瑞星卡卡安全论坛技术交流区系统软件 TINY防火墙Tracklog Analyzer 注册表日志的看法

12   2  /  2  页   跳转

TINY防火墙Tracklog Analyzer 注册表日志的看法

引用:
【疯狂粽子的贴子】baohe版主,真是麻烦你了
3楼上的那个我也是那样设置的,其实monitor 和do not monitor我都设置过,但是当用tracklog analyzer追踪软件的行为时,在reports里面仍然没有追踪这断时间的记录,在Tracklog Analyzer里面能看到创建删除许多问题,但是在reports里面只显示了程序的启动和结束,中间过程一点也没有记录。如图1

………………

估计是你的监控设置有问题。
关于Tiny监控日志文本的导出,我是这样实现的。

1、用word打开Tracking日志文件.xml。然后,另存为单一网页文件。

附件附件:

下载次数:132
文件类型:image/pjpeg
文件大小:
上传时间:2006-12-13 21:07:41
描述:
预览信息:EXIF信息



gototop
 

2、用IE打开刚才那个单一网页文件即可得到监控日志的完整文本内容。

附件附件:

下载次数:128
文件类型:image/pjpeg
文件大小:
上传时间:2006-12-13 21:09:42
描述:
预览信息:EXIF信息



gototop
 

3、这时,你愿意怎么剪切、粘贴,就随你便了。
下面是粘贴到“写字板”上的例子。

附件附件:

下载次数:128
文件类型:image/pjpeg
文件大小:
上传时间:2006-12-13 21:11:47
描述:
预览信息:EXIF信息



gototop
 

这是导出的监控“免疫007”的部分日志文本。
HKCU\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\\MRUListEx

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





HKCU\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\6\\MRUListEx

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\40\Shell\\FolderType

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\65\Shell\\FolderType

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\66\Shell\\FolderType

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\\Common Documents

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





{00000000-0000-0000-0000-000000000000}

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





{00BB2763-6A77-11D0-A535-00C04FD7D062}

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





{03C036F1-A186-11D0-824A-00AA005B4383}

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





{42AEDC87-2188-41FD-B9A3-0C966FEABEC1}

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





{603D3800-BD81-11D0-A3A5-00C04FD706EC}

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





{60664CAF-AF0D-0004-A300-5C7D25FF22A0}

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





{750FDF0E-2A26-11D1-A3EA-080036587F03}

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





C:\WINDOWS\system32\olepro32.dll

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





C:\WINDOWS\system32\winspool.drv

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed





C:\WINDOWS\system32\oledlg.dll

C:\Documents and Settings\baohelin\Local Settings\Temp\Rar$EX03.711\免疫007.exe

Allowed
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT