这对DW来说只是小菜一碟,能静默地完美地拦截。贴出日志如下:
DefenseWall log file
01.06.2012 23:04:54, 模块 C:\Documents and Settings\All Users\Application Data\gocBcScmNJwBeCF.exe, Attempt to set value 5761b2dc-ce77-4bfa-b965-6f33b1867cf2 within the key HKCU\Control Panel\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to create new key HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to create new key HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value DisableTaskMgr within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to create new key HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to create new key HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to create new key HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to create new key HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\All Users\Application Data\gocBcScmNJwBeCF.exe, 1:Process is running untrusted now (进程)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value gocBcScmNJwBeCF.exe within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value gocBcScmNJwBeCF.exe within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value Cache within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to create new file C:\Documents and Settings\china\Local Settings\Temporary Internet Files\desktop.ini (文件 )
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value Directory within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value Cookies within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value History within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, 10:Attempt to open protected file C:\Documents and Settings\china\Cookies\ (资源隔离)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, 10:Attempt to open protected file C:\Documents and Settings\china\Cookies\ (资源隔离)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, 8:Attempt to open protected file C:\Documents and Settings\china\Cookies\index.dat (资源隔离)
01.06.2012 23:04:49, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to delete service (服务)
01.06.2012 23:04:49, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value AppData within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
01.06.2012 23:04:49, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value MigrateProxy within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ (注册表)
01.06.2012 23:04:49, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value ProxyEnable within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ (注册表)
01.06.2012 23:04:49, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value SavedLegacySettings within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\ (注册表)
01.06.2012 23:04:49, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to create new key HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\ (注册表)
01.06.2012 23:04:49, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to create new key HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\ (注册表)
01.06.2012 23:04:49, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to create new key HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\ (注册表)
01.06.2012 23:04:49, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to create new key HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\ (注册表)
01.06.2012 23:04:49, 模块 C:\Documents and Settings\*\Local Settings\Temp\bhQdIh3ZhlUede.exe.tmp, Attempt to set value PendingFileRenameOperations within the key HKLM\SYSTEM\ControlSet002\Control\Session Manager\ (注册表)
01.06.2012 23:04:48, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value Common AppData within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
01.06.2012 23:01:48, 模块 C:\Documents and Settings\china\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, Attempt to set value 5761b2dc-ce77-4bfa-b965-6f33b1867cf2 within the key HKCU\Control Panel\ (注册表)
01.06.2012 23:01:41, 模块 C:\Documents and Settings\*\桌面\fpishzgukueugzgsyok\fpishzgukueugzgsyok.exe, 1:Process is running untrusted now (进程)
01.06.2012 23:01:25, 模块 C:\Program Files\WinRAR\WinRAR.exe, Attempt to set value AppData within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
01.06.2012 23:01:25, 模块 C:\Program Files\WinRAR\WinRAR.exe, Attempt to delete service (服务)
01.06.2012 23:01:24, 模块 C:\Program Files\WinRAR\WinRAR.exe, 2:Process is running untrusted now (进程)
|