火绒安全软件
标题:
VeraCrypt.exe触犯自定义注册表防护规则?
[打印本页]
作者:
pabloescobar
时间:
2017-1-24 13:11
标题:
VeraCrypt.exe触犯自定义注册表防护规则?
本帖最后由 pabloescobar 于 2017-1-24 13:12 编辑
{
"ver":"3.0",
"tlb":[
{
"power":1,
"name":"禁止***全家桶安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\****"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止***全家桶写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\****"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止金山全家桶安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\kingsoft*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止金山全家桶写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\kingsoft*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止百度全家桶安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\baidu*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止百度全家桶写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\baidu*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止腾讯管家安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\qqpc*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止腾讯管家写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\qqpc*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止***卫士安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\***safe*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止***卫士写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\***safe*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止***杀毒安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\***sd*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止***杀毒写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\***sd*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止***浏览器安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\***se*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止***浏览器写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\***se*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止***压缩安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\***zip*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止***压缩写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\***zip*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止金山毒霸安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\kingsoft antivirus*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止金山毒霸写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\kingsoft antivirus*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止金山WPS安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\WPS Office*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止金山WPS写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\WPS*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止金山卫士安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\ksafe*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止金山卫士写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\ksafe*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止猎豹浏览器安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\liebao*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止猎豹浏览器写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\liebao*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止百度杀毒安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\BaiduSd*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止百度杀毒写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\BaiduSd*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止百度卫士安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\BaiduAn*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止百度卫士写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\BaiduAn*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止百度浏览器安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\BaiduBrowser*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止百度浏览器写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\BaiduBrowser*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止搜狗浏览器安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\sogouexplorer*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止搜狗浏览器写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\sogouexplorer*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止搜狗输入法安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\SogouInput*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止搜狗输入法写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\SogouInput*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止搜狗全家桶安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\Sogou*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止搜狗全家桶写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\Sogou*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止搜狐影音安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\搜狐影音*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止搜狐影音写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\sohuva*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止QQ浏览器安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\qqbrowser*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止QQ浏览器写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\qqbrowser*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"腾讯应用宝(手机助手)安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\qqphonemanager*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"腾讯应用宝(手机助手)写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\qqphonemanager*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止迅雷***影视写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\kkvideo*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止酷屏安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\kuping*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止酷屏写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\kuping*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止PPTV安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\pptv*"
},
{
"mt":1,
"at":1,
"res_path":"*\pplive*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止PPTV写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\pptv*"
},
{
"mt":2,
"at":5,
"res_path":"*\pplive*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止暴风影音安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\baofeng*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止暴风影音写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\baofeng*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止暴风助手安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\PhoneAssistant*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止暴风助手写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\PhoneAssistant*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止如意淘安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\Shopping Assistant*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止如意淘写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\ruyitao*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止风行安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\funshion*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止风行写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\funshion*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止快压安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\快压*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止uusee网络电视写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\uusee*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止好压安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\haozip*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止好压写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\haozip*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止2345全家桶安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\2345*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止2335全家桶写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\2345*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"Search Protect by conduit(流氓)",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\Search Protect by conduit*"
},
{
"mt":1,
"at":1,
"res_path":"*\cltmng*.exe"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止稻**人安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\daocaoren*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止稻**人注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\DcrsysFastutil*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止七喜软件安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\qixi*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止阿里电话安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\alicall*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止阿里电话写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\alicall*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止皮皮全家桶安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\pipi*"
},
{
"mt":1,
"at":1,
"res_path":"*\ppsoft*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止皮皮全家桶写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\pipi*"
},
{
"mt":2,
"at":5,
"res_path":"*\ppsoft*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止点心软件安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\dianxin*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止音乐FM安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\yyfm*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止爱聊安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\ailiao*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止快玩安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\kuaiwai*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止快玩写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\kuaiwai*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止多玩全家桶安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\duowan*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止多玩写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\duowan*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止瑞星安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\rising*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止瑞星写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\rising*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止***历安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\ttrili*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止简单日历安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\jdrl*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止人生日历安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\DTLSoft*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止人生日历写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\DTLSoft*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止今日新闻安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\look_xw*"
},
{
"mt":1,
"at":1,
"res_path":"*\numfirst*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止时刻在线安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\时刻在线*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止小菜桌面安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\小菜桌面*"
},
{
"mt":1,
"at":1,
"res_path":"*\xiaocai_desktool*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止光速输入法安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\gssoft*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止快车安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\flashget*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止快车写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\JetCar*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止光影魔术手安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\NeoImaging*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止光影魔术手写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\NeoImaging*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止光影看图安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\NeoViewer*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止UC浏览器安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\UCBrowser*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止UC浏览器写入注册表",
"policies":{
"*":[
{
"mt":2,
"at":5,
"res_path":"*\UCBrowser*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止神马***影视安装",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\ShenmTV*"
}
]
},
"verdict":0
},
{
"power":1,
"name":"禁止桌面创建乱七八糟图标",
"policies":{
"*":[
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*包邮*"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*****.ink"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*影视*.url"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*****.url"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*影视*.ink"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*网址大全*.url"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*导航*.ink"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*电影*.url"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*热门*.ink"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*网址大全*.ink"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*游戏*.ink"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*游戏*.url"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*导航*.url"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*热门*.url"
},
{
"mt":1,
"at":1,
"res_path":"*\Desktop\*电影*.ink"
}
]
},
"verdict":0
},
{
"power":1,
"name":"YY",
"policies":{
"*":[
{
"mt":1,
"at":16,
"res_path":"*\yyrun.exe"
},
{
"mt":1,
"at":16,
"res_path":"*\yyexternal.exe"
},
{
"mt":1,
"at":16,
"res_path":"*\yylauncher.exe"
},
{
"mt":1,
"at":16,
"res_path":"*\yypcgame.exe"
},
{
"mt":1,
"at":16,
"res_path":"*\yybrowser.exe"
},
{
"mt":1,
"at":16,
"res_path":"*\instlauncher.exe"
}
]
},
"verdict":0
}
]
}
复制代码
以上在论坛下载的全家桶规则。veracrypt是一个正常磁盘加密软件,而我当时又没有安装***,为什么会报警呢
作者:
admin
时间:
2017-1-24 13:16
看日志,这个软件创建了 带360 字符的注册表项了~~
你这个自定义规则(注册表的*\\360\\*)这类的,太狠了。
作者:
pabloescobar
时间:
2017-1-24 15:12
原来如此,那只好删除这条规则了
欢迎光临 火绒安全软件 (https://bbs.huorong.cn/)
Powered by Discuz! X3.4