序号-时间 进程名 进程ID 动作 路径 参数 结果 1-06:09:17.2857669 System 4 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3034489277-1165069589-1523088021-500 access:0x000F003F 0x00000000 [操作成功完成。 ] 2-06:09:17.2857669 System 4 REG_getval HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3034489277-1165069589-1523088021-500\\Device\HarddiskVolume3\Program Files\PowerShell\7\pwsh.exe type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 3-06:09:17.2857669 System 4 REG_setval HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3034489277-1165069589-1523088021-500\\Device\HarddiskVolume3\Program Files\PowerShell\7\pwsh.exe type:0x00000003 datalen:0x00000018 data:'00000010: 45 BF 46 3F 14 13 DD 01 00 00 00 00 00 00 00 00 ' 0x00000000 [操作成功完成。 ] 4-06:09:17.2857669 System 4 REG_setval HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3034489277-1165069589-1523088021-500\SequenceNumber type:0x00000004 datalen:0x00000004 data:'00000010: 53 00 00 00 ' 0x00000000 [操作成功完成。 ] 5-06:09:17.3807114 WindowsTerminal.exe 5332 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize access:0x00000001 0x00000000 [操作成功完成。 ] 6-06:09:17.3807114 WindowsTerminal.exe 5332 REG_getval HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 7-06:09:17.3807114 WindowsTerminal.exe 5332 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize access:0x00000001 0x00000000 [操作成功完成。 ] 8-06:09:17.3807114 WindowsTerminal.exe 5332 REG_getval HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 9-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache access:0x00020019 0x00000000 [操作成功完成。 ] 10-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Metadata access:0x00020019 0x00000000 [操作成功完成。 ] 11-06:09:17.4041541 sihost.exe 8272 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Metadata\Revision type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 12-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName access:0x00020019 0x00000000 [操作成功完成。 ] 13-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\MicrosoftWindows.Client.CBS_cw5n1h2txyewy access:0x00020019 0x00000000 [操作成功完成。 ] 14-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\User\Index\UserSid access:0x00020019 0x00000000 [操作成功完成。 ] 15-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\User\Index\UserSid\S-1-5-21-3034489277-1165069589-1523088021-500 access:0x00020019 0x00000000 [操作成功完成。 ] 16-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\User\Data access:0x00020019 0x00000000 [操作成功完成。 ] 17-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\User\Data\2 access:0x00020019 0x00000000 [操作成功完成。 ] 18-06:09:17.4041541 sihost.exe 8272 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\User\Data\2\UserSid type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 19-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFamily access:0x00020019 0x00000000 [操作成功完成。 ] 20-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFamily\22 access:0x00020019 0x00000000 [操作成功完成。 ] 21-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data access:0x00020019 0x00000000 [操作成功完成。 ] 22-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\1014 access:0x00020019 0x00000000 [操作成功完成。 ] 23-06:09:17.4041541 sihost.exe 8272 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\1014\PackageFullName type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 24-06:09:17.4041541 sihost.exe 8272 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\1014\PackageType type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 25-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage access:0x00020019 0x00000000 [操作成功完成。 ] 26-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\2^1014 access:0x00020019 0x00000000 [操作成功完成。 ] 27-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache access:0x00020019 0x00000000 [操作成功完成。 ] 28-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Metadata access:0x00020019 0x00000000 [操作成功完成。 ] 29-06:09:17.4041541 sihost.exe 8272 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Metadata\Revision type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 30-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName access:0x00020019 0x00000000 [操作成功完成。 ] 31-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\MicrosoftWindows.Client.CBS_cw5n1h2txyewy access:0x00020019 0x00000000 [操作成功完成。 ] 32-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\User\Index\UserSid access:0x00020019 0x00000000 [操作成功完成。 ] 33-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\User\Index\UserSid\S-1-5-21-3034489277-1165069589-1523088021-500 access:0x00020019 0x00000000 [操作成功完成。 ] 34-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\User\Data access:0x00020019 0x00000000 [操作成功完成。 ] 35-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\User\Data\2 access:0x00020019 0x00000000 [操作成功完成。 ] 36-06:09:17.4041541 sihost.exe 8272 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\User\Data\2\UserSid type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 37-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFamily access:0x00020019 0x00000000 [操作成功完成。 ] 38-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFamily\22 access:0x00020019 0x00000000 [操作成功完成。 ] 39-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data access:0x00020019 0x00000000 [操作成功完成。 ] 40-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\1014 access:0x00020019 0x00000000 [操作成功完成。 ] 41-06:09:17.4041541 sihost.exe 8272 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\1014\PackageFullName type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 42-06:09:17.4041541 sihost.exe 8272 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\1014\PackageType type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 43-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage access:0x00020019 0x00000000 [操作成功完成。 ] 44-06:09:17.4041541 sihost.exe 8272 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\2^1014 access:0x00020019 0x00000000 [操作成功完成。 ] 45-06:09:17.4122796 pwsh.exe 2848 FILE_write C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt offset:0x0000ECED datalen:0x0000005E 0x00000000 [操作成功完成。 ] 46-06:09:17.4122796 pwsh.exe 2848 FILE_modified C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt - 0x00000000 [操作成功完成。 ] 47-06:09:17.4122796 pwsh.exe 2848 FILE_readdir C:\Program Files\PowerShell\7 filter:* 0x00000000 [操作成功完成。 ] 48-06:09:17.4122796 pwsh.exe 2848 FILE_readdir C:\Program Files\Common Files\Oracle\Java\javapath_target_3739343 filter:* 0x00000000 [操作成功完成。 ] 49-06:09:17.4122796 pwsh.exe 2848 FILE_readdir C:\Program Files (x86)\Common Files\Oracle\Java\java8path_target_13350000 filter:* 0x00000000 [操作成功完成。 ] 50-06:09:17.4122796 pwsh.exe 2848 FILE_readdir C:\Windows\System32 filter:* 0x00000000 [操作成功完成。 ] 51-06:09:17.4122796 pwsh.exe 2848 FILE_open C:\Windows\System32\netsh.exe access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 52-06:09:17.4122796 pwsh.exe 2848 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Memory Management access:0x00000001 0x00000000 [操作成功完成。 ] 53-06:09:17.4122796 pwsh.exe 2848 FILE_open C:\Windows\System32\netsh.exe access:0x001000A1 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 54-06:09:17.4122796 pwsh.exe 2848 FILE_read C:\Program Files\PowerShell\7\pwsh.exe offset:0x00000000 datalen:0x00048138 0x00000000 [操作成功完成。 ] 55-06:09:17.4279996 pwsh.exe 2848 FILE_read C:\Windows\System32\netsh.exe offset:0x00000000 datalen:0x0001F000 0x00000000 [操作成功完成。 ] 56-06:09:17.4279996 pwsh.exe 2848 FILE_read C:\Windows\System32\netsh.exe offset:0x00000000 datalen:0x0001F000 0x00000000 [操作成功完成。 ] 57-06:09:17.4279996 pwsh.exe 2848 PROC_exec C:\Windows\System32\netsh.exe target_pid:1984 cmdline:"C:\Windows\system32\netsh.exe" interface ip set address name=以太网 static 192.168.1.2 255.255.255.0 192.168.1.1 0x00000000 [操作成功完成。 ] 58-06:09:17.4279996 pwsh.exe 2848 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3034489277-1165069589-1523088021-500 access:0x000F003F 0x00000000 [操作成功完成。 ] 59-06:09:17.4279996 pwsh.exe 2848 REG_getval HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3034489277-1165069589-1523088021-500\\Device\HarddiskVolume3\Windows\System32\netsh.exe type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 60-06:09:17.4279996 pwsh.exe 2848 REG_setval HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3034489277-1165069589-1523088021-500\\Device\HarddiskVolume3\Windows\System32\netsh.exe type:0x00000003 datalen:0x00000018 data:'00000010: 3C 73 5C 3F 14 13 DD 01 00 00 00 00 00 00 00 00 ' 0x00000000 [操作成功完成。 ] 61-06:09:17.4279996 pwsh.exe 2848 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders access:0x00000001 0x00000000 [操作成功完成。 ] 62-06:09:17.4279996 pwsh.exe 2848 REG_getval HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 63-06:09:17.4279996 pwsh.exe 2848 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers access:0x00000001 0x00000000 [操作成功完成。 ] 64-06:09:17.4279996 pwsh.exe 2848 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\SdbUpdates access:0x00020019 0x00000000 [操作成功完成。 ] 65-06:09:17.4279996 pwsh.exe 2848 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\SdbUpdates\ManifestedMergeStubSdbs access:0x00020019 0x00000000 [操作成功完成。 ] 66-06:09:17.4279996 pwsh.exe 2848 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\SdbUpdates\ManifestedMergeStubSdbs\C:\Windows\apppatch\MergeSdbFilesSource\sysMerge.sdb type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 67-06:09:17.4279996 pwsh.exe 2848 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\SdbUpdates access:0x00020019 0x00000000 [操作成功完成。 ] 69-06:09:17.4436929 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\dhcpclient type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 70-06:09:17.4436929 netsh.exe 1984 FILE_open C:\Windows\System32\dhcpcmonitor.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 71-06:09:17.4436929 netsh.exe 1984 EXEC_module_load C:\Windows\System32\dhcpcmonitor.dll base:0x00007FFABCA20000 size:0x0000B000 0x00000000 [操作成功完成。 ] 72-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\dhcpcsvc.dll access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 73-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\dot3cfg type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 74-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\dot3cfg.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 75-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\dot3cfg.dll base:0x00007FFAA7F60000 size:0x00017000 0x00000000 [操作成功完成。 ] 76-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\dot3api.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 77-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\eappcfg.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 78-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\onex.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 79-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\eappcfg.dll base:0x00007FFA9E6F0000 size:0x00051000 0x00000000 [操作成功完成。 ] 80-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\dot3api.dll base:0x00007FFAA0310000 size:0x00033000 0x00000000 [操作成功完成。 ] 81-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\mfc42.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 82-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\onex.dll base:0x00007FFAA0450000 size:0x0004B000 0x00000000 [操作成功完成。 ] 83-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\ncrypt.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 84-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\eappprxy.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 85-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\ncrypt.dll base:0x00007FFAC1C60000 size:0x00030000 0x00000000 [操作成功完成。 ] 86-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\eappprxy.dll base:0x00007FFA98DE0000 size:0x0001B000 0x00000000 [操作成功完成。 ] 87-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\mfc42.dll base:0x00007FFA8E3E0000 size:0x0015D000 0x00000000 [操作成功完成。 ] 88-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\mobilenetworking.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 89-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\ntasn1.dll base:0x00007FFAC1C10000 size:0x0003F000 0x00000000 [操作成功完成。 ] 90-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\mobilenetworking.dll base:0x00007FFAB9440000 size:0x00022000 0x00000000 [操作成功完成。 ] 91-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\ntasn1.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 92-06:09:17.4593740 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\LanguageOverlay\OverlayPackages\zh-CN access:0x00020019 0x00000000 [操作成功完成。 ] 93-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\LanguageOverlay\OverlayPackages\zh-CN\Type type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 94-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\LanguageOverlay\OverlayPackages\zh-CN\Latest type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 95-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackzh-CN_26100.161.258.0_neutral__8wekyb3d8bbwe\Windows\System32\zh-CN\a0954090cb9e3a6dba3e4178a3aeb73b\MFC42.dll.mui access:0x00100001 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 96-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\fwcfg type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 97-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\fwcfg.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 98-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\fwcfg.dll base:0x00007FFAA7F40000 size:0x00015000 0x00000000 [操作成功完成。 ] 99-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\hnetmon type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 100-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\hnetmon.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 101-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\hnetmon.dll base:0x00007FFAA68F0000 size:0x00017000 0x00000000 [操作成功完成。 ] 102-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\netshell.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 103-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\netshell.dll base:0x00007FFA989A0000 size:0x0009B000 0x00000000 [操作成功完成。 ] 104-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\shlwapi.dll base:0x00007FFAC4390000 size:0x00067000 0x00000000 [操作成功完成。 ] 105-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\windows.storage.dll base:0x00007FFAC24A0000 size:0x00864000 0x00000000 [操作成功完成。 ] 106-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\shell32.dll base:0x00007FFAC5160000 size:0x0075F000 0x00000000 [操作成功完成。 ] 107-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\WinTypes.dll base:0x00007FFAC2D10000 size:0x0016A000 0x00000000 [操作成功完成。 ] 108-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\NetSetupApi.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 109-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\NetSetupApi.dll base:0x00007FFAA0410000 size:0x00030000 0x00000000 [操作成功完成。 ] 110-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\netiohlp type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 111-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\netiohlp.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 112-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\netiohlp.dll base:0x00007FFA9FC50000 size:0x00046000 0x00000000 [操作成功完成。 ] 113-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\nsi.dll base:0x00007FFAC3A20000 size:0x0000A000 0x00000000 [操作成功完成。 ] 114-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\dhcpcsvc.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 115-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\winnsi.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 116-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\dhcpcsvc.dll base:0x00007FFAB9BB0000 size:0x00023000 0x00000000 [操作成功完成。 ] 117-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\winnsi.dll base:0x00007FFABDE20000 size:0x0000E000 0x00000000 [操作成功完成。 ] 118-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\netprofm type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 119-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\netprofm.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 120-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\netprofm.dll base:0x00007FFABC3C0000 size:0x0006F000 0x00000000 [操作成功完成。 ] 121-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\nettrace type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 122-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\nettrace.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 123-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\nettrace.dll base:0x00007FFA984F0000 size:0x00083000 0x00000000 [操作成功完成。 ] 124-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\tdh.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 125-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\nshhttp.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 126-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\tdh.dll base:0x00007FFAA6350000 size:0x00077000 0x00000000 [操作成功完成。 ] 127-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\nshhttp type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 128-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\nshhttp.dll base:0x00007FFA9D9B0000 size:0x0001E000 0x00000000 [操作成功完成。 ] 129-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\httpapi.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 130-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\httpapi.dll base:0x00007FFAA0C60000 size:0x00018000 0x00000000 [操作成功完成。 ] 131-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\nshipsec type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 132-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\nshipsec.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 133-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\winipsec.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 134-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\Wldap32.dll base:0x00007FFAC45C0000 size:0x00072000 0x00000000 [操作成功完成。 ] 135-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\userenv.dll base:0x00007FFAC1810000 size:0x00032000 0x00000000 [操作成功完成。 ] 136-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\polstore.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 137-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\nshipsec.dll base:0x00007FFA9BAD0000 size:0x00056000 0x00000000 [操作成功完成。 ] 138-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\userenv.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 139-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\activeds.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 140-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\dnsapi.dll base:0x00007FFAC0C90000 size:0x0012A000 0x00000000 [操作成功完成。 ] 141-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\activeds.dll base:0x00007FFA9B830000 size:0x0004A000 0x00000000 [操作成功完成。 ] 142-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\dnsapi.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 143-06:09:17.4593740 csrss.exe 1164 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PublisherPolicyChangeTime type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 144-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\adsldpc.dll base:0x00007FFA98950000 size:0x00045000 0x00000000 [操作成功完成。 ] 145-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\winipsec.dll base:0x00007FFA99000000 size:0x0001E000 0x00000000 [操作成功完成。 ] 146-06:09:17.4593740 netsh.exe 1984 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500 access:0x02000000 0x00000000 [操作成功完成。 ] 147-06:09:17.4593740 netsh.exe 1984 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Control Panel\Desktop access:0x00020019 0x00000000 [操作成功完成。 ] 148-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Control Panel\Desktop\PreferredUILanguages type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 149-06:09:17.4593740 netsh.exe 1984 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500 access:0x02000000 0x00000000 [操作成功完成。 ] 150-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\adsldpc.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 151-06:09:17.4593740 netsh.exe 1984 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Control Panel\Desktop\LanguageConfiguration access:0x00020019 0x00000000 [操作成功完成。 ] 152-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Control Panel\Desktop\LanguageConfiguration\zh-CN type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 153-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\polstore.dll base:0x00007FFA99EC0000 size:0x0004A000 0x00000000 [操作成功完成。 ] 154-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\adsldpc.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 155-06:09:17.4593740 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide access:0x00020019 0x00000000 [操作成功完成。 ] 156-06:09:17.4593740 netsh.exe 1984 FILE_open C:\Windows\System32\polstore.dll access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 157-06:09:17.4593740 netsh.exe 1984 EXEC_module_load C:\Windows\System32\adsldpc.dll base:0x000001311E5D0000 size:0x00045000 0x00000000 [操作成功完成。 ] 158-06:09:17.4593740 csrss.exe 1164 FILE_open C:\Windows\System32\polstore.dll access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 159-06:09:17.4593740 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ldap access:0x00020019 0x00000000 [操作成功完成。 ] 160-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ldap\LdapClientIntegrity type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 161-06:09:17.4593740 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ldap access:0x00020019 0x00000000 [操作成功完成。 ] 162-06:09:17.4593740 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ldap\LdapClientConfidentiality type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 163-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ldap access:0x00020019 0x00000000 [操作成功完成。 ] 164-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ldap access:0x00020019 0x00000000 [操作成功完成。 ] 165-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ldap access:0x00020019 0x00000000 [操作成功完成。 ] 166-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ldap access:0x00020019 0x00000000 [操作成功完成。 ] 167-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ldap access:0x00020019 0x00000000 [操作成功完成。 ] 168-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale access:0x00020019 0x00000000 [操作成功完成。 ] 169-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale access:0x00020019 0x00000000 [操作成功完成。 ] 170-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Versions\000605xx type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 171-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\Globalization\Sorting\SortDefault.nls access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000001 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 172-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Ids access:0x00020019 0x00000000 [操作成功完成。 ] 173-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces access:0x00020019 0x00000000 [操作成功完成。 ] 174-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces access:0x00020019 0x00000000 [操作成功完成。 ] 175-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local access:0x000F003F 0x00000000 [操作成功完成。 ] 176-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE access:0x02000000 0x00000000 [操作成功完成。 ] 177-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\nshwfp type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 178-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\nshwfp.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 179-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\nshwfp.dll base:0x00007FFA90B00000 size:0x000D5000 0x00000000 [操作成功完成。 ] 180-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\cabinet.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 181-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\cabinet.dll base:0x00007FFAA6320000 size:0x0002A000 0x00000000 [操作成功完成。 ] 182-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\rpc type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 183-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\rpcnsh.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 184-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\rpcnsh.dll base:0x00007FFA9FC30000 size:0x00018000 0x00000000 [操作成功完成。 ] 185-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\WcnNetsh type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 186-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\WcnNetsh.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 187-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\WcnNetsh.dll base:0x00007FFA9DBF0000 size:0x00012000 0x00000000 [操作成功完成。 ] 188-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\wlanapi.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 189-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\wlanapi.dll base:0x00007FFAB9B10000 size:0x0008E000 0x00000000 [操作成功完成。 ] 190-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\whhelper type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 191-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\whhelper.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 192-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\whhelper.dll base:0x00007FFA9BAB0000 size:0x0000F000 0x00000000 [操作成功完成。 ] 193-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\winhttp.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 194-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\winhttp.dll base:0x00007FFAB9920000 size:0x00127000 0x00000000 [操作成功完成。 ] 195-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\wlancfg type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 196-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\wlancfg.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 197-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\wlancfg.dll base:0x00007FFA98700000 size:0x00060000 0x00000000 [操作成功完成。 ] 198-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\SHCore.dll base:0x00007FFAC3AE0000 size:0x000F7000 0x00000000 [操作成功完成。 ] 199-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\wshelper type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 200-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\wshelper.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 201-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\wshelper.dll base:0x00007FFABCA10000 size:0x0000B000 0x00000000 [操作成功完成。 ] 202-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\wevtapi.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 203-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\mswsock.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 204-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\mswsock.dll base:0x00007FFAC1760000 size:0x0006B000 0x00000000 [操作成功完成。 ] 205-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\wevtapi.dll base:0x00007FFABCB80000 size:0x0004C000 0x00000000 [操作成功完成。 ] 206-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\wwancfg type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 207-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\wwancfg.