32楼: |
20:00:35:751, fmxlinux-trial.exe, 4212:0, 4212, EXEC_create, C:\Users\1\Desktop\fmxlinux-trial.exe, parent_pid:3096 cmdline:'"C:\Users\1\Desktop\fmxlinux-trial.exe" ' image_base:0x0000000000400000 image_size:0x00028000 , 0x00000000 [操作成功完成。 ], 20:00:35:756, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Segment Heap, access:0x00000001 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:756, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Segment Heap, access:0x00000001 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:758, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Wow64\x86, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:759, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wow64\x86\, type:0x00000001 datalen:26 data:'77 00 6F 00 77 00 36 00 34 00 63 00 70 00 75 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:766, fmxlinux-trial.exe, 4212:0, 4212, EXEC_module_load, C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll, base:0x0000000072DB0000 size:0x0020A000 , 0x00000000 [操作成功完成。 ], 20:00:35:772, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale, access:0x00000001 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:772, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale, access:0x00000001 , 0x00000000 [操作成功完成。 ], 20:00:35:772, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\NLS\Language, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:772, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\NLS\Language, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:772, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:772, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:772, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\Type, type:0x00000004 datalen:4 data:'92 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\DefaultFallback, type:0x00000001 datalen:12 data:'65 00 6E 00 2D 00 55 00 53 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\en-US, type:0x00000007 datalen:4 data:'00 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\DefaultFallback, type:0x00000001 datalen:12 data:'65 00 6E 00 2D 00 55 00 53 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\en-US, type:0x00000007 datalen:4 data:'00 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\LCID, type:0x00000004 datalen:4 data:'04 08 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\Type, type:0x00000004 datalen:4 data:'92 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\PendingDelete, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\PendingDelete, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MUI\Settings, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MUI\Settings, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER, access:0x02000000 , 0x00000000 [操作成功完成。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:773, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MUI\Settings, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MUI\Settings, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER, access:0x02000000 , 0x00000000 [操作成功完成。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Policies\Microsoft\Control Panel\Desktop, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Control Panel\Desktop\LanguageConfiguration, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MUI\Settings, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MUI\Settings, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER, access:0x02000000 , 0x00000000 [操作成功完成。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Policies\Microsoft\Control Panel\Desktop, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Control Panel\Desktop, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Control Panel\Desktop\PreferredUILanguages, type:0x00000007 datalen:12 data:'7A 00 68 00 2D 00 43 00 4E 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MUI\Settings, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MUI\Settings, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:774, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER, access:0x02000000 , 0x00000000 [操作成功完成。 ], 20:00:35:775, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:775, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages, type:0x00000007 datalen:12 data:'7A 00 68 00 2D 00 43 00 4E 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:775, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:775, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs, type:0x00000004 datalen:4 data:'00 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:776, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\WindowsShell.Manifest, access:0x001200A9 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:776, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:777, fmxlinux-trial.exe, 4212:0, 4212, EXEC_module_load, C:\Windows\SysWOW64\dtrampo.dll, base:0x0000000073A50000 size:0x0005F000 , 0x00000000 [操作成功完成。 ], 20:00:35:777, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER, access:0x02000000 , 0x00000000 [操作成功完成。 ], 20:00:35:777, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\CodeGear\Locales, access:0x000F0019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:778, fmxlinux-trial.exe, 4212:1216, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\Select, access:0x000F003F , 0xC0000022 [拒绝访问。 ], 20:00:35:778, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\WOW6432Node\CodeGear\Locales, access:0x000F0019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:778, fmxlinux-trial.exe, 4212:1216, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\Select, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:778, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Borland\Locales, access:0x000F0019 , 0x00000000 [操作成功完成。 ], 20:00:35:778, fmxlinux-trial.exe, 4212:1216, 4212, REG_getval, HKEY_LOCAL_MACHINE\SYSTEM\Select\Current, type:0x00000004 datalen:4 data:'01 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:778, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Users\1\Desktop\fmxlinux-trial.exe, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:35:779, fmxlinux-trial.exe, 4212:6328, 4212, FILE_readdir, C:\, filter:'Users' , 0x00000000 [操作成功完成。 ], 20:00:35:779, fmxlinux-trial.exe, 4212:6328, 4212, FILE_readdir, C:\Users, filter:'1' , 0x00000000 [操作成功完成。 ], 20:00:35:779, fmxlinux-trial.exe, 4212:6328, 4212, FILE_readdir, C:\Users\1, filter:'Desktop' , 0x00000000 [操作成功完成。 ], 20:00:35:783, fmxlinux-trial.exe, 4212:6328, 4212, SYS_opendev, \Device\DeviceApi, devtype:34 access:0x80000000 share:0x00000000 , 0x00000000 [操作成功完成。 ], 20:00:35:784, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CMF\Config, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:784, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CMF\Config, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:784, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CMF\Config\SYSTEM, type:0x00000004 datalen:4 data:'00 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:784, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\SysWOW64\zh-CN\KernelBase.dll.mui, access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000000 , 0x00000000 [操作成功完成。 ], 20:00:35:785, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\SysWOW64\netmsg.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:35:785, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\SysWOW64\netmsg.dll, access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:785, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\SysWOW64\zh-CN\netmsg.dll.mui, access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000000 , 0x00000000 [操作成功完成。 ], 20:00:35:785, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Users\1\Desktop\fmxlinux-trial.exe, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:787, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:787, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:787, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem\LongPathsEnabled, type:0x00000004 datalen:4 data:'00 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:789, fmxlinux-trial.exe, 4212:6328, 4212, FILE_touch, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, access:0x00120196 alloc_size:0 attrib:0x00000080 share_access:0x00000000 disposition:0x00000005 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:789, fmxlinux-trial.exe, 4212:6328, 4212, FILE_truncate, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, eof:0x00000000 , 0x00000000 [操作成功完成。 ], 20:00:35:850, fmxlinux-trial.exe, 4212:6328, 4212, FILE_truncate, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, eof:0x0011F600 , 0x00000000 [操作成功完成。 ], 20:00:35:850, fmxlinux-trial.exe, 4212:6328, 4212, FILE_truncate, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, eof:0x0011F600 , 0x00000000 [操作成功完成。 ], 20:00:35:851, fmxlinux-trial.exe, 4212:6328, 4212, FILE_write, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, offset:0x00000000 datalen:0x0011F600 , 0x00000000 [操作成功完成。 ], 20:00:35:852, fmxlinux-trial.exe, 4212:6328, 4212, FILE_modified, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, , 0x00000000 [操作成功完成。 ], 20:00:35:852, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Versions\000602xx, type:0x00000001 datalen:26 data:'6B 00 65 00 72 00 6E 00 65 00 6C 00 33 00 32 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:852, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\Globalization\Sorting\SortDefault.nls, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:853, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Ids, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:853, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Ids, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:853, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Ids\zh, type:0x00000001 datalen:78 data:'7B 00 30 00 30 00 30 00 30 00 30 00 30 00 33 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:854, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\SysWOW64\uxtheme.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:35:854, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\SysWOW64\uxtheme.dll, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:858, fmxlinux-trial.exe, 4212:6328, 4212, FILE_write, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, offset:0x00000000 datalen:0x00100000 , 0x00000000 [操作成功完成。 ], 20:00:35:858, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\SysWOW64\dwmapi.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:35:858, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\SysWOW64\dwmapi.dll, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:860, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:35:860, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:35:861, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, access:0x001000A1 alloc_size:0 attrib:0x00000080 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:862, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000003 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:871, fmxlinux-trial.exe, 4212:0, 4212, PROC_exec, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, target_pid:3904 , 0x00000000 [操作成功完成。 ], 20:00:35:874, fmxlinux-trial.exe, 4212:0, 4212, BA_exec_extratedfile, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, , 0x00000000 [操作成功完成。 ], 20:00:35:871, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:871, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:871, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\Temp, type:0x00000002 datalen:36 data:'25 00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:871, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:871, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot, type:0x00000001 datalen:22 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:871, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory, type:0x00000001 datalen:70 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001\ProfileImagePath, type:0x00000002 datalen:22 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\Temp, type:0x00000002 datalen:36 data:'25 00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:872, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot, type:0x00000001 datalen:22 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory, type:0x00000001 datalen:70 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001\ProfileImagePath, type:0x00000002 datalen:22 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\Temp, type:0x00000002 datalen:36 data:'25 00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:873, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot, type:0x00000001 datalen:22 