一定要注意喔.CMD (events: 2)
2008/10/1 下午 05:03:11 Placed in group High Restricted
2008/10/1 下午 05:03:15 Process start c:\documents and settings\administrator\local settings\temp\rarsfx0\21.sfx.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLStartProc
一定要注意喔.CMD (events: 2)
2008/10/1 下午 05:03:15 Placed in group High Restricted
2008/10/1 下午 05:03:15 Process start c:\windows\system32\notepad.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLStartProc
2008/10/1 下午 05:03:18 Process start c:\windows\system32\verclsid.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLStartProc
2008/10/1 下午 05:03:20 Process start c:\documents and settings\administrator\local settings\temp\rarsfx0\21.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLStartProc
一定要注意喔.CMD (events: 2)
2008/10/1 下午 05:03:20 Placed in group High Restricted
2008/10/1 下午 05:03:21 Process start c:\documents and settings\administrator\local settings\temp\sdwfew.bat Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLStartProc
2008/10/1 下午 05:03:21 Create C:\WINDOWS\system32\Lilo.exe Denied: KLSystemData/KLSystemFiles/SystemExe
2008/10/1 下午 05:03:21 Create C:\WINDOWS\system32\Lilo.exe Denied: KLSystemData/KLSystemFiles/SystemExe
2008/10/1 下午 05:03:21 Create C:\WINDOWS\system32\Lilo.exe Denied: KLSystemData/KLSystemFiles/SystemExe
2008/10/1 下午 05:03:21 Create C:\WINDOWS\Debug\Lilo.dll Denied: KLSystemData/KLSystemFiles/SystemDll
2008/10/1 下午 05:03:21 Process start c:\windows\system32\cmd.exe Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLStartProc
一定要注意喔.CMD (events: 2)
2008/10/1 下午 05:03:21 Placed in group Low Restricted
2008/10/1 下午 05:03:22 Process start c:\documents and settings\administrator\local settings\temp\xyntw.reg Allowed: KLPrivileges/KLPermissionAppAccess/KLPermissionProcManage/KLStartProc
一定要注意喔.CMD (events: 2)
2008/10/1 下午 05:03:22 Placed in group Low Restricted
2008/10/1 下午 05:03:22 Modification hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks Denied: KLSystemData/KLStartupRegKeys/ShellExecuteHooks
書籤