|
发表于 2016-4-20 09:13:47
|
显示全部楼层
时间 操作 说明 次数
2016-04-20 09:07:26 [已阻止] 修改 系统常用文件夹 防护 1 次
详细描述:
注册表位置:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\[AppData]
注册表内容:C:\Documents and Settings\wangping\Application Data
进程:E:\Program Files\USM_v5全能版\Data\PECMDx86.EXE
父进程:C:\WINDOWS\System32\cmd.exe , (103)
2016-04-20 09:06:47 [已允许] 磁盘关键扇区写入 防护 1 次
详细描述:
进程:C:\WINDOWS\system32\FORMAT.COM
动作:写物理磁盘
路径:
2016-04-20 09:06:27 [已允许] 磁盘关键扇区写入 防护 1 次
详细描述:
进程:e:\Program Files\USM_v5全能版\data\PECMDx86.EXE
动作:写物理磁盘
路径:
2016-04-20 09:06:16 [自动阻止] 模拟按键 防护 1 次
详细描述:
进程:e:\Program Files\USM_v5全能版\data\PECMDx86.EXE PECMD**pecmd-cmd* LOAD *qk #20:INDATA U 32768, (1, 4)
动作:模拟按键
路径:
2016-04-20 09:02:42 [已允许] 磁盘关键扇区写入 防护 1 次
详细描述:
进程:D:\temp\usmsettemp\uwork.fun
动作:写物理磁盘
路径:
2016-04-20 09:00:49 [已阻止] 磁盘关键扇区写入 防护 1 次
详细描述:
进程:D:\temp\usmsettemp\uwork.fun
动作:写物理磁盘
路径:
2016-04-20 08:56:56 [已阻止] 修改 IE连接设置 防护 1 次
详细描述:
注册表位置:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\[DefaultConnectionSettings]
注册表内容:46 00 00 00 82 22 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 D0 82 6C F7 BA 97 D1 01 01 00 00 00 C0 A8 01 65 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 C0 A8 01 C8 00 00 00 00 00 00 00 00 49 00 43 00 45 00 5C 00 54 00 43 00 50 00 49 00 50 00 5F 00 7B 00 38 00 41 00 39 00 41 00 43 00 43 00 31 00 38 00 2D 00 43 00 43 00 46 00 36 00 2D 00 34 00 38 00 34 00 37 00 2D 00 38 00 38 00 33 00 36 00 2D 00 43 00 38 00 33 00 39 00 46 00 37 00 30 00 45 00 44 00 39 00 46 00 45 00 7D 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
进程:D:\temp\usmup.exe
父进程:E:\Program Files\USM_v5全能版\USM.exe , (103)
2016-04-20 08:56:21 [已阻止] 修改 IE连接设置 防护 1 次
详细描述:
注册表位置:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\[DefaultConnectionSettings]
注册表内容:46 00 00 00 82 22 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 D0 82 6C F7 BA 97 D1 01 01 00 00 00 C0 A8 01 65 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 C0 A8 01 C8 00 00 00 00 00 00 00 00 49 00 43 00 45 00 5C 00 54 00 43 00 50 00 49 00 50 00 5F 00 7B 00 38 00 41 00 39 00 41 00 43 00 43 00 31 00 38 00 2D 00 43 00 43 00 46 00 36 00 2D 00 34 00 38 00 34 00 37 00 2D 00 38 00 38 00 33 00 36 00 2D 00 43 00 38 00 33 00 39 00 46 00 37 00 30 00 45 00 44 00 39 00 46 00 45 00 7D 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
进程:E:\Program Files\USM_v5全能版\USM.exe
父进程:D:\temp\usmup.exe , (103)
2016-04-20 08:55:34 [已阻止] 修改 系统常用文件夹 防护 1 次
详细描述:
注册表位置:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\[AppData]
注册表内容:C:\Documents and Settings\wangping\Application Data
进程:C:\WINDOWS\Temp\~tmpxunlei\download\MiniThunderPlatform.exe
父进程:D:\temp\usmup.exe , (103)
2016-04-20 08:54:55 [已阻止] 修改 IE连接设置 防护 1 次
详细描述:
注册表位置:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\[DefaultConnectionSettings]
注册表内容:46 00 00 00 82 22 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 D0 82 6C F7 BA 97 D1 01 01 00 00 00 C0 A8 01 65 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 C0 A8 01 C8 00 00 00 00 00 00 00 00 49 00 43 00 45 00 5C 00 54 00 43 00 50 00 49 00 50 00 5F 00 7B 00 38 00 41 00 39 00 41 00 43 00 43 00 31 00 38 00 2D 00 43 00 43 00 46 00 36 00 2D 00 34 00 38 00 34 00 37 00 2D 00 38 00 38 00 33 00 36 00 2D 00 43 00 38 00 33 00 39 00 46 00 37 00 30 00 45 00 44 00 39 00 46 00 45 00 7D 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
进程:D:\temp\usmup.exe
父进程:E:\Program Files\USM_v5全能版\USM.exe , (103)
2016-04-20 08:54:42 [已阻止] 修改 IE连接设置 防护 1 次
详细描述:
注册表位置:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\[DefaultConnectionSettings]
注册表内容:46 00 00 00 81 22 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 D0 82 6C F7 BA 97 D1 01 01 00 00 00 C0 A8 01 65 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 C0 A8 01 C8 00 00 00 00 00 00 00 00 49 00 43 00 45 00 5C 00 54 00 43 00 50 00 49 00 50 00 5F 00 7B 00 38 00 41 00 39 00 41 00 43 00 43 00 31 00 38 00 2D 00 43 00 43 00 46 00 36 00 2D 00 34 00 38 00 34 00 37 00 2D 00 38 00 38 00 33 00 36 00 2D 00 43 00 38 00 33 00 39 00 46 00 37 00 30 00 45 00 44 00 39 00 46 00 45 00 7D 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
进程:E:\Program Files\USM_v5全能版\USM.exe
父进程:E:\cache\桌面\TEMP\usm_v5f.exe , (103)
|
|