2007-07-23 06:56:59 创建文件 操作:允许
进程路径:D:\桌面\virus\update1\update1.exe
文件路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\user\current\Local Settings\Temp\4mz.dll
触发规则:黑名单->白名單->C:\Documents and Settings\HungAndy\Application Data\Sandbox\*
2007-07-23 06:57:00 创建文件 操作:允许
进程路径:D:\桌面\virus\update1\update1.exe
文件路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\user\current\Local Settings\Temp\t.sys
触发规则:黑名单->白名單->C:\Documents and Settings\HungAndy\Application Data\Sandbox\*
2007-07-23 06:57:03 加载驱动程序 操作:允许
进程路径:D:\桌面\virus\update1\update1.exe
驱动名称:t.sys
触发规则:所有程序规则->*
2007-07-23 06:57:05 修改其它进程内存 操作:允许
进程路径:D:\桌面\virus\update1\update1.exe
目标进程:C:\Program Files\Internet Explorer\iexplore.exe
触发规则:所有程序规则->系統程序->%ProgramFiles%\Internet Explorer\IEXPLORE.EXE
2007-07-23 06:57:11 创建文件 操作:允许
进程路径:D:\桌面\virus\update1\update1.exe
文件路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\drive\C\Program Files\Windows NT\SERVICES.EXE
触发规则:黑名单->白名單->C:\Documents and Settings\HungAndy\Application Data\Sandbox\*
2007-07-23 06:57:11 创建注册表值 操作:阻止
进程路径:D:\桌面\virus\update1\update1.exe
注册表路径:HKEY_CURRENT_USER\machine\software\microsoft\windows nt\currentversion\winlogon
注册表名称:Userinit
注册表数据:C:\WINDOWS\system32\userinit.exe,C:\Program Files\Windows NT\SERVICES.EXE,
触发规则:所有程序规则->WinLogon->*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon*
2007-07-23 06:57:11 创建文件 操作:允许
进程路径:D:\桌面\virus\update1\update1.exe
文件路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\user\current\Local Settings\Temp\$$c31.tmp
触发规则:黑名单->白名單->C:\Documents and Settings\HungAndy\Application Data\Sandbox\*
2007-07-23 06:57:11 创建文件 操作:允许
进程路径:D:\桌面\virus\update1\update1.exe
文件路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\user\current\Local Settings\Temp\$$c31.tmp.bat
触发规则:黑名单->白名單->C:\Documents and Settings\HungAndy\Application Data\Sandbox\*
2007-07-23 06:57:11 运行应用程序 操作:阻止
进程路径:D:\桌面\virus\update1\update1.exe
文件路径:C:\windows\system32\cmd.exe
命令行:/c C:\DOCUME~1\HungAndy\LOCALS~1\Temp\$$c31.tmp.bat
触发规则:所有程序规则->系統程序->%windir%\system32\cmd.exe
2007-07-23 06:57:14 创建文件 操作:允许
进程路径:C:\Program Files\Internet Explorer\iexplore.exe
文件路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\drive\C\windows\system32\wincab.sys
触发规则:黑名单->白名單->C:\Documents and Settings\HungAndy\Application Data\Sandbox\*
2007-07-23 06:57:14 运行应用程序 操作:允许
进程路径:D:\桌面\virus\update1\update1.exe
文件路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\drive\C\Program Files\Windows NT\SERVICES.EXE
触发规则:所有程序规则->*
2007-07-23 06:57:15 修改文件 操作:允许
进程路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\drive\C\Program Files\Windows NT\SERVICES.EXE
文件路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\user\current\Local Settings\Temp\4mz.dll
触发规则:黑名单->白名單->C:\Documents and Settings\HungAndy\Application Data\Sandbox\*
2007-07-23 06:57:15 创建文件 操作:允许
进程路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\drive\C\Program Files\Windows NT\SERVICES.EXE
文件路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\user\current\Local Settings\Temp\hykii4i.sys
触发规则:黑名单->白名單->C:\Documents and Settings\HungAndy\Application Data\Sandbox\*
2007-07-23 06:57:17 加载驱动程序 操作:允许
进程路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\drive\C\Program Files\Windows NT\SERVICES.EXE
驱动名称:hykii4i.sys
触发规则:所有程序规则->*
2007-07-23 06:57:19 修改其它进程内存 操作:允许
进程路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\drive\C\Program Files\Windows NT\SERVICES.EXE
目标进程:C:\Program Files\Internet Explorer\iexplore.exe
触发规则:所有程序规则->系統程序->%ProgramFiles%\Internet Explorer\IEXPLORE.EXE
2007-07-23 06:57:22 创建文件 操作:允许
进程路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\drive\C\Program Files\Windows NT\SERVICES.EXE
文件路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\drive\C\windows\system32\ACE.dll
触发规则:黑名单->白名單->C:\Documents and Settings\HungAndy\Application Data\Sandbox\*
2007-07-23 06:57:22 创建文件 操作:允许
进程路径:C:\Program Files\Internet Explorer\iexplore.exe
文件路径:C:\Documents and Settings\HungAndy\Application Data\Sandbox\DefaultBox\drive\C\windows\system32\wincab.sys
触发规则:黑名单->白名單->C:\Documents and Settings\HungAndy\Application Data\Sandbox\*
書籤