Не обнаружил защиты ветвей реестра, связанных с автозапуском. В настройках ПЗ всё стоит на "запретить", кроме пунктов "Загрузка драйверов" и "Системные службы". Мануал пишет вот что:
===
Автозапуск программ:
·Software\Microsoft\Windows\CurrentVersion\Run
·Software\Microsoft\Windows\CurrentVersion\RunOnce
·Software\Microsoft\Windows\CurrentVersion\RunOnceEx
===
Однако запись в эти ветви делается без какой-либо реакции со стороны АВ. Лог сервиса прилагаю. В нем смущают записи от hips-manager... Хотя, возможно, они "не в кассу".
ОС - XP SP3.
2014-Nov-01 19:23:13.968750 [3068] [DBG] [GetEngineDumpSettings] Collect settings
2014-Nov-01 19:23:13.968750 [3068] [DBG] [GetEngineDumpSettings] Core/DumpOnError/Enable is 'Off'
2014-Nov-01 19:23:13.968750 [3068] [DBG] [GetEngineDumpSettings] Core/DumpOnError/Full is 'Off'
2014-Nov-01 19:23:13.968750 [3068] [DBG] [GetEngineDumpSettings] Dump/Enable is 'Off'
2014-Nov-01 19:23:13.968750 [3068] [DBG] [GetEngineDumpSettings] Dump/Full is 'Off'
2014-Nov-01 19:23:13.984375 [3068] [DBG] [config] DiffConfig:
++++++++++++++++++++++++++++++++++++++++++++++++++
setting_scheme: ""
Agent8 {
report {
detailed_log {
av_service: true
}
}
}
++++++++++++++++++++++++++++++++++++++++++++++++++
2014-Nov-01 19:23:13.984375 [3068] [INF] [create_allowed_param] Set 0 objects for white list
2014-Nov-01 19:23:13.984375 [3068] [INF] [DPH] reinit objects...
2014-Nov-01 19:23:13.984375 [3068] [DBG] [HIPSObject] Add file
2014-Nov-01 19:23:13.984375 [3068] [ERR] [hips-manager] error while reload objects:
2014-Nov-01 19:23:40.312500 [2876] [DBG] [task_manager] New task named 'services'
2014-Nov-01 19:23:40.312500 [2872] [DBG] [services_task::check_service] DrWebEngine is 'Running', pid: 2880
2014-Nov-01 19:23:49.312500 [3068] [DBG] [GetEngineDumpSettings] Collect settings
2014-Nov-01 19:23:49.312500 [3068] [DBG] [GetEngineDumpSettings] Core/DumpOnError/Enable is 'Off'
2014-Nov-01 19:23:49.312500 [3068] [DBG] [GetEngineDumpSettings] Core/DumpOnError/Full is 'Off'
2014-Nov-01 19:23:49.312500 [3068] [DBG] [GetEngineDumpSettings] Dump/Enable is 'Off'
2014-Nov-01 19:23:49.312500 [3068] [DBG] [GetEngineDumpSettings] Dump/Full is 'Off'
2014-Nov-01 19:23:49.312500 [3068] [DBG] [get_user_reg] S-1-5-18
2014-Nov-01 19:23:49.312500 [3068] [DBG] [get_user_reg] S-1-5-19
2014-Nov-01 19:23:49.312500 [3068] [DBG] [get_user_reg] S-1-5-20
2014-Nov-01 19:23:49.312500 [3068] [DBG] [get_user_reg] S-1-5-21-1214440339-1532298954-682003330-1003
2014-Nov-01 19:23:57.765625 [3068] [DBG] [GetEngineDumpSettings] Collect settings
2014-Nov-01 19:23:57.765625 [3068] [DBG] [GetEngineDumpSettings] Core/DumpOnError/Enable is 'Off'
2014-Nov-01 19:23:57.765625 [3068] [DBG] [GetEngineDumpSettings] Core/DumpOnError/Full is 'Off'
2014-Nov-01 19:23:57.765625 [3068] [DBG] [GetEngineDumpSettings] Dump/Enable is 'Off'
2014-Nov-01 19:23:57.765625 [3068] [DBG] [GetEngineDumpSettings] Dump/Full is 'Off'
2014-Nov-01 19:23:57.765625 [3068] [DBG] [config] DiffConfig:
++++++++++++++++++++++++++++++++++++++++++++++++++
setting_scheme: ""
Agent8 {
netting {
hips_access {
value {
object_type: hips_hosts
access: action_deny
}
value {
object_type: hips_disk_low_level
access: action_deny
}
value {
object_type: hips_driver_load
access: action_deny
}
value {
object_type: hips_IFEO
access: action_deny
}
value {
object_type: hips_user_drivers
access: action_deny
}
value {
object_type: hips_winlogon_shell
access: action_deny
}
value {
