2010-10-10 11:21:58 | C:\Program Files\Thunder\Program\takeown.bat | 修改文件 | \Global??\FltMgrMsg |
2010-10-10 11:21:58 | C:\Program Files\Thunder\Program\takeown.bat | 创建进程 | C:\Windows\System32\takeown.exe |
2010-10-10 11:21:58 | C:\Program Files\Thunder\Program\takeown.bat | 修改文件 | \Global??\FltMgrMsg |
2010-10-10 11:21:58 | C:\Program Files\Thunder\Program\takeown.bat | 创建进程 | C:\Windows\System32\takeown.exe |
2010-10-10 11:21:58 | C:\Program Files\Thunder\Program\takeown.bat | 修改文件 | \Global??\FltMgrMsg |
2010-10-10 11:21:58 | C:\Program Files\Thunder\Program\takeown.bat | 创建进程 | C:\Windows\System32\netsh.exe |
2010-10-10 11:21:58 | C:\Program Files\Thunder\Program\takeown.bat | 修改文件 | \Device\C: |
2010-10-10 11:21:58 | C:\Program Files\Thunder\Program\takeown.bat | 创建进程 | C:\Windows\System32\takeown.exe |
2010-10-10 11:21:58 | C:\Program Files\Thunder\Program\takeown.bat | 修改文件 | \Global??\FltMgrMsg |
2010-10-10 11:21:58 | C:\Program Files\Thunder\Program\takeown.bat | 创建进程 | C:\Windows\System32\netsh.exe |
2010-10-10 11:21:58 | C:\Program Files\Thunder\Program\takeown.bat | 修改文件 | \Device\C: |
2010-10-10 11:21:58 | C:\Program Files\Thunder\Program\takeown.bat | 创建进程 | C:\Windows\System32\takeown.exe |
2010-10-10 02:17:09 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | \Global??\FltMgrMsg |
2010-10-10 02:17:14 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 直接磁盘访问 | PhysicalDrive0 |
2010-10-10 02:17:14 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | \Device\Scsi0: |
2010-10-10 02:17:14 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 直接磁盘访问 | PhysicalDrive0 |
2010-10-10 02:17:14 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | C:\ProgramData |
2010-10-10 02:17:14 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
2010-10-10 02:17:14 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | \Device\Nsi |
2010-10-10 02:17:14 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改注册表项 | HKUS\S-1-5-21-846135387-1610982575-1679880407-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
2010-10-10 02:17:14 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | C:\Users\Love |
2010-10-10 02:17:14 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | C:\Windows\system32 |
2010-10-10 02:17:19 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | \Device\Scsi0: |
2010-10-10 02:17:19 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 直接磁盘访问 | PhysicalDrive0 |
2010-10-10 02:17:19 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | C:\ProgramData |
2010-10-10 02:17:19 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
2010-10-10 02:17:19 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | \Device\Nsi |
2010-10-10 02:17:19 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | C:\Windows\system32 |
2010-10-10 02:17:24 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | \Device\Scsi0: |
2010-10-10 02:17:24 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 直接磁盘访问 | PhysicalDrive0 |
2010-10-10 02:17:24 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | C:\ProgramData |
2010-10-10 02:17:24 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
2010-10-10 02:17:24 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | \Device\Nsi |
2010-10-10 02:17:24 | F:\TheWorld 3\TheWorld.exe | 访问内存 | C:\Windows\explorer.exe |
2010-10-10 02:17:24 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | C:\Windows\system32 |
2010-10-10 02:17:29 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | \Device\Scsi0: |
2010-10-10 02:17:29 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 直接磁盘访问 | PhysicalDrive0 |
2010-10-10 02:17:29 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | C:\ProgramData |
2010-10-10 02:17:29 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
2010-10-10 02:17:29 | F:\QQPinyin\3.4.922.400\QQPYConfig.exe | 修改文件 | \Device\Nsi |