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:874, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:874, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:874, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:874, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory, type:0x00000001 datalen:70 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:874, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:874, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:874, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:874, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:874, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:874, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001\ProfileImagePath, type:0x00000002 datalen:22 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:876, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:876, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:876, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\Temp, type:0x00000002 datalen:36 data:'25 00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:876, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:876, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot, type:0x00000001 datalen:22 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:877, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:877, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:877, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:877, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory, type:0x00000001 datalen:70 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:877, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:877, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:878, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:878, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:878, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:878, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001\ProfileImagePath, type:0x00000002 datalen:22 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:878, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:878, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:878, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\Temp, type:0x00000002 datalen:36 data:'25 00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:878, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:878, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot, type:0x00000001 datalen:22 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:878, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory, type:0x00000001 datalen:70 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001\ProfileImagePath, type:0x00000002 datalen:22 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\Temp, type:0x00000002 datalen:36 data:'25 00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:879, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot, type:0x00000001 datalen:22 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:880, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:880, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:880, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:880, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory, type:0x00000001 datalen:70 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:880, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:880, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:880, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:880, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:880, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:35:880, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001\ProfileImagePath, type:0x00000002 datalen:22 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:882, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls, access:0x00000001 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:882, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls, access:0x00000001 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:882, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option, access:0x00000003 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:35:883, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option, access:0x00000003 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:883, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, access:0x00000001 , 0x00000000 [操作成功完成。 ], 20:00:35:883, fmxlinux-trial.exe, 4212:6328, 4212, REG_getval, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache, type:0x00000001 datalen:106 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:35:883, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion, access:0x00000008 , 0x00000000 [操作成功完成。 ], 20:00:35:883, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers, access:0x00000001 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:884, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\AppPatch\sysmain.sdb, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:884, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\AppPatch\apppatch64\sysmain.sdb, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:884, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\AppPatch\sysmain.sdb, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:885, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:885, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:885, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\fmxlinux-trial.tmp, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:35:886, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:886, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:887, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:887, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:887, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:888, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:889, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:889, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:890, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:890, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:890, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:890, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:891, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:35:911, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\SysWOW64\apphelp.