object_type: hips_winlogon_notifiers
access: action_deny
}
value {
object_type: hips_shell_modules
access: action_deny
}
value {
object_type: hips_exe_associations
access: action_deny
}
value {
object_type: hips_SRP
access: action_deny
}
value {
object_type: hips_BHO
access: action_deny
}
value {
object_type: hips_autoruns
access: action_deny
}
value {
object_type: hips_policy_autoruns
access: action_deny
}
value {
object_type: hips_safe_boot_config
access: action_deny
}
value {
object_type: hips_session_manager
access: action_deny
}
value {
object_type: hips_system_services
access: action_permit
}
value {
object_type: hips_ps_inject
access: action_deny
}
value {
object_type: hips_encoders
access: action_deny
}
value {
object_type: hips_prn_inject
access: action_deny
}
value {
object_type: hips_objects
access: action_deny
}
value {
object_type: hips_change_time
access: action_permit
}
}
}
}
++++++++++++++++++++++++++++++++++++++++++++++++++
2014-Nov-01 19:23:57.765625 [2868] [INF] [DPH] reinit objects...
2014-Nov-01 19:23:57.765625 [3068] [INF] [create_allowed_param] Set 0 objects for white list
2014-Nov-01 19:23:57.765625 [3068] [INF] [DPH] reinit objects...
2014-Nov-01 19:23:57.765625 [2868] [DBG] [HIPSObject] Add file
2014-Nov-01 19:23:57.765625 [2868] [ERR] [hips-manager] error while reload objects:
2014-Nov-01 19:23:57.765625 [3068] [DBG] [HIPSObject] Add file
2014-Nov-01 19:23:57.765625 [3068] [ERR] [hips-manager] error while reload objects:
2014-Nov-01 19:24:00.734375 [3068] [DBG] [GetEngineDumpSettings] Collect settings
2014-Nov-01 19:24:00.734375 [3068] [DBG] [GetEngineDumpSettings] Core/DumpOnError/Enable is 'Off'
2014-Nov-01 19:24:00.734375 [3068] [DBG] [GetEngineDumpSettings] Core/DumpOnError/Full is 'Off'
2014-Nov-01 19:24:00.734375 [3068] [DBG] [GetEngineDumpSettings] Dump/Enable is 'Off'
2014-Nov-01 19:24:00.734375 [3068] [DBG] [GetEngineDumpSettings] Dump/Full is 'Off'
2014-Nov-01 19:24:00.734375 [3068] [DBG] [config] DiffConfig:
++++++++++++++++++++++++++++++++++++++++++++++++++
setting_scheme: ""
Agent8 {
netting {
hips_access {
value {
object_type: hips_hosts
access: action_deny
}
value {
object_type: hips_disk_low_level
access: action_deny
}
value {
object_type: hips_driver_load
access: action_permit
}
value {
object_type: hips_IFEO
access: action_deny
}
value {
object_type: hips_user_drivers
access: action_deny
}
value {
object_type: hips_winlogon_shell
access: action_deny
}
value {
object_type: hips_winlogon_notifiers
access: action_deny
}
value {
object_type: hips_shell_modules
access: action_deny
}
value {
object_type: hips_exe_associations
access: action_deny
}
value {
object_type: hips_SRP
access: action_deny
}
value {
object_type: hips_BHO
access: action_deny
}
value {
object_type: hips_autoruns
access: action_deny
}
value {
object_type: hips_policy_autoruns
access: action_deny
}
value {
object_type: hips_safe_boot_config
access: action_deny
}
value {
object_type: hips_session_manager
access: action_deny
}
value {
object_type: hips_system_services
access: action_permit
}
value {
object_type: hips_ps_inject
access: action_deny
}
value {
object_type: hips_encoders
access: action_deny
}
value {
object_type: hips_prn_inject
access: action_deny
}
value {
object_type: hips_objects
access: action_deny
}
value {
object_type: hips_change_time
access: action_permit
}
}
}
}
++++++++++++++++++++++++++++++++++++++++++++++++++
2014-Nov-01 19:24:00.734375 [2852] [INF] [DPH] reinit objects...
