火绒扫描miss双击
- 【1】2020-08-19 20:09:34,系统防护,系统加固,reg.exe触犯注册表防护规则, 已阻止
- 操作进程:C:\Windows\system32\reg.exe
- 命令行:"C:\Windows\system32\reg.exe" ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utilman.exe" /f /v Debugger /t REG_SZ /d %windir%\system32\cmd.exe
- 父进程:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
- 防护项目:映像劫持项
- 目标注册表:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utilman.exe\Debugger
- 操作类型:【修改】
- 数据内容:%windir%\system32\cmd.exe
- 操作结果:已阻止
- >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
- 【2】2020-08-19 20:09:34,系统防护,系统加固,reg.exe触犯注册表防护规则, 已阻止
- 操作进程:C:\Windows\system32\reg.exe
- 命令行:"C:\Windows\system32\reg.exe" ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe" /f /v Debugger /t REG_SZ /d "Hotkey Disabled"
- 父进程:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
- 防护项目:映像劫持项
- 目标注册表:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\Debugger
- 操作类型:【修改】
- 数据内容:Hotkey Disabled
- 操作结果:已阻止
- >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
- 【3】2020-08-19 20:09:29,系统防护,系统加固,powershell.exe触犯敏感动作防护规则, 已阻止
- 操作进程:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
- 命令行:powershell.exe -NoExit -Command -
- 父进程:C:\Users\Administrator\Desktop\bild.exe
- 防护项目:命令行删除卷影还原点
- 执行文件:C:\Windows\system32\vssadmin.exe
- 执行命令行:"C:\Windows\system32\vssadmin.exe" Delete Shadows /All /Quiet
- 操作结果:已阻止
- >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
- 【4】2020-08-19 20:09:27,系统防护,系统加固,powershell.exe触犯敏感动作防护规则, 已阻止
- 操作进程:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
- 命令行:powershell.exe -NoExit -Command -
- 父进程:C:\Users\Administrator\Desktop\bild.exe
- 防护项目:命令行删除卷影还原点
- 执行文件:C:\Windows\System32\Wbem\WMIC.exe
- 执行命令行:"C:\Windows\System32\Wbem\WMIC.exe" SHADOWCOPY DELETE
- 操作结果:已阻止
- >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
复制代码 出现:
|