本帖最后由 ksss5566 于 2013-8-31 09:28 编辑
虚拟机Vmware 9.0.2 build-1031769
手贱,直接点了清除Vmware 打不开了,隔离区恢复不回去,点击恢复并信任后,才成功的。
信任列表里还找不到Vmware,肿么了这是?
上图:
主程序有点大,上了网盘链接:http://pan.baidu.com/share/link? ... 8&uk=1191547842
动态防御日志:
2013-08-31 08:59:48, C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe 试图改写敏感文件 \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS. . 云鉴定: 无建议, (等待处理)
2013-08-31 08:59:48, ServerCreatePrompt and send to client success for C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe, action: 0
2013-08-31 08:59:48, ClientCreatePrompt success
2013-08-31 08:59:48, ->ShowPromptWindow
2013-08-31 08:59:48, <-ShowPromptWindow: 0
2013-08-31 08:59:53, ->ShowPromptWindow
2013-08-31 08:59:53, <-ShowPromptWindow: 1
2013-08-31 08:59:56, ->ShowPromptWindow
2013-08-31 08:59:56, <-ShowPromptWindow: 1
2013-08-31 08:59:57, SystemProtection was blocked for \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS. <- C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe(PID:6056)::C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe(TID:3368)
2013-08-31 08:59:57, Begin Rollback for C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe
2013-08-31 08:59:57, Rollback Terminate Process C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe(PID: 6056) succed(0x0)
2013-08-31 08:59:57, Rollback Terminate MainThread 3368 in process C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe(PID: 6056) succed(0x0)
2013-08-31 08:59:57, End Rollback for C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe
2013-08-31 08:59:57, 成功 结束进程 C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe(PID: 6056)
2013-08-31 08:59:57, Begin Rollback for C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe
2013-08-31 08:59:57, Rollback Terminate MainThread 3368 in process C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe(PID: 6056) succed(0x0)
2013-08-31 08:59:57, Rollback to remove and quarantine dropped file C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe, quarantine succed.
2013-08-31 08:59:57, End Rollback for C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe
2013-08-31 08:59:57, 失败 结束进程 C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe, 返回代码: -1073741810
2013-08-31 08:59:57, 清除文件 C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe. 云鉴定: 无建议, (成功清除) 备份返回代码: 4, 清除返回代码: -1
|