2011-01-07 18:51:41 | C:\Users\k\Desktop\baidu.vbs | 发送消息 | C:\Windows\explorer.exe |
2011-01-07 18:51:46 | C:\Users\k\Desktop\baidu.vbs | 创建进程 | C:\Program Files\Internet Explorer\iexplore.exe |
2011-01-07 18:51:49 | C:\Users\k\Desktop\baidu.vbs | 修改文件 | C:\Users\k\Desktop\baidu.vbs |
2011-01-07 18:51:50 | C:\Users\k\Desktop\baidu.vbs | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
2011-01-07 18:51:51 | C:\Users\k\Desktop\baidu.vbs | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer |
2011-01-07 18:51:52 | C:\Users\k\Desktop\baidu.vbs | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride |
2011-01-07 18:51:53 | C:\Users\k\Desktop\baidu.vbs | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
2011-01-07 18:51:59 | C:\Users\k\Desktop\baidu.vbs | 创建进程 | C:\Windows\System32\cmd.exe |
2011-01-07 18:52:03 | C:\Users\k\Desktop\baidu.vbs | 创建进程 | C:\Windows\regedit.exe |
2011-01-07 18:52:06 | C:\Users\k\AppData\Local\Temp\xf.vbs | 发送消息 | C:\Program Files\Internet Explorer\iexplore.exe |
2011-01-07 18:52:08 | C:\Users\k\AppData\Local\Temp\page.vbs | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
2011-01-07 18:52:11 | C:\Windows\System32\cmd.exe | 创建进程 | C:\Users\k\AppData\Local\Temp\aa.exe |
2011-01-07 18:52:12 | C:\Users\k\AppData\Local\Temp\page.vbs | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer |
2011-01-07 18:52:13 | C:\Users\k\AppData\Local\Temp\aa.exe | 访问COM接口 | Shell.Explorer.2 |
2011-01-07 18:52:14 | C:\Users\k\AppData\Local\Temp\page.vbs | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride |
2011-01-07 18:52:15 | C:\Users\k\AppData\Local\Temp\aa.exe | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
2011-01-07 18:52:16 | C:\Users\k\AppData\Local\Temp\aa.exe | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer |
2011-01-07 18:52:17 | C:\Users\k\AppData\Local\Temp\aa.exe | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride |
2011-01-07 18:52:18 | C:\Users\k\AppData\Local\Temp\aa.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
2011-01-07 18:52:19 | C:\Users\k\AppData\Local\Temp\page.vbs | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
2011-01-07 18:52:24 | C:\Users\k\AppData\Local\Temp\page.vbs | 创建进程 | C:\Windows\System32\cmd.exe |
2011-01-07 18:52:28 | C:\Users\k\AppData\Local\Temp\page.vbs | 发送消息 | C:\Program Files\Internet Explorer\iexplore.exe |
2011-01-07 18:52:31 | C:\Windows\System32\cmd.exe | 创建进程 | C:\Users\k\AppData\Local\Temp\aiqi4397.exe |
2011-01-07 18:52:32 | C:\Users\k\AppData\Local\Temp\de.vbs | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Internet Explorer\Main\Start Page |
2011-01-07 18:52:33 | C:\Users\k\AppData\Local\Temp\aiqi4397.exe | 安装钩子 | C:\Windows\system32\MSVBVM60.DLL |
2011-01-07 18:52:34 | C:\Users\k\AppData\Local\Temp\de.vbs | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Internet Explorer\Main\Start Page |
2011-01-07 18:52:35 | C:\Users\k\AppData\Local\Temp\de.vbs | 修改注册表项 | HKLM\SOFTWARE\Classes\CLSID\{1f4de370-ba4f-11d1-d627-00a0c91eedba}\Instance\InitPropertyBag |
2011-01-07 18:52:36 | C:\Windows\System32\cmd.exe | 创建进程 | C:\Users\k\AppData\Local\Temp\cpa.exe |
2011-01-07 18:52:37 | C:\Users\k\AppData\Local\Temp\aiqi4397.exe | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
2011-01-07 18:52:38 | C:\Users\k\AppData\Local\Temp\de.vbs | 修改注册表项 | HKLM\SOFTWARE\Classes\CLSID |
2011-01-07 18:52:39 | C:\Users\k\AppData\Local\Temp\aiqi4397.exe | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer |
2011-01-07 18:52:40 | C:\Users\k\AppData\Local\Temp\de.vbs | 修改注册表项 | HKLM\SOFTWARE\Classes\CLSID\{1f4de370-ba4f-11d1-d627-00a0c91eedba} |
2011-01-07 18:52:41 | C:\Users\k\AppData\Local\Temp\aiqi4397.exe | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride |
2011-01-07 18:52:42 | C:\Users\k\AppData\Local\Temp\de.vbs | 修改注册表项 | HKLM\SOFTWARE\Classes\CLSID\{1f4de370-ba4f-11d1-d627-00a0c91eedba}\Instance |
2011-01-07 18:52:43 | C:\Users\k\AppData\Local\Temp\aiqi4397.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |
2011-01-07 18:52:44 | C:\Users\k\AppData\Local\Temp\de.vbs | 修改注册表项 | HKLM\SOFTWARE\Classes\CLSID\{1f4de370-ba4f-11d1-d627-00a0c91eedba}\Instance\InitPropertyBag\method |
2011-01-07 18:52:45 | C:\Users\k\AppData\Local\Temp\de.vbs | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Policies\Microsoft\MMC |
2011-01-07 18:52:48 | C:\Users\k\AppData\Local\Temp\de.vbs | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Policies\Microsoft\MMC\RestrictToPermittedSnapins |
2011-01-07 18:52:50 | C:\Users\k\AppData\Local\Temp\de.vbs | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
2011-01-07 18:52:51 | C:\Users\k\AppData\Local\Temp\de.vbs | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktopCleanupWizard |
2011-01-07 18:52:52 | C:\Users\k\AppData\Local\Temp\aa.exe | 访问内存 | C:\Windows\explorer.exe |
2011-01-07 18:52:59 | C:\Windows\System32\cmd.exe | 创建进程 | C:\Users\k\AppData\Local\Temp\1018new.exe |
2011-01-07 18:53:10 | C:\Users\k\AppData\Local\Temp\1018new.exe | 创建进程 | C:\Program Files\TTPlayer\TPlayer.exe |
2011-01-07 18:53:14 | C:\Users\k\AppData\Local\Temp\xing.vbs | 修改文件 | C:\Windows\jeo.vbe |
2011-01-07 18:53:16 | C:\Users\k\Desktop\baidu.vbs | 创建进程 | C:\Windows\explorer.exe |
2011-01-07 18:53:17 | C:\Program Files\TTPlayer\TPlayer.exe | 修改文件 | C:\Windows\system32\Factory.dll |
2011-01-07 18:53:18 | C:\Users\k\AppData\Local\Temp\xing.vbs | 访问COM接口 | WINMGMTS.1 |
2011-01-07 18:53:21 | C:\Program Files\TTPlayer\TPlayer.exe | 创建进程 | C:\Windows\System32\wscript.exe |
2011-01-07 18:53:24 | C:\Users\k\AppData\Local\Temp\xing.vbs | 访问COM接口 | {8BC3F05E-D86B-11D0-A075-00C04FB68820} |
2011-01-07 18:53:26 | C:\Program Files\TTPlayer\TPlayer.exe | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable |
2011-01-07 18:53:28 | C:\Users\k\AppData\Local\Temp\xing.vbs | 访问COM接口 | C:\Windows\System32\svchost.exe |
2011-01-07 18:53:29 | C:\Program Files\TTPlayer\TPlayer.exe | 访问COM接口 | Shell.Explorer.2 |
2011-01-07 18:53:31 | C:\Program Files\TTPlayer\TPlayer.exe | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer |
2011-01-07 18:53:33 | C:\Users\k\AppData\Local\Temp\C4PU8.vbs | 访问COM接口 | {8BC3F05E-D86B-11D0-A075-00C04FB68820} |
2011-01-07 18:53:35 | C:\Users\k\AppData\Local\Temp\xing.vbs | 创建进程 | C:\Windows\System32\attrib.exe |
2011-01-07 18:53:36 | C:\Program Files\TTPlayer\TPlayer.exe | 修改注册表项 | HKUS\S-1-5-21-3799767426-424094828-1398871737-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride |
2011-01-07 18:53:38 | C:\Users\k\AppData\Local\Temp\C4PU8.vbs | 访问COM接口 | C:\Windows\System32\svchost.exe |
2011-01-07 18:53:39 | C:\Users\k\AppData\Local\Temp\xing.vbs | 创建进程 | C:\Windows\System32\cacls.exe |
2011-01-07 18:53:40 | C:\Program Files\TTPlayer\TPlayer.exe | DNS/RPC 客户端访问 | \RPC Control\DNSResolver |