|
前几天注册表防护升级后,提示开始频繁了,正常操作也会提示
建议我关闭的就不用说了,我也不是菜鸟,我是不会关闭注册表监控或加这些程序到信任区的,我认为这是升级后BUG.
也发在官方论坛了,可惜工程师没反应.
使用6.0.2.678工作站版.
原本是Fujitsu的笔记本调节屏幕亮度的软件,住注册表写亮度状态值,居然触发System Startup组的规则:
Process is trying to modify value in system registry key that belongsto group System Startup. These keys control the list of modulesexecuted during Windows startup.
You are advised to grant access to these settings only if you are sureyou want to allow this program to run automatically when your computerstarts. Otherwise it is better to deny access.
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Fujitsu\IndicatorUtility
Value: BrightAC
Data(32-bit number):
0x00000004 (4)
New data(32-bit number):
0x00000005 (5)
电驴的,开和关都会
Process is trying to create value in system registry key that belongsto group System Startup. These keys control the list of modulesexecuted during Windows startup.
You are advised to grant access to these settings only if you are sureyou want to allow this program to run automatically when your computerstarts. Otherwise it is better to deny access.
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ed2k\DefaultIcon
Value: OldIcon
New data(Unicode null-terminated string):
d:\Program Files\eMule\eMule.exe
不钩选以下两条规则后一切正常:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter
HKEY_CLASSES_ROOT\PROTOCOLS\Filter
另外附上Process Monitor的监控IndicatorUty.exe(PID 1040)日志,访问注册表总共只有3处,头两处和最后,过滤规则为进程号不为1040的全排除.3处操作根本就不匹配这两条规则! |
|