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:35:911, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\SysWOW64\apphelp.dll, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:912, fmxlinux-trial.exe, 4212:6328, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00000001 , 0x00000000 [操作成功完成。 ], 20:00:35:912, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Windows\AppPatch\sysmain.sdb, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:35:913, fmxlinux-trial.exe, 4212:6328, 4212, THRD_resume, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, target_pid:3904 target_tid:6740 , 0x00000000 [操作成功完成。 ], 20:00:37:545, fmxlinux-trial.exe, 584:0, 4212, EXEC_create, C:\Users\1\Desktop\fmxlinux-trial.exe, parent_pid:3904 cmdline:'"C:\Users\1\Desktop\fmxlinux-trial.exe" /SPAWNWND=$20DA0 /NOTIFYWND=$20C74 ' image_base:0x0000000000400000 image_size:0x00028000 , 0x00000000 [操作成功完成。 ], 20:00:37:549, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Segment Heap, access:0x00000001 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:549, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Segment Heap, access:0x00000001 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:37:551, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Wow64\x86, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:551, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wow64\x86\, type:0x00000001 datalen:26 data:'77 00 6F 00 77 00 36 00 34 00 63 00 70 00 75 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:568, fmxlinux-trial.exe, 584:0, 4212, EXEC_module_load, C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll, base:0x0000000072DB0000 size:0x0020A000 , 0x00000000 [操作成功完成。 ], 20:00:37:577, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:577, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs, type:0x00000004 datalen:4 data:'00 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:580, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\WindowsShell.Manifest, access:0x001200A9 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:37:580, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:580, fmxlinux-trial.exe, 584:0, 4212, EXEC_module_load, C:\Windows\SysWOW64\dtrampo.dll, base:0x0000000073A50000 size:0x0005F000 , 0x00000000 [操作成功完成。 ], 20:00:37:580, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER, access:0x02000000 , 0x00000000 [操作成功完成。 ], 20:00:37:580, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Software\CodeGear\Locales, access:0x000F0019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:37:581, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\WOW6432Node\CodeGear\Locales, access:0x000F0019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:37:581, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Borland\Locales, access:0x000F0019 , 0x00000000 [操作成功完成。 ], 20:00:37:581, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Users\1\Desktop\fmxlinux-trial.exe, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:37:581, fmxlinux-trial.exe, 584:6588, 4212, FILE_readdir, C:\, filter:'Users' , 0x00000000 [操作成功完成。 ], 20:00:37:581, fmxlinux-trial.exe, 584:6060, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\Select, access:0x000F003F , 0x00000000 [操作成功完成。 ], 20:00:37:582, fmxlinux-trial.exe, 584:6060, 4212, REG_getval, HKEY_LOCAL_MACHINE\SYSTEM\Select\Current, type:0x00000004 datalen:4 data:'01 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:582, fmxlinux-trial.exe, 584:6588, 4212, FILE_readdir, C:\Users, filter:'1' , 0x00000000 [操作成功完成。 ], 20:00:37:582, fmxlinux-trial.exe, 584:6588, 4212, FILE_readdir, C:\Users\1, filter:'Desktop' , 0x00000000 [操作成功完成。 ], 20:00:37:589, fmxlinux-trial.exe, 584:6588, 4212, SYS_opendev, \Device\DeviceApi, devtype:34 access:0x80000000 share:0x00000000 , 0x00000000 [操作成功完成。 ], 20:00:37:590, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CMF\Config, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:590, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CMF\Config, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:590, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CMF\Config\SYSTEM, type:0x00000004 datalen:4 data:'00 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:590, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\SysWOW64\zh-CN\KernelBase.dll.mui, access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000000 , 0x00000000 [操作成功完成。 ], 20:00:37:591, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\SysWOW64\netmsg.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:37:591, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\SysWOW64\zh-CN\netmsg.dll.mui, access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000000 , 0x00000000 [操作成功完成。 ], 20:00:37:593, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:593, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:594, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem\LongPathsEnabled, type:0x00000004 datalen:4 data:'00 00 00 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:596, fmxlinux-trial.exe, 584:6588, 4212, FILE_touch, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, access:0x00120196 alloc_size:0 attrib:0x00000080 share_access:0x00000000 disposition:0x00000005 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:37:596, fmxlinux-trial.exe, 584:6588, 4212, FILE_truncate, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, eof:0x00000000 , 0x00000000 [操作成功完成。 ], 20:00:37:653, fmxlinux-trial.exe, 584:6588, 4212, FILE_truncate, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, eof:0x0011F600 , 0x00000000 [操作成功完成。 ], 20:00:37:653, fmxlinux-trial.exe, 584:6588, 4212, FILE_truncate, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, eof:0x0011F600 , 0x00000000 [操作成功完成。 ], 20:00:37:654, fmxlinux-trial.exe, 584:6588, 4212, FILE_write, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, offset:0x00000000 datalen:0x0011F600 , 0x00000000 [操作成功完成。 ], 20:00:37:654, fmxlinux-trial.exe, 584:6588, 4212, FILE_modified, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, , 0x00000000 [操作成功完成。 ], 20:00:37:655, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Versions\000602xx, type:0x00000001 datalen:26 data:'6B 00 65 00 72 00 6E 00 65 00 6C 00 33 00 32 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:656, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Ids, access:0x00020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:656, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Ids, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:656, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Ids\zh, type:0x00000001 datalen:78 data:'7B 00 30 00 30 00 30 00 30 00 30 00 30 00 33 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:656, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\SysWOW64\uxtheme.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:37:657, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\SysWOW64\uxtheme.dll, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:37:658, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\SysWOW64\uxtheme.dll, access:0x00020000 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000000 , 0x00000000 [操作成功完成。 ], 20:00:37:659, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\SysWOW64\msctf.dll, access:0x00020000 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000000 , 0x00000000 [操作成功完成。 ], 20:00:37:661, fmxlinux-trial.exe, 584:6588, 4212, FILE_write, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, offset:0x00000000 datalen:0x00100000 , 0x00000000 [操作成功完成。 ], 20:00:37:661, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\SysWOW64\dwmapi.dll, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:37:661, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\SysWOW64\dwmapi.dll, access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:37:662, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\SysWOW64\dwmapi.dll, access:0x00020000 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000000 , 0x00000000 [操作成功完成。 ], 20:00:37:663, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:37:664, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, access:0x00000080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200000 , 0x00000000 [操作成功完成。 ], 20:00:37:664, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, access:0x001000A1 alloc_size:0 attrib:0x00000080 share_access:0x00000005 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:37:666, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000003 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:37:677, fmxlinux-trial.exe, 584:0, 4212, PROC_exec, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, target_pid:6004 , 0x00000000 [操作成功完成。 ], 20:00:37:681, fmxlinux-trial.exe, 584:0, 4212, BA_exec_extratedfile, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, , 0x00000000 [操作成功完成。 ], 20:00:37:678, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:678, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:678, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\Temp, type:0x00000002 datalen:36 data:'25 00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:678, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:678, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot, type:0x00000001 datalen:22 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:678, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:678, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:678, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:678, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory, type:0x00000001 datalen:70 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:678, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:678, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:678, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001\ProfileImagePath, type:0x00000002 datalen:22 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\Temp, type:0x00000002 datalen:36 data:'25 00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot, type:0x00000001 datalen:22 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory, type:0x00000001 datalen:70 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:679, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001\ProfileImagePath, type:0x00000002 datalen:22 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\Temp, type:0x00000002 datalen:36 data:'25 00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot, type:0x00000001 datalen:22 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory, type:0x00000001 datalen:70 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:680, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:681, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:681, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:681, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001\ProfileImagePath, type:0x00000002 datalen:22 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:683, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:683, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:683, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\Temp, type:0x00000002 datalen:36 data:'25 00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:683, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:684, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot, type:0x00000001 datalen:22 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:684, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:684, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:684, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:684, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory, type:0x00000001 datalen:70 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:684, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:684, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:684, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:684, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:684, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:684, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001\ProfileImagePath, type:0x00000002 datalen:22 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:684, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\Temp, type:0x00000002 datalen:36 data:'25 00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot, type:0x00000001 datalen:22 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory, type:0x00000001 datalen:70 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:685, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001\ProfileImagePath, type:0x00000002 datalen:22 