09:56:06:025,Morfar.exe,4560:0,4560,EXEC_create,C:\Users\Administrator\AppData\Roaming\iNotePad\pkg\Morfar.exe,parent_pid:9208 cmdline:'C:\Users\Administrator\AppData\Roaming\iNotePad\pkg\Morfar.exe' image_base:0x00000000008E0000 image_size:0x00038000 ,0x00000000 [操作成功完成。 ],
09:56:06:025,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager,access:0x00000001 ,0x00000000 [操作成功完成。 ],
09:56:06:026,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager,access:0x00000009 ,0x00000000 [操作成功完成。 ],
09:56:06:028,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wow64\x86,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:028,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wow64\x86\,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:028,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager,access:0x00000001 ,0x00000000 [操作成功完成。 ],
09:56:06:029,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager,access:0x00000009 ,0x00000000 [操作成功完成。 ],
09:56:06:033,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:033,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem\LongPathsEnabled,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:034,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager,access:0x00000009 ,0x00000000 [操作成功完成。 ],
09:56:06:035,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager,access:0x00000001 ,0x00000000 [操作成功完成。 ],
09:56:06:035,Morfar.exe,4560:0,4560,FILE_open,C:\Users\Administrator\AppData\Roaming\iNotePad\pkg\iUtils.dll,access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 ,0x00000000 [操作成功完成。 ],
09:56:06:035,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CI,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:035,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CI,access:0x00000001 ,0x00000000 [操作成功完成。 ],
09:56:06:035,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale,access:0x00000001 ,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\Type,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\DefaultFallback,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\en-US,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\DefaultFallback,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\en-US,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\LCID,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\Type,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500,access:0x02000000 ,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500,access:0x02000000 ,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500,access:0x02000000 ,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500\Control Panel\Desktop,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500,access:0x02000000 ,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500\Control Panel\Desktop\MuiCached,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_getval,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:038,Morfar.exe,4560:0,4560,FILE_open,C:\Users\Administrator\AppData\Roaming\iNotePad\pkg\iUtils.dll,access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 ,0x00000000 [操作成功完成。 ],
09:56:06:048,Morfar.exe,4560:0,4560,FILE_open,C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.928_none_429ce31a8a8fefd2\GdiPlus.dll,access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 ,0x00000000 [操作成功完成。 ],
09:56:06:048,Morfar.exe,4560:0,4560,FILE_open,C:\Windows\SysWOW64\urlmon.dll,access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 ,0x00000000 [操作成功完成。 ],
09:56:06:025,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager,access:0x00000001 ,0x00000000 [操作成功完成。 ],
09:56:06:026,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager,access:0x00000009 ,0x00000000 [操作成功完成。 ],
09:56:06:028,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wow64\x86,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:028,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wow64\x86\,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:028,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager,access:0x00000001 ,0x00000000 [操作成功完成。 ],
09:56:06:029,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager,access:0x00000009 ,0x00000000 [操作成功完成。 ],
09:56:06:033,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:033,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem\LongPathsEnabled,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:034,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager,access:0x00000009 ,0x00000000 [操作成功完成。 ],
09:56:06:035,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager,access:0x00000001 ,0x00000000 [操作成功完成。 ],
09:56:06:035,Morfar.exe,4560:0,4560,FILE_open,C:\Users\Administrator\AppData\Roaming\iNotePad\pkg\iUtils.dll,access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 ,0x00000000 [操作成功完成。 ],
09:56:06:035,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CI,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:035,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CI,access:0x00000001 ,0x00000000 [操作成功完成。 ],
09:56:06:035,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale,access:0x00000001 ,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\Type,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\DefaultFallback,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\en-US,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\DefaultFallback,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\en-US,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\LCID,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_getval,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\UILanguages\zh-CN\Type,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500,access:0x02000000 ,0x00000000 [操作成功完成。 ],
09:56:06:036,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500,access:0x02000000 ,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500,access:0x02000000 ,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500\Control Panel\Desktop,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500,access:0x02000000 ,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500\Control Panel\Desktop\MuiCached,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_getval,HKEY_USERS\S-1-5-21-3300882840-3968337680-1944493803-500\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages,type:0x00000000 datalen:0 data:,0x00000000 [操作成功完成。 ],
09:56:06:037,Morfar.exe,4560:3616,4560,REG_openkey,HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide,access:0x00020019 ,0x00000000 [操作成功完成。 ],
09:56:06:038,Morfar.exe,4560:0,4560,FILE_open,C:\Users\Administrator\AppData\Roaming\iNotePad\pkg\iUtils.dll,access:0x00120089 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 ,0x00000000 [操作成功完成。 ],
09:56:06:048,Morfar.exe,4560:0,4560,FILE_open,C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.928_none_429ce31a8a8fefd2\GdiPlus.dll,access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 ,0x00000000 [操作成功完成。 ],
09:56:06:048,Morfar.exe,4560:0,4560,FILE_open,C:\Windows\SysWOW64\urlmon.dll,access:0x00100021 alloc_size:0 attrib:0x00000000 share_access:0x00000005 disposition:0x00000001 options:0x00000060 ,0x00000000 [操作成功完成。 ],