zhousulin5 发表于 2011-5-5 16:29 
正好,刚刚被这个玩意吓了一大跳,(除了加载动态库允许)什么都阻止的,居然被它关了防火墙。楼主试试看。 ...
Program Guard: rmb.exe 2011/5/6 19:10 Blocked C:\Users\xxxx\Desktop\rmb\rmb.exe wants to get a list of the files C:\*
Program Guard: rmb.exe -> ShellWindows 2011/5/6 19:10 Blocked C:\Users\xxxx\Desktop\rmb\rmb.exe(788) wants to remotely control ShellWindows
Firewall: User decision 2011/5/6 19:09 Blocked C:\Users\xxxx\Desktop\rmb\rmb.exe, Outgoing TCP access blocked to: (muhecuxudy.com;bivudywigana.com) 74.62.154.219:80
Program Guard: kernel event 2011/5/6 19:09 None OADriver: Registry, PID: 788, Act: 1, Idn: 0, Mask: \REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell - Deny (rule)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: Registry, PID: 788, Act: 1, Idn: 0, Mask: \REGISTRY\MACHINE\SOFTWARE\Classes\.exe - Deny (rule)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: Registry, PID: 788, Act: 8, Idn: 0, Mask: \REGISTRY\USER\S-1-5-21-3967847571-3398153747-2210395389-1001_CLASSES\exefile\ - Deny (rule)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: Registry, PID: 788, Act: 1, Idn: 0, Mask: \REGISTRY\MACHINE\SOFTWARE\Classes\exefile\DefaultIcon - Deny (rule)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: Registry, PID: 788, Act: 8, Idn: 0, Mask: \REGISTRY\USER\S-1-5-21-3967847571-3398153747-2210395389-1001_CLASSES\exefile\Content Type - Deny (rule)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: Registry, PID: 788, Act: 1, Idn: 0, Mask: \REGISTRY\USER\S-1-5-21-3967847571-3398153747-2210395389-1001_CLASSES\exefile\shell - Deny (rule)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: Registry, PID: 788, Act: 1, Idn: 0, Mask: \REGISTRY\USER\S-1-5-21-3967847571-3398153747-2210395389-1001_CLASSES\exefile\DefaultIcon - Deny (rule)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: Registry, PID: 788, Act: 8, Idn: 0, Mask: \REGISTRY\USER\S-1-5-21-3967847571-3398153747-2210395389-1001_CLASSES\exefile\ - Deny (rule)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: Registry, PID: 788, Act: 8, Idn: 0, Mask: \REGISTRY\USER\S-1-5-21-3967847571-3398153747-2210395389-1001_CLASSES\exefile\Content Type - Deny (rule)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: Registry, PID: 788, Act: 1, Idn: 0, Mask: \REGISTRY\USER\S-1-5-21-3967847571-3398153747-2210395389-1001_CLASSES\.exe - Deny (rule)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: OB_OPERATION_HANDLE_CREATE, 788 -> 2948, Mask: 1FFFFF - 1FF414
Program Guard: rmb.exe -> AmIcoSinglun64.exe 2011/5/6 19:09 Blocked C:\Users\xxxx\Desktop\rmb\rmb.exe(788) wants to open C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe(2948)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: OB_OPERATION_HANDLE_CREATE, 788 -> 2388, Mask: 1FFFFF - 1FF414
Program Guard: rmb.exe -> RAVBg64.exe 2011/5/6 19:09 Blocked C:\Users\xxxx\Desktop\rmb\rmb.exe(788) wants to open C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe(2388)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: OB_OPERATION_HANDLE_CREATE, 788 -> 2644, Mask: 1FFFFF - 1FF414
Program Guard: rmb.exe -> RAVCpl64.exe 2011/5/6 19:09 Blocked C:\Users\xxxx\Desktop\rmb\rmb.exe(788) wants to open C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe(2644)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: OB_OPERATION_HANDLE_CREATE, 788 -> 2924, Mask: 1FFFFF - 1FF414
Program Guard: rmb.exe -> rundll32.exe 2011/5/6 19:09 Blocked C:\Users\xxxx\Desktop\rmb\rmb.exe(788) wants to open C:\Windows\System32\rundll32.exe(2924)
Program Guard: rmb.exe -> taskhost.exe 2011/5/6 19:09 Blocked C:\Users\xxxx\Desktop\rmb\rmb.exe(788) wants to open C:\Windows\System32\taskhost.exe(1828)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: OB_OPERATION_HANDLE_CREATE, 788 -> 1828, Mask: 1FFFFF - 1FF414
Program Guard: kernel event 2011/5/6 19:09 None OADriver: OB_OPERATION_HANDLE_CREATE, 788 -> 1672, Mask: 1FFFFF - 1FF414
Program Guard: rmb.exe -> explorer.exe 2011/5/6 19:09 Blocked C:\Users\xxxx\Desktop\rmb\rmb.exe(788) wants to open C:\Windows\explorer.exe(1672)
Program Guard: rmb.exe -> dwm.exe 2011/5/6 19:09 Blocked C:\Users\xxxx\Desktop\rmb\rmb.exe(788) wants to open C:\Windows\System32\dwm.exe(1624)
Program Guard: kernel event 2011/5/6 19:09 None OADriver: OB_OPERATION_HANDLE_CREATE, 788 -> 1624, Mask: 1FFFFF - 1FF414
Program Guard: rmb.exe 2011/5/6 19:09 Allowed C:\Windows\explorer.exe -> C:\Users\xxxx\Desktop\rmb\rmb.exe
|