没想到规则回来了,可喜可贺。
刚测试了一下,该规则默认配置下会误报Lenovo Vantage的Battery Widget相关组件,谨附上从火绒导出的相关日志文件。
- 【1】2022-08-10 12:04:04,高级防护,自定义防护,regList.wsf触犯自定义防护规则, 已允许
- 触犯规则:Suspicious.ScriptHost.A
- 操作类型:【执行】
- 操作文件:C:\WINDOWS\System32\conhost.exe
- 操作结果:已允许
- 进程ID:11276
- 操作进程:C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\resources\app\node_modules\regedit\vbs\regList.wsf
- 操作进程命令行:cscript.exe //Nologo C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\resources\app\node_modules\regedit\vbs\regList.wsf A HKLM\Software\WOW6432Node\Lenovo\VantageService\FileLogger
- 父进程ID:18168
- 父进程:C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe
- 父进程命令行:"C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe"
- >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
- 【2】2022-08-10 12:04:00,高级防护,自定义防护,cscript.exe触犯自定义防护规则, 已允许
- 触犯规则:Suspicious.ScriptHost.A
- 操作类型:【执行】
- 操作文件:C:\WINDOWS\System32\conhost.exe
- 操作结果:已允许
- 进程ID:15576
- 操作进程:C:\Windows\System32\cscript.exe
- 操作进程命令行:cscript.exe
- 父进程ID:18168
- 父进程:C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe
- 父进程命令行:"C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe"
- >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
- 【3】2022-08-10 11:53:29,高级防护,自定义防护,cscript.exe触犯自定义防护规则, 已允许
- 触犯规则:Suspicious.ScriptHost.A
- 操作类型:【执行】
- 操作文件:C:\WINDOWS\System32\conhost.exe
- 操作结果:已允许
- 进程ID:20332
- 操作进程:C:\Windows\System32\cscript.exe
- 操作进程命令行:cscript.exe
- 父进程ID:13504
- 父进程:C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe
- 父进程命令行:"C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe" -StartByContractBatteryWidgetEnable
- >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
- 【4】2022-08-10 11:53:26,高级防护,自定义防护,cscript.exe触犯自定义防护规则, 已阻止
- 触犯规则:Suspicious.ScriptHost.A
- 操作类型:【执行】
- 操作文件:C:\WINDOWS\System32\conhost.exe
- 操作结果:已阻止
- 进程ID:14448
- 操作进程:C:\Windows\System32\cscript.exe
- 操作进程命令行:cscript.exe
- 父进程ID:15020
- 父进程:C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe
- 父进程命令行:"C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe" -StartByContractBatteryWidgetEnable
- >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
- 【5】2022-08-10 11:53:21,高级防护,自定义防护,cscript.exe触犯自定义防护规则, 已阻止
- 触犯规则:Suspicious.ScriptHost.A
- 操作类型:【执行】
- 操作文件:C:\WINDOWS\System32\conhost.exe
- 操作结果:已阻止
- 进程ID:21684
- 操作进程:C:\Windows\System32\cscript.exe
- 操作进程命令行:cscript.exe
- 父进程ID:2140
- 父进程:C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe
- 父进程命令行:"C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe" -StartByContractBatteryWidgetEnable
- >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
- 【6】2022-08-10 11:53:07,高级防护,自定义防护,cscript.exe触犯自定义防护规则, 已允许
- 触犯规则:Suspicious.ScriptHost.A
- 操作类型:【执行】
- 操作文件:C:\WINDOWS\System32\conhost.exe
- 操作结果:已允许
- 进程ID:22120
- 操作进程:C:\Windows\System32\cscript.exe
- 操作进程命令行:cscript.exe
- 父进程ID:21776
- 父进程:C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe
- 父进程命令行:"C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe" -StartByContractBatteryWidgetEnable
- >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
- 【7】2022-08-10 11:50:21,高级防护,自定义防护,cscript.exe触犯自定义防护规则, 已阻止
- 触犯规则:Suspicious.ScriptHost.A
- 操作类型:【执行】
- 操作文件:C:\WINDOWS\System32\conhost.exe
- 操作结果:已阻止
- 进程ID:18164
- 操作进程:C:\Windows\System32\cscript.exe
- 操作进程命令行:cscript.exe
- 父进程ID:17988
- 父进程:C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe
- 父进程命令行:"C:\ProgramData\Lenovo\Vantage\Addins\BatteryWidgetAddin\1.0.0.75\BatteryWidgetHost\BatteryWidgetHost.exe"
- >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
复制代码
|