\Bin\QQ.exe | 修改注册表项 | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Start Menu |
2010-09-12 09:32:04 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | C:\Autorun.inf |
2010-09-12 09:32:04 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | D:\Autorun.inf |
2010-09-12 09:32:04 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | E:\Autorun.inf |
2010-09-12 09:32:04 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | F:\Autorun.inf |
2010-09-12 09:32:04 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | G:\Autorun.inf |
2010-09-12 09:32:04 | D:\hotel2009\hmisdata.exe | 终止进程 | D:\hotel2009\HMIS6.exe |
2010-09-12 09:33:37 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | C:\Autorun.inf |
2010-09-12 09:33:37 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | D:\Autorun.inf |
2010-09-12 09:33:37 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | E:\Autorun.inf |
2010-09-12 09:33:37 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | F:\Autorun.inf |
2010-09-12 09:33:37 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | G:\Autorun.inf |
2010-09-12 09:34:30 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | C:\Autorun.inf |
2010-09-12 09:34:38 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | D:\Autorun.inf |
2010-09-12 09:34:38 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | E:\Autorun.inf |
2010-09-12 09:34:38 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | F:\Autorun.inf |
2010-09-12 09:34:38 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | G:\Autorun.inf |
2010-09-12 09:34:54 | D:\hotel2009\HMIS6.exe | 终止进程 | D:\hotel2009\hmisdata.exe |
2010-09-12 09:35:06 | D:\hotel2009\HMIS6.exe | 终止进程 | D:\hotel2009\hmisdata.exe |
2010-09-12 09:35:28 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | C:\Autorun.inf |
2010-09-12 09:35:28 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | D:\Autorun.inf |
2010-09-12 09:35:28 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | E:\Autorun.inf |
2010-09-12 09:35:28 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | F:\Autorun.inf |
2010-09-12 09:35:28 | C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe | 拦截文件 | G:\Autorun.inf |