2014-Nov-01 19:24:00.734375 [3068] [INF] [create_allowed_param] Set 0 objects for white list
2014-Nov-01 19:24:00.734375 [3068] [INF] [DPH] reinit objects...
2014-Nov-01 19:24:00.734375 [2852] [DBG] [HIPSObject] Add file
2014-Nov-01 19:24:00.734375 [2852] [ERR] [hips-manager] error while reload objects:
2014-Nov-01 19:24:00.734375 [3068] [DBG] [HIPSObject] Add file
2014-Nov-01 19:24:00.734375 [3068] [ERR] [hips-manager] error while reload objects:
2014-Nov-01 19:24:10.312500 [2876] [DBG] [task_manager] New task named 'services'
2014-Nov-01 19:24:10.312500 [2872] [DBG] [services_task::check_service] DrWebEngine is 'Running', pid: 2880
2014-Nov-01 19:24:40.312500 [2876] [DBG] [task_manager] New task named 'services'
2014-Nov-01 19:24:40.312500 [2872] [DBG] [services_task::check_service] DrWebEngine is 'Running', pid: 2880
2014-Nov-01 19:24:48.484375 [2840] [DBG] [3092] [DPH] evt: P: 0 I: 141 C: 3 T: 16 Pi: 1412 Pa: 1412 Ti: 1496 W: 1, +result: undef
2014-Nov-01 19:24:54.562500 [2860] [DBG] [3092] [DPH] evt: P: 0 I: 142 C: 3 T: 17 Pi: 4 Pa: 4 Ti: 64 W: 0
2014-Nov-01 19:25:10.312500 [2876] [DBG] [task_manager] New task named 'services'
2014-Nov-01 19:25:10.312500 [2872] [DBG] [services_task::check_service] DrWebEngine is 'Running', pid: 2880
2014-Nov-01 19:25:29.953125 [2864] [DBG] [3092] [DPH] evt: P: 0 I: 143 C: 3 T: 39 Pi: 4 Pa: 4 Ti: 40 W: 1, +result: undef
2014-Nov-01 19:25:29.968750 [2840] [DBG] [3092] [DPH] evt: P: 0 I: 144 C: 3 T: 39 Pi: 4 Pa: 4 Ti: 40 W: 1, +result: undef
2014-Nov-01 19:25:29.968750 [2840] [DBG] [3092] [DPH] evt: P: 0 I: 145 C: 3 T: 39 Pi: 4 Pa: 4 Ti: 40 W: 1, +result: undef
2014-Nov-01 19:25:30.484375 [2840] [DBG] [3092] [DPH] evt: P: 0 I: 146 C: 3 T: 16 Pi: 1412 Pa: 1412 Ti: 1496 W: 1, +result: undef
2014-Nov-01 19:25:36.500000 [2852] [DBG] [3092] [DPH] evt: P: 0 I: 147 C: 3 T: 17 Pi: 4 Pa: 4 Ti: 64 W: 0
2014-Nov-01 19:25:40.312500 [2876] [DBG] [task_manager] New task named 'services'
2014-Nov-01 19:25:40.312500 [2872] [DBG] [services_task::check_service] DrWebEngine is 'Running', pid: 2880
2014-Nov-01 19:26:10.281250 [2868] [DBG] [Scheduler] Run task: tasks::logrot
2014-Nov-01 19:26:10.312500 [2876] [DBG] [task_manager] New task named 'services'
2014-Nov-01 19:26:10.312500 [2872] [DBG] [services_task::check_service] DrWebEngine is 'Running', pid: 2880
2014-Nov-01 19:26:40.312500 [2876] [DBG] [task_manager] New task named 'services'
2014-Nov-01 19:26:40.312500 [2872] [DBG] [services_task::check_service] DrWebEngine is 'Running', pid: 2880
2014-Nov-01 19:27:10.312500 [2876] [DBG] [task_manager] New task named 'services'
Сообщение было изменено Dmitry_rus: 01 Ноябрь 2014 - 19:39