联盟版瑞星阻止安装QQ轻聊版组件【未复现】
2016-6-20 10:16 | 设备访问防护 | 阻止qqprotect.exe | 规则ID:131268621 防护类型:创建服务 进程:C:\Program Files\Common Files\Tencent\QQProtect\Bin\QQProtect.exe 目标进程: |
2016-6-20 10:16 | 关键文件防护 | 阻止qq7.9light.exe | 规则ID:131272640 防护类型:写方式打开 进程:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\QQ7.9Light.exe 文件路径:C:\WINDOWS\system32\drivers\QQProtect.sys |
2016-6-20 10:15 | 关键文件防护 | 阻止qq7.9light.exe | 规则ID:131272640 防护类型:写方式打开 进程:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\QQ7.9Light.exe 文件路径:C:\WINDOWS\system32\drivers\QQFrmMgr.sys |
2016-6-20 10:15 | 注册表防护 | 阻止aliworkbenchsafe.exe | 规则ID:131271456 防护类型:修改 进程:C:\Program Files\AliWorkbenchSafe\0.2.4\AliWorkbenchSafe.exe 注册表路径:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AliWorkbench Safe Service |
2016-6-20 10:15 | 注册表防护 | 阻止qq7.9light.exe | 规则ID:131271648 防护类型:修改 进程:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\QQ7.9Light.exe 注册表路径:HKEY_USERS\S-1-5-21-3895204715-4065939156-3972322764-500\Software\Microsoft\Windows\CurrentVersion\Run |
2016-6-20 10:15 | 系统内核加固 | 阻止qq7.9light.exe | 规则ID:131269249 防护类型:创建 进程:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\QQ7.9Light.exe 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDD362CF-523B-4BC9-8FDC-58F93B6BC945} |
2016-6-20 10:15 | 注册表防护 | 阻止qq7.9light.exe | 规则ID:131269248 防护类型:创建 进程:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\QQ7.9Light.exe 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects |
2016-6-20 10:15 | 系统内核加固 | 阻止regsvr32.exe | 规则ID:131269249 防护类型:创建 进程:C:\WINDOWS\system32\regsvr32.exe 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDD362CF-523B-4BC9-8FDC-58F93B6BC945} |
2016-6-20 10:15 | 系统内核加固 | 阻止regsvr32.exe | 规则ID:131269249 防护类型:创建 进程:C:\WINDOWS\system32\regsvr32.exe 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDD362CF-523B-4BC9-8FDC-58F93B6BC945} |
2016-6-20 10:15 | 注册表防护 | 阻止instasm.exe | 规则ID:131271888 防护类型:修改 进程:C:\Documents and Settings\Administrator\Application Data\Tencent\QQLite\STemp\TXQQ2052~0\SysDir\InstAsm.exe 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
2016-6-20 10:15 | 注册表防护 | 阻止instasm.exe | 规则ID:131271888 防护类型:修改 进程:C:\Documents and Settings\Administrator\Application Data\Tencent\QQLite\STemp\TXQQ2052~0\SysDir\InstAsm.exe 注册表路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
麦青儿 最后编辑于 2016-06-20 18:36:48