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 208-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\wwancfg.dll base:0x00007FFA98670000 size:0x0003B000 0x00000000 [操作成功完成。 ] 209-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\wwapi.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 210-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\WwanPrfl.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 211-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\luiapi.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 212-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\wwapi.dll base:0x00007FFA9D7F0000 size:0x00031000 0x00000000 [操作成功完成。 ] 213-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\luiapi.dll base:0x00007FFA984D0000 size:0x0001A000 0x00000000 [操作成功完成。 ] 214-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\WwanPrfl.dll base:0x00007FFA98930000 size:0x0001A000 0x00000000 [操作成功完成。 ] 215-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\profapi.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 216-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\profapi.dll base:0x00007FFAC2380000 size:0x00029000 0x00000000 [操作成功完成。 ] 217-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh\peerdistsh type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 218-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\PeerDistSh.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 219-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\PeerDistSh.dll base:0x00007FFA944F0000 size:0x00073000 0x00000000 [操作成功完成。 ] 220-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\rpcss.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 221-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\bcryptprimitives.dll base:0x00007FFAC2E80000 size:0x000A5000 0x00000000 [操作成功完成。 ] 222-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE access:0x02000000 0x00000000 [操作成功完成。 ] 223-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa access:0x00000001 0x00000000 [操作成功完成。 ] 224-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\LsaPid type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 225-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\uxtheme.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 226-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\uxtheme.dll base:0x00007FFABFFA0000 size:0x000AA000 0x00000000 [操作成功完成。 ] 227-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500 access:0x00020019 0x00000000 [操作成功完成。 ] 228-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize access:0x00000001 0x00000000 [操作成功完成。 ] 229-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 230-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\LanguageOverlay\OverlayPackages\zh-CN access:0x00020019 0x00000000 [操作成功完成。 ] 231-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\LanguageOverlay\OverlayPackages\zh-CN\Type type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 232-06:09:17.4754045 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\LanguageOverlay\OverlayPackages\zh-CN\Latest type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 233-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackzh-CN_26100.161.258.0_neutral__8wekyb3d8bbwe\Windows\System32\zh-CN\4202f8c2a4b0bae373b3f400646c5444\fwcfg.dll.mui access:0x00100001 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 234-06:09:17.4754045 netsh.exe 1984 FILE_open C:\Windows\System32\wcmapi.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 235-06:09:17.4754045 netsh.exe 1984 EXEC_module_load C:\Windows\System32\wcmapi.dll base:0x00007FFAB0210000 size:0x00030000 0x00000000 [操作成功完成。 ] 236-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist access:0x00020019 0x00000000 [操作成功完成。 ] 237-06:09:17.4754045 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist access:0x00020019 0x00000000 [操作成功完成。 ] 238-06:09:17.4911481 netsh.exe 1984 FILE_open C:\Windows\System32\slc.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 239-06:09:17.4911481 netsh.exe 1984 EXEC_module_load C:\Windows\System32\slc.dll base:0x00007FFAC09A0000 size:0x0002D000 0x00000000 [操作成功完成。 ] 240-06:09:17.4911481 netsh.exe 1984 FILE_open C:\Windows\System32\sppc.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 241-06:09:17.4911481 netsh.exe 1984 EXEC_module_load C:\Windows\System32\sppc.dll base:0x00007FFAB02C0000 size:0x00025000 0x00000000 [操作成功完成。 ] 242-06:09:17.4911481 netsh.exe 1984 FILE_open C:\Windows\System32\gpapi.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 243-06:09:17.4911481 netsh.exe 1984 EXEC_module_load C:\Windows\System32\gpapi.dll base:0x00007FFAC17D0000 size:0x00030000 0x00000000 [操作成功完成。 ] 244-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon access:0x00020019 0x00000000 [操作成功完成。 ] 245-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System access:0x00020019 0x00000000 [操作成功完成。 ] 246-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SYSTEM\Setup access:0x00020019 0x00000000 [操作成功完成。 ] 247-06:09:17.4911481 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 248-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist access:0x00020019 0x00000000 [操作成功完成。 ] 249-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service access:0x00000001 0x00000000 [操作成功完成。 ] 250-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service access:0x00000001 0x00000000 [操作成功完成。 ] 251-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service access:0x00000001 0x00000000 [操作成功完成。 ] 252-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service access:0x00000001 0x00000000 [操作成功完成。 ] 253-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service access:0x00000001 0x00000000 [操作成功完成。 ] 254-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service access:0x00000001 0x00000000 [操作成功完成。 ] 255-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service access:0x00000001 0x00000000 [操作成功完成。 ] 256-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service access:0x00000001 0x00000000 [操作成功完成。 ] 257-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service access:0x00000001 0x00000000 [操作成功完成。 ] 258-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service access:0x00000001 0x00000000 [操作成功完成。 ] 259-06:09:17.4911481 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\HTTPExtension type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 260-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Extension access:0x00000001 0x00000000 [操作成功完成。 ] 261-06:09:17.4911481 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Extension\PeerdistDllName type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 262-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager access:0x00000001 0x00000000 [操作成功完成。 ] 263-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager access:0x00000001 0x00000000 [操作成功完成。 ] 264-06:09:17.4911481 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\TransportDllPath type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 265-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager access:0x00000001 0x00000000 [操作成功完成。 ] 266-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager access:0x00000001 0x00000000 [操作成功完成。 ] 267-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager access:0x00000001 0x00000000 [操作成功完成。 ] 268-06:09:17.4911481 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager access:0x00000001 0x00000000 [操作成功完成。 ] 269-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager access:0x00000001 0x00000000 [操作成功完成。 ] 270-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\Restricted access:0x00000001 0x00000000 [操作成功完成。 ] 271-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr access:0x00000001 0x00000000 [操作成功完成。 ] 272-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr access:0x00000001 0x00000000 [操作成功完成。 ] 273-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr access:0x00000001 0x00000000 [操作成功完成。 ] 274-06:09:17.4944208 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\CacheRescalingFactor type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 275-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr access:0x00000001 0x00000000 [操作成功完成。 ] 276-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr access:0x00000001 0x00000000 [操作成功完成。 ] 277-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr access:0x00000001 0x00000000 [操作成功完成。 ] 278-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr access:0x00000001 0x00000000 [操作成功完成。 ] 279-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr access:0x00000001 0x00000000 [操作成功完成。 ] 280-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 281-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 282-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 283-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 284-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 285-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 286-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 287-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 288-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 289-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 290-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 291-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 292-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 293-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 294-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 295-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 296-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 297-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 298-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 299-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 300-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 301-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 302-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary0 access:0x00000001 0x00000000 [操作成功完成。 ] 303-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary0 access:0x00000001 0x00000000 [操作成功完成。 ] 304-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary0 access:0x00000001 0x00000000 [操作成功完成。 ] 305-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary0 access:0x00000001 0x00000000 [操作成功完成。 ] 306-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary1 access:0x00000001 0x00000000 [操作成功完成。 ] 307-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary1 access:0x00000001 0x00000000 [操作成功完成。 ] 308-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary1 access:0x00000001 0x00000000 [操作成功完成。 ] 309-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary1 access:0x00000001 0x00000000 [操作成功完成。 ] 310-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary2 access:0x00000001 0x00000000 [操作成功完成。 ] 311-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary2 access:0x00000001 0x00000000 [操作成功完成。 ] 312-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary2 access:0x00000001 0x00000000 [操作成功完成。 ] 313-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary2 access:0x00000001 0x00000000 [操作成功完成。 ] 314-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary3 access:0x00000001 0x00000000 [操作成功完成。 ] 315-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary3 access:0x00000001 0x00000000 [操作成功完成。 ] 316-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary3 access:0x00000001 0x00000000 [操作成功完成。 ] 317-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication\Secondary3 access:0x00000001 0x00000000 [操作成功完成。 ] 318-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 319-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication access:0x00000001 0x00000000 [操作成功完成。 ] 320-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 321-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 322-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 323-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 324-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 325-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 326-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 327-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 328-06:09:17.4944208 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 329-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 330-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 331-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 332-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 333-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 334-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication access:0x00000001 0x00000000 [操作成功完成。 ] 335-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache access:0x00000001 0x00000000 [操作成功完成。 ] 336-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache access:0x00000001 0x00000000 [操作成功完成。 ] 337-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache access:0x00000001 0x00000000 [操作成功完成。 ] 338-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\TransportDllPath type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 339-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache access:0x00000001 0x00000000 [操作成功完成。 ] 340-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache access:0x00000001 0x00000000 [操作成功完成。 ] 341-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache access:0x00000001 0x00000000 [操作成功完成。 ] 342-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache access:0x00000001 0x00000000 [操作成功完成。 ] 343-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache access:0x00000001 0x00000000 [操作成功完成。 ] 344-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache access:0x00000001 0x00000000 [操作成功完成。 ] 345-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache access:0x00000001 0x00000000 [操作成功完成。 ] 346-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache access:0x00000001 0x00000000 [操作成功完成。 ] 347-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery access:0x00000001 0x00000000 [操作成功完成。 ] 348-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery\ProviderDLLPath type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 349-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery access:0x00000001 0x00000000 [操作成功完成。 ] 350-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery access:0x00000001 0x00000000 [操作成功完成。 ] 351-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery access:0x00000001 0x00000000 [操作成功完成。 ] 352-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery access:0x00000001 0x00000000 [操作成功完成。 ] 353-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery access:0x00000001 0x00000000 [操作成功完成。 ] 354-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery access:0x00000001 0x00000000 [操作成功完成。 ] 355-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery access:0x00000001 0x00000000 [操作成功完成。 ] 356-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery access:0x00000001 0x00000000 [操作成功完成。 ] 357-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery\Current access:0x00000001 0x00000000 [操作成功完成。 ] 358-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery\Current access:0x00000001 0x00000000 [操作成功完成。 ] 359-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery\Current access:0x00000001 0x00000000 [操作成功完成。 ] 360-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Discovery\Current access:0x00000001 0x00000000 [操作成功完成。 ] 361-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager access:0x00000001 0x00000000 [操作成功完成。 ] 362-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager access:0x00000001 0x00000000 [操作成功完成。 ] 363-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager access:0x00000001 0x00000000 [操作成功完成。 ] 364-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\DiscoveryProviderDllPath type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 365-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming access:0x00000001 0x00000000 [操作成功完成。 ] 366-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming access:0x00000001 0x00000000 [操作成功完成。 ] 367-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshDllName type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 368-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming access:0x00000001 0x00000000 [操作成功完成。 ] 369-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshProcName type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 370-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 371-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 372-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 373-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 374-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 375-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 376-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 377-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 378-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 379-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 380-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 381-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 382-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PerfCounters access:0x00000001 0x00000000 [操作成功完成。 ] 383-06:09:17.4964223 netsh.exe 1984 FILE_open C:\Windows\System32\ktmw32.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 384-06:09:17.4964223 netsh.exe 1984 EXEC_module_load C:\Windows\System32\ktmw32.dll base:0x00007FFAA3D20000 size:0x0000B000 0x00000000 [操作成功完成。 ] 385-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist access:0x00020019 0x00000000 [操作成功完成。 ] 386-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist access:0x00020019 0x00000000 [操作成功完成。 ] 387-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist access:0x00020019 0x00000000 [操作成功完成。 ] 388-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist access:0x00020019 0x00000000 [操作成功完成。 ] 389-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MultipleServers access:0x00000001 0x00000000 [操作成功完成。 ] 390-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_USERS access:0x02000000 0x00000000 [操作成功完成。 ] 391-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders access:0x000F003F 0x00000000 [操作成功完成。 ] 392-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 393-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3034489277-1165069589-1523088021-500 access:0x00020019 0x00000000 [操作成功完成。 ] 394-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3034489277-1165069589-1523088021-500\ProfileImagePath type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 395-06:09:17.4964223 netsh.exe 1984 FILE_readdir C:\Users\Administrator\AppData\Local\PeerDistRepub filter:* 0x00000000 [操作成功完成。 ] 396-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Ids\zh type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 397-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Cryptography\Providers access:0x00020019 0x00000000 [操作成功完成。 ] 398-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Cryptography\Configuration access:0x00020019 0x00000000 [操作成功完成。 ] 399-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Cryptography\Providers access:0x00020019 0x00000000 [操作成功完成。 ] 400-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Cryptography\Configuration access:0x00020019 0x00000000 [操作成功完成。 ] 401-06:09:17.4964223 netsh.exe 1984 FILE_open C:\Windows\System32\mprmsg.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 402-06:09:17.4964223 netsh.exe 1984 EXEC_module_load C:\Windows\System32\mprmsg.dll base:0x00007FFA98440000 size:0x00023000 0x00000000 [操作成功完成。 ] 403-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing access:0x00000003 0x00000000 [操作成功完成。 ] 404-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\EnableConsoleTracing type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 405-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI access:0x00020019 0x00000000 [操作成功完成。 ] 406-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\EnableFileTracing type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 407-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\FileTracingMask type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 408-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\EnableConsoleTracing type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 409-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\ConsoleTracingMask type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 410-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\MaxFileSize type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 411-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\FileDirectory type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 412-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\EnableFileTracing type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 413-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\FileTracingMask type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 414-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\EnableConsoleTracing type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 415-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\ConsoleTracingMask type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 416-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\MaxFileSize type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 417-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\FileDirectory type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 418-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MPRAPI\FileDirectory type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 419-06:09:17.4964223 netsh.exe 1984 FILE_open C:\Windows\System32\nettracehelper.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 420-06:09:17.4964223 netsh.exe 1984 EXEC_module_load C:\Windows\System32\nettracehelper.dll base:0x00007FFA92F90000 size:0x00023000 0x00000000 [操作成功完成。 ] 421-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500 access:0x02000000 0x00000000 [操作成功完成。 ] 422-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Control Panel\Desktop access:0x00020019 0x00000000 [操作成功完成。 ] 423-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Control Panel\Desktop\PreferredUILanguages type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 424-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500 access:0x02000000 0x00000000 [操作成功完成。 ] 425-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Control Panel\Desktop\LanguageConfiguration access:0x00020019 0x00000000 [操作成功完成。 ] 426-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Control Panel\Desktop\LanguageConfiguration\zh-CN type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 427-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\LanguageOverlay\OverlayPackages\zh-CN access:0x00020019 0x00000000 [操作成功完成。 ] 428-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\LanguageOverlay\OverlayPackages\zh-CN\Type type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 429-06:09:17.4964223 netsh.exe 1984 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\LanguageOverlay\OverlayPackages\zh-CN\Latest type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 430-06:09:17.4964223 netsh.exe 1984 FILE_open C:\Windows\System32\zh-CN\KernelBase.dll.mui access:0x00100001 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 431-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon access:0x00020019 0x00000000 [操作成功完成。 ] 432-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System access:0x00020019 0x00000000 [操作成功完成。 ] 433-06:09:17.4964223 netsh.exe 1984 REG_openkey HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RasMan\Parameters access:0x00020019 0x00000000 [操作成功完成。 ] 434-06:09:17.5072732 netsh.exe 1984 REG_setval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Notifications\Data\418A073AA3BC1C75 type:0x00000003 datalen:0x00000470 data:'00000010: 65 FD 02 00 00 00 00 00 04 00 04 00 01 00 C7 00 ' 0x00000000 [操作成功完成。 ] 435-06:09:17.5072732 netsh.exe 1984 FILE_open C:\Windows\System32\msasn1.dll access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 436-06:09:17.5072732 netsh.exe 1984 EXEC_module_load C:\Windows\System32\msasn1.dll base:0x00007FFAC1B70000 size:0x00013000 0x00000000 [操作成功完成。 ] 437-06:09:17.5072732 netsh.exe 1984 EXEC_destroy C:\Windows\System32\netsh.exe parent_pid:2848 cmdline:"C:\Windows\system32\netsh.exe" interface ip set address name=以太网 static 192.168.1.2 255.255.255.0 192.168.1.1 0x00000000 [操作成功完成。 ] 438-06:09:18.0163221 svchost.exe 4248 REG_openkey HKEY_LOCAL_MACHINE access:0x02000000 0x00000000 [操作成功完成。 ] 439-06:09:18.0163221 svchost.exe 4248 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags access:0x00000001 0x00000000 [操作成功完成。 ] 440-06:09:18.0163221 svchost.exe 4248 REG_openkey HKEY_LOCAL_MACHINE access:0x02000000 0x00000000 [操作成功完成。 ] 441-06:09:18.0163221 svchost.exe 4248 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags access:0x00000001 0x00000000 [操作成功完成。 ] 442-06:09:18.0174512 svchost.exe 4248 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\AmiHivePermissionsCorrect type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 443-06:09:18.0174512 svchost.exe 4248 REG_openkey HKEY_LOCAL_MACHINE access:0x02000000 0x00000000 [操作成功完成。 ] 444-06:09:18.0174512 svchost.exe 4248 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags access:0x00000001 0x00000000 [操作成功完成。 ] 445-06:09:18.0174512 svchost.exe 4248 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\AmiHiveOwnerCorrect type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 446-06:09:18.0174512 svchost.exe 4248 FILE_open C:\Windows\appcompat\Programs\Amcache.hve access:0x00020003 alloc_size:0 attrib:0x00000000 share_access:0x00000000 disposition:0x00000003 options:0x00008024 0x00000000 [操作成功完成。 ] 447-06:09:18.5098118 svchost.exe 2932 REG_openkey HKEY_LOCAL_MACHINE access:0x02000000 0x00000000 [操作成功完成。 ] 448-06:09:18.5098118 svchost.exe 2932 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers access:0x00020019 0x00000000 [操作成功完成。 ] 449-06:09:18.5098118 svchost.exe 2932 REG_openkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{a148cf02-be6d-5f08-94e3-b68de60d8422} access:0x00020019 0x00000000 [操作成功完成。 ] 450-06:09:18.5098118 svchost.exe 2932 REG_getval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{a148cf02-be6d-5f08-94e3-b68de60d8422}\ type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 451-06:09:18.5101373 svchost.exe 2932 FILE_open C:\Windows\System32\nettracehelper.dll access:0x001200A9 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 0x00000000 [操作成功完成。 ] 452-06:09:18.5458652 WindowsTerminal.exe 5332 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize access:0x00000001 0x00000000 [操作成功完成。 ] 453-06:09:18.5458652 WindowsTerminal.exe 5332 REG_getval HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ] 454-06:09:18.5458652 WindowsTerminal.exe 5332 REG_openkey HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize access:0x00000001 0x00000000 [操作成功完成。 ] 455-06:09:18.5458652 WindowsTerminal.exe 5332 REG_getval HKEY_USERS\S-1-5-21-3034489277-1165069589-1523088021-500\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme type:0x00000000 datalen:0x00000000 data: 0x00000000 [操作成功完成。 ]