本帖最后由 驭龙 于 2019-7-26 09:50 编辑
我这里也是剩余6个,没有双击
=========================
今天无聊,实机双击,WD云五连杀
剩余1个虽然没杀,却被自定义规则的WD Exploit Guard功能干掉,而且还触发神秘的WDATP反馈机制,反馈至WDATP平台分析,PS: WD内置福利,我什么都没有说
五连杀中有被WD HIPS功能的规则干掉,母体触发云杀
2019-07-26T01:26:52.701Z [MpRtp] Engine VFZ HIPS block: \Device\HarddiskVolume5\12345\7.25_3\2019-07-25 D36E446B.exe. status=0x40070000, statusex=0x1310, threatid=0x80000000, sigseq=0x212bd9417d460
2019-07-26T01:26:52.717Z [Mini-filter] Blocked file: \Device\HarddiskVolume5\12345\7.25_3\2019-07-25 D36E446B.exe. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0x0, State: 6, ScanRequest #7961, FileId: 0x100000000b4e3, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x1000a1, FileAttributes:0x20, ScanAttributes:0x60, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0
|