对于DW来说,只是小菜一碟,完美防御。以下是日志:
DefenseWall log file
02.18.2013 17:05:34, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to set value Favorites within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
02.18.2013 17:05:34, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to delete service (服务)
02.18.2013 17:05:34, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to set value Cache within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
02.18.2013 17:05:34, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to create new file C:\Documents and Settings\GDFS\Local Settings\Temporary Internet Files\desktop.ini (文件 )
02.18.2013 17:05:34, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to set value Directory within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\ (注册表)
02.18.2013 17:05:34, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to set value Cookies within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
02.18.2013 17:05:34, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to set value History within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
02.18.2013 17:05:34, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to set value Desktop within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
02.18.2013 17:04:42, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to set value Favorites within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
02.18.2013 17:04:42, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to delete service (服务)
02.18.2013 17:04:42, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to set value Cache within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
02.18.2013 17:04:42, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to create new file C:\Documents and Settings\GDFS\Local Settings\Temporary Internet Files\desktop.ini (文件 )
02.18.2013 17:04:42, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to set value Directory within the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\ (注册表)
02.18.2013 17:04:42, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to set value Cookies within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
02.18.2013 17:04:42, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to set value History within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
02.18.2013 17:04:42, 模块 C:\Program Files\Internet Explorer\IEXPLORE.EXE, Attempt to set value Desktop within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
02.18.2013 17:04:10, 模块 C:\WINDOWS\system32\rundll32.exe, Attempt to delete service (服务)
02.18.2013 17:03:47, 模块 C:\WINDOWS\system32\rundll32.exe, Attempt to open process C:\WINDOWS\system32\ctfmon.exe (进程)
02.18.2013 17:03:47, 模块 C:\WINDOWS\system32\rundll32.exe, Attempt to open process C:\WINDOWS\system32\ctfmon.exe (进程)
02.18.2013 17:03:41, 模块 C:\WINDOWS\system32\rundll32.exe, Attempt to delete service (服务)
02.18.2013 17:03:25, 模块 C:\Program Files\WinRAR\WinRAR.exe, Attempt to set value AppData within the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ (注册表)
02.18.2013 17:03:25, 模块 C:\Program Files\WinRAR\WinRAR.exe, Attempt to delete service (服务)
02.18.2013 17:03:24, 模块 C:\Program Files\WinRAR\WinRAR.exe, 2:Process is running untrusted now (进程) |