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:686, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:686, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:686, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\Temp, type:0x00000002 datalen:36 data:'25 00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:686, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:686, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot, type:0x00000001 datalen:22 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:686, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:686, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:686, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:686, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory, type:0x00000001 datalen:70 data:'43 00 3A 00 5C 00 57 00 69 00 6E 00 64 00 6F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:686, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:686, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:686, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Environment, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:687, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\Environment\temp, type:0x00000002 datalen:66 data:'25 00 55 00 53 00 45 00 52 00 50 00 52 00 4F 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:687, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001, access:0x02020019 , 0x00000000 [操作成功完成。 ], 20:00:37:687, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3575969459-664706433-1206411049-1001\ProfileImagePath, type:0x00000002 datalen:22 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:689, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls, access:0x00000001 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:689, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls, access:0x00000001 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:37:689, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option, access:0x00000003 , 0x00000104 [因为文件名产生符号链接,所以需由对象管理器重新运行分析操作。 ], 20:00:37:689, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option, access:0x00000003 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:37:689, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, access:0x00000001 , 0x00000000 [操作成功完成。 ], 20:00:37:690, fmxlinux-trial.exe, 584:6588, 4212, REG_getval, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache, type:0x00000001 datalen:106 data:'43 00 3A 00 5C 00 55 00 73 00 65 00 72 00 73 00 ' , 0x00000000 [操作成功完成。 ], 20:00:37:690, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion, access:0x00000008 , 0x00000000 [操作成功完成。 ], 20:00:37:690, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers, access:0x00000001 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:37:690, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\AppPatch\sysmain.sdb, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:37:691, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\AppPatch\apppatch64\sysmain.sdb, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:37:691, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Windows\AppPatch\sysmain.sdb, access:0x00120089 alloc_size:0 attrib:0x00000080 share_access:0x00000001 disposition:0x00000001 options:0x00000060 , 0x00000000 [操作成功完成。 ], 20:00:37:692, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:37:692, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:37:692, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\fmxlinux-trial.tmp, access:0x00020019 , 0xC0000034 [系统找不到指定的文件。 ], 20:00:37:693, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:693, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:693, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:693, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:694, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:694, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:695, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:695, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:696, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:696, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:696, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:696, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:698, fmxlinux-trial.exe, 584:6588, 4212, REG_openkey, HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide, access:0x00020019 , 0x00000000 [操作成功完成。 ], 20:00:37:720, fmxlinux-trial.exe, 584:6588, 4212, THRD_resume, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, target_pid:6004 target_tid:1932 , 0x00000000 [操作成功完成。 ], 20:01:14:680, fmxlinux-trial.exe, 584:6588, 4212, FILE_open, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, access:0x00010080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200040 , 0x00000000 [操作成功完成。 ], 20:01:14:680, fmxlinux-trial.exe, 584:6588, 4212, FILE_remove, C:\Users\1\AppData\Local\Temp\is-08B90.tmp\fmxlinux-trial.tmp, , 0x00000000 [操作成功完成。 ], 20:01:14:689, fmxlinux-trial.exe, 584:0, 4212, EXEC_destroy, C:\Users\1\Desktop\fmxlinux-trial.exe, parent_pid:3904 cmdline:'"C:\Users\1\Desktop\fmxlinux-trial.exe" /SPAWNWND=$20DA0 /NOTIFYWND=$20C74 ' , 0x00000000 [操作成功完成。 ], 20:01:14:703, fmxlinux-trial.exe, 4212:6328, 4212, FILE_open, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, access:0x00010080 alloc_size:0 attrib:0x00000000 share_access:0x00000007 disposition:0x00000001 options:0x00200040 , 0x00000000 [操作成功完成。 ], 20:01:14:703, fmxlinux-trial.exe, 4212:6328, 4212, FILE_remove, C:\Users\1\AppData\Local\Temp\is-BSP8Q.tmp\fmxlinux-trial.tmp, , 0x00000000 [操作成功完成。 ], 20:01:14:709, fmxlinux-trial.exe, 4212:0, 4212, EXEC_destroy, C:\Users\1\Desktop\fmxlinux-trial.exe, parent_pid:3096 cmdline:'"C:\Users\1\Desktop\fmxlinux-trial.exe" ' , 0x00000000 [操作成功完成。 ], 安装信息。
----------------------------------------------
免费的FTPhttps://download-installer.cdn.mozilla.net/pub/firefox/releases/43.0/win64/zh-CN/https://cc.embarcadero.com/Author/575019>http://delphi-z.ruhttps://download-installer.cdn.mozilla.net/pub/firefox/releases/43.0/win64/zh-CN/https://cc.embarcadero.com/Author/575019>http://delphi.icm.edu.pl/ftp/https://download-installer.cdn.mozilla.net/pub/firefox/releases/43.0/win64/zh-CN/https://cc.embarcadero.com/Author/575019>http://delphi-z.ruhttps://download-installer.cdn.mozilla.net/pub/firefox/releases/43.0/win64/zh-CN/https://cc.embarcadero.com/Author/575019
|