序号,时间,进程(PID),IO类型,COM口,数据长度,数据,
689,16:57:27.882,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 22 03 00 00 00 00 00 00 00 B2 0D | :\#4\#1$"\#3\#0\#0\#0\#0\#0\#0\#0瞈#13,
690,16:57:27.976,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 22 03 00 00 00 00 00 00 00 B2 0D | :\#4\#1$"\#3\#0\#0\#0\#0\#0\#0\#0瞈#13,
691,16:57:28.085,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 1C 00 00 00 00 00 00 00 B8 0D | :\#4\#1$\#3\#0\#0\#0\#0\#0\#0\#0竆#13,
692,16:57:28.334,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 1C 00 00 00 00 00 00 00 B8 0D | :\#4\#1$\#3\#0\#0\#0\#0\#0\#0\#0竆#13,
693,16:57:28.397,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 1C 01 00 00 00 03 00 00 B4 0D | :\#4\#1$\#3\#1\#0\#0\#0\#3\#0\#0碶#13,
694,16:57:28.600,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 15 00 00 00 00 00 00 00 BF 0D | :\#4\#1$\#3\#0\#0\#0\#0\#0\#0\#0縗#13,
695,16:57:28.646,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 15 00 00 00 01 00 00 00 BE 0D | :\#4\#1$\#3\#0\#0\#0\#1\#0\#0\#0綷#13,
696,16:57:28.802,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 0B 00 00 00 00 00 00 00 C9 0D | :\#4\#1$\#3\#11\#0\#0\#0\#0\#0\#0\#0蒤#13,
697,16:57:28.880,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 0B 00 00 00 00 00 00 00 C9 0D | :\#4\#1$\#3\#11\#0\#0\#0\#0\#0\#0\#0蒤#13,
698,16:57:29.005,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 0C 00 00 00 00 00 00 00 C8 0D | :\#4\#1$\#3\#12\#0\#0\#0\#0\#0\#0\#0萛#13,
699,16:57:29.068,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 0C 00 00 00 50 00 00 00 78 0D | :\#4\#1$\#3\#12\#0\#0\#0P\#0\#0\#0x\#13,
700,16:57:29.208,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 0D 00 00 00 00 00 00 00 C7 0D | :\#4\#1$\#3\#13\#0\#0\#0\#0\#0\#0\#0荺#13,
701,16:57:29.255,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 0D 00 00 00 1E 00 00 00 A9 0D | :\#4\#1$\#3\#13\#0\#0\#0\#0\#0\#0‐#13,
702,16:57:29.411,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 0E 00 00 00 00 00 00 00 C6 0D | :\#4\#1$\#3\#14\#0\#0\#0\#0\#0\#0\#0芢#13,
703,16:57:29.442,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 0E 00 00 00 50 00 00 00 76 0D | :\#4\#1$\#3\#14\#0\#0\#0P\#0\#0\#0v\#13,
704,16:57:29.614,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 12 00 00 00 00 00 00 00 C2 0D | :\#4\#1$\#3\#18\#0\#0\#0\#0\#0\#0\#0耚#13,
705,16:57:29.676,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 12 00 00 00 1E 00 00 00 A4 0D | :\#4\#1$\#3\#18\#0\#0\#0\#0\#0\#0#13,
706,16:57:29.816,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 0F 00 00 00 00 00 00 00 C5 0D | :\#4\#1$\#3\#15\#0\#0\#0\#0\#0\#0\#0臷#13,
707,16:57:29.863,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 0F 00 00 00 0A 00 00 00 BB 0D | :\#4\#1$\#3\#15\#0\#0\#0\#10\#0\#0\#0籠#13,
708,16:57:30.019,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 16 01 00 00 00 00 00 00 BD 0D | :\#4\#1$\#3\#1\#0\#0\#0\#0\#0\#0絓#13,
709,16:57:30.050,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 16 01 00 00 14 00 00 00 A9 0D | :\#4\#1$\#3\#1\#0\#0\#0\#0\#0‐#13,
710,16:57:30.222,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 17 01 00 00 00 00 00 00 BC 0D | :\#4\#1$\#3\#1\#0\#0\#0\#0\#0\#0糪#13,
711,16:57:30.284,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 17 01 FF FF EC 00 00 00 D2 0D | :\#4\#1$\#3\#1靄#0\#0\#0襖#13,
712,16:57:30.425,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 1D 01 00 00 00 00 00 00 B6 0D | :\#4\#1$\#3\#1\#0\#0\#0\#0\#0\#0禱#13,
