本帖最后由 c/mm 于 2018-9-15 21:56 编辑
大蜘蛛扫描MISS WIN10 1803 64位实机双击虽然拦截不到位的地方 但是1分钟关闭电脑后开机还算一切正常 为了演示文件名字更改为222222222222222.EXE
事件注册表相关拦截
Preventive Protection event: Change protected value
id: 4832, timestamp: 21:33:33.518, type: RegSetValue (14), flags: 1 (wait: 1)
sid: S-1-5-21-1330110338-2855936389-87448162-1001, cid: 6568/5628:\Device\HarddiskVolume4\Users\cbwf5\Desktop\111111111\2222222222222222222222222222.exe
context: start addr: 0xe6e942, image: 0x400000:\Device\HarddiskVolume4\Users\cbwf5\Desktop\111111111\2222222222222222222222222222.exe
hips: type: 9, action: deny [5]
cmd: "C:\Users\cbwf5\Desktop\111111111\2222222222222222222222222222.exe"
fileinfo: size: 5410816, easize: 40, attr: 0x20, buildtime: 13.09.2018 16:41:26.000, ctime: 15.09.2018 20:10:27.832, atime: 15.09.2018 21:30:56.840, mtime: 13.09.2018 16:46:32.151, descr: 泰哥多功能助手, ver: 1.0.0.0, company: 1, oname:
hash: 2fd243a14615b570deeeed073af0946181b9cb9b status: unsigned, pe32, new_pe / unsigned / unknown / unknown
key: \REGISTRY\MACHINE\SOFTWARE\Classes\exefile\DefaultIcon, access: 0x0
value: , type: sz
current content:
00000000: 25 00 31 00 00 00 %.1...
new content:
00000000: 43 00 3a 00 5c 00 77 00 69 00 6e 00 64 00 6f 00 C.:.\.w.i.n.d.o.
00000010: 77 00 73 00 5c 00 53 00 79 00 73 00 57 00 6f 00 w.s.\.S.y.s.W.o.
00000020: 77 00 36 00 34 00 5c 00 31 00 2e 00 69 00 63 00 w.6.4.\.1...i.c.
00000030: 6f 00 00 00 o...
send user blocked alert
id: 4832 ==> denied [5], time: 0.358769 ms
id: 4495, timestamp: 21:33:21.979, type: RegSetValue (14), flags: 1 (wait: 1)
sid: S-1-5-21-1330110338-2855936389-87448162-1001, cid: 6568/5628:\Device\HarddiskVolume4\Users\cbwf5\Desktop\111111111\2222222222222222222222222222.exe
context: start addr: 0xe6e942, image: 0x400000:\Device\HarddiskVolume4\Users\cbwf5\Desktop\111111111\2222222222222222222222222222.exe
hips: type: 12, action: ask [0]
cmd: "C:\Users\cbwf5\Desktop\111111111\2222222222222222222222222222.exe"
fileinfo: size: 5410816, easize: 40, attr: 0x20, buildtime: 13.09.2018 16:41:26.000, ctime: 15.09.2018 20:10:27.832, atime: 15.09.2018 21:30:56.840, mtime: 13.09.2018 16:46:32.151, descr: 泰哥多功能助手, ver: 1.0.0.0, company: 1, oname:
hash: 2fd243a14615b570deeeed073af0946181b9cb9b status: unsigned, pe32, new_pe / unsigned / unknown / unknown
key: \REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run, access: 0x0
value: System, type: sz
new content:
00000000: 43 00 3a 00 5c 00 50 00 72 00 6f 00 67 00 72 00 C.:.\.P.r.o.g.r.
00000010: 61 00 6d 00 20 00 46 00 69 00 6c 00 65 00 73 00 a.m. .F.i.l.e.s.
00000020: 5c 00 53 00 79 00 73 00 74 00 65 00 6d 00 2e 00 \.S.y.s.t.e.m...
00000030: 64 00 6c 00 6c 00 00 00 d.l.l...
send user alert and wait action...
user selected action: deny [5]
id: 4495 ==> denied [5], time: 9418.672809 ms
|