713,16:57:30.472,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 1D 01 00 01 7C 00 00 00 39 0D | :\#4\#1$\#3\#1\#0\#1|\#0\#0\#09\#13,
714,16:57:30.628,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 18 03 00 00 00 00 00 00 B9 0D | :\#4\#1$\#3\#3\#0\#0\#0\#0\#0\#0筡#13,
715,16:57:30.659,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 18 03 00 00 AA 00 00 00 0F 0D | :\#4\#1$\#3\#3\#0\#0猏#0\#0\#0\#15\#13,
716,16:57:30.830,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 19 03 00 00 00 00 00 00 B8 0D | :\#4\#1$\#3\#3\#0\#0\#0\#0\#0\#0竆#13,
717,16:57:30.893,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 19 03 00 00 96 00 00 00 22 0D | :\#4\#1$\#3\#3\#0\#0?\#0\#0\#0"\#13,
718,16:57:31.033,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 1A 00 00 00 00 00 00 00 BA 0D | :\#4\#1$\#3\#0\#0\#0\#0\#0\#0\#0篭#13,
719,16:57:31.080,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 1A 00 00 00 00 00 00 00 BA 0D | :\#4\#1$\#3\#0\#0\#0\#0\#0\#0\#0篭#13,
720,16:57:31.236,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 03 1B 00 00 00 00 00 00 00 B9 0D | :\#4\#1$\#3\#0\#0\#0\#0\#0\#0\#0筡#13,
721,16:57:31.267,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 03 1B 01 00 00 00 00 00 00 B8 0D | :\#4\#1$\#3\#1\#0\#0\#0\#0\#0\#0竆#13,
722,16:57:32.656,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 22 04 00 00 00 00 00 00 00 B1 0D | :\#4\#1$"\#4\#0\#0\#0\#0\#0\#0\#0盶#13,
723,16:57:32.749,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 22 04 00 00 00 00 00 00 00 B1 0D | :\#4\#1$"\#4\#0\#0\#0\#0\#0\#0\#0盶#13,
724,16:57:45.650,(+=+??_-Ζ?.exe(2348),IRP_MJ_WRITE,COM4,15,
3A 04 01 24 22 01 00 00 00 00 00 00 00 B4 0D | :\#4\#1$"\#1\#0\#0\#0\#0\#0\#0\#0碶#13,
725,16:57:45.682,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 22 01 00 00 00 00 00 00 00 B4 0D | :\#4\#1$"\#1\#0\#0\#0\#0\#0\#0\#0碶#13,
726,16:57:45.994,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 30 0C 00 00 00 50 03 00 9F A9 0D | :\#4\#1$0\#12\#0\#0\#0P\#3\#0?‐#13,
727,16:57:53.762,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 30 0D 00 00 00 1E 03 00 9F DA 0D | :\#4\#1$0\#13\#0\#0\#0\#3\#0?赲#13,
728,16:57:56.851,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 30 0E 00 00 00 50 03 00 9F A7 0D | :\#4\#1$0\#14\#0\#0\#0P\#3\#0?#13,
729,16:57:56.976,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 33 0E 01 00 00 04 03 00 9F EF 0D | :\#4\#1$3\#14\#1\#0\#0\#4\#3\#0?颸#13,
730,16:57:57.148,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 33 0E 01 00 00 08 03 00 9F EB 0D | :\#4\#1$3\#14\#1\#0\#0\#8\#3\#0?隲#13,
731,16:57:57.351,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 33 0E 01 00 00 0D 03 00 9F E6 0D | :\#4\#1$3\#14\#1\#0\#0\#13\#3\#0?鎈#13,
732,16:57:57.553,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 33 0E 01 00 00 12 03 00 9F E1 0D | :\#4\#1$3\#14\#1\#0\#0\#18\#3\#0?醆#13,
733,16:57:57.756,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 33 0E 01 00 00 16 03 00 9F DD 0D | :\#4\#1$3\#14\#1\#0\#0\#3\#0?輁#13,
734,16:57:58.146,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 30 11 01 00 00 16 03 00 9F DD 0D | :\#4\#1$0\#17\#1\#0\#0\#3\#0?輁#13,
735,16:57:58.271,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 30 0F 00 00 00 0A 03 00 9F EC 0D | :\#4\#1$0\#15\#0\#0\#0\#10\#3\#0?靄#13,
736,16:57:59.098,(+=+??_-Ζ?.exe(2348),IRP_MJ_READ,COM4,15,
3A 04 01 24 22 02 00 00 00 00 00 00 00 B3 0D | :\#4\#1$"\#2\#0\#0\#0\#0\#0\#0\#0砛#13,