Impostazioni di sicurezza cartelle di sistema

Anonimo
2023-08-27T21:50:22+00:00

Buonasera, vorrei sapere quali dovrebbero essere i proprietari e i permessi di default delle cartelle di sistema come Windows. Controllando l'accesso valido per me, noto che è assente il controllo completo, anche per administrators.

Windows per utenti privati | Windows 10 | Sicurezza e privacy

Domanda bloccata. Questa domanda è stata eseguita dalla community del supporto tecnico Microsoft. È possibile votare se è utile, ma non è possibile aggiungere commenti o risposte o seguire la domanda.

0 commenti Nessun commento

54 risposte

Ordina per: Più utili
  1. Spigolo 136.2K Punti di reputazione Moderatore volontario
    2023-08-31T17:14:02+00:00

    A giudicare dal log, l'operazione sembra conclusa correttamente.

    Stopped On 08-31-2023 19:03:41 (Exit Code = 0x0)

    La risposta è stata utile?

    0 commenti Nessun commento
  2. Anonimo
    2023-08-31T17:09:08+00:00

    Trovato:


    Microsoft Antimalware (F7F4CD20-7371-4319-B1DB-6FCFC68573EC) Service Log

    Started On 08-31-2023 18:59:23

    ************************************************************

    OS install time not retrieved: hr = 0x8007000d

    Current time: 08/31/2023 18:59:23.892370400 UTC (11796 ms since boot)

    2023-08-31T18:59:23.888Z ProductId: 4, ProductFeature: 0, LaunchedProtected: 0, IsWcos: 0, IsContainerOs: 0

    2023-08-31T18:59:23.888Z [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: WdoWppTracing-20230831-185923-00000003-ffffffff.bin ...

    2023-08-31T18:59:23.888Z [WPP] Trace session started - WdoWppTracing-20230831-185923-00000003-ffffffff.bin

    2023-08-31T18:59:23.888Z OS Build/Branch info: 19041.1.amd64fre.vb_release.191206-1406

    2023-08-31T18:59:23.888Z [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Offline Scanner

    2023-08-31T18:59:23.888Z Service is asked to be reenabled.

    2023-08-31T18:59:23.888Z Task(-EnableService) launched

    2023-08-31T18:59:23.935Z Loaded module#0 MpComServer.

    2023-08-31T18:59:23.935Z Loading engine...

    2023-08-31T18:59:24.560Z UpdateEngine start: Source: 3, szUpdateDirectory: C:\Windows\Microsoft Antimalware\Definition Updates{2BCCDFF2-C33D-4B08-848D-97DE9DAF08B4}

    2023-08-31T18:59:25.169Z Verifying engine and signature files (source: 0) ...

    2023-08-31T18:59:25.309Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates{09F7CAD7-BC5C-4502-8C31-A06349EEC325}\mpengine.dll]

    2023-08-31T18:59:25.840Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates{09F7CAD7-BC5C-4502-8C31-A06349EEC325}\mpasbase.vdm]

    2023-08-31T18:59:25.855Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates{09F7CAD7-BC5C-4502-8C31-A06349EEC325}\mpasdlta.vdm]

    2023-08-31T18:59:26.121Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates{09F7CAD7-BC5C-4502-8C31-A06349EEC325}\mpavbase.vdm]

    2023-08-31T18:59:26.121Z Verified [C:\Windows\Microsoft Antimalware\Definition Updates{09F7CAD7-BC5C-4502-8C31-A06349EEC325}\mpavdlta.vdm]

    Database:

    2023-08-31T18:59:26.308Z Can't find offline cache cache (C:\Windows\Microsoft Antimalware\Scans\mpcache-C6D6A097A855E62FF640BF872BB1CBD563F9B64C.bin): 0x00000002IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007bIDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000dIDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d

    2023-08-31T18:59:32.151Z [AutoExclusion] Skipped Non-Windows 10+ Server SKUs.

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=144000000000, scope=0x380)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Aplha Test for ASR in Audit Mode", State=5, Action=1, Type=1, Duplicates(Interval=0, scope=0x0)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Aplha Test for ASR in Block Mode", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0)

    Engine-HIPS:

    2023-08-31T18:59:32.182Z Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100)

    2023-08-31T18:59:32.182Z CSignatureStatus: back to good

    2023-08-31T18:59:32.182Z [Engine] Loaded C:\Windows\Microsoft Antimalware\Definition Updates{09F7CAD7-BC5C-4502-8C31-A06349EEC325}

    2023-08-31T18:59:32.182Z [Engine] Removing C:\Windows\Microsoft Antimalware\Definition Updates{2BCCDFF2-C33D-4B08-848D-97DE9DAF08B4} ...

    2023-08-31T18:59:32.182Z MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0x0

    Signature updated via XCopy on 08-31-2023 18:59:32

    Product Version: 4.18.1907.16384

    Service Version: 4.18.1909.6

    Engine Version: 1.1.23080.2005

    AS Signature Version: 1.397.101.0

    AV Signature Version: 1.397.101.0

    ************************************************************

    2023-08-31T18:59:32.198Z UpdateEngine finished with 0x0: Source: 3, szUpdateDirectory: C:\Windows\Microsoft Antimalware\Definition Updates{2BCCDFF2-C33D-4B08-848D-97DE9DAF08B4}

    2023-08-31T18:59:32.213Z Engine loaded!

    2023-08-31T18:59:32.213Z Verifying license file...

    2023-08-31T18:59:32.213Z Verified [C:\ProgramData\Microsoft\Windows Defender\Offline Scanner\msmplics.dll]

    2023-08-31T18:59:32.213Z MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0x0

    Product Version: 4.18.1907.16384

    Service Version: 4.18.1909.6

    Engine Version: 1.1.23080.2005

    AS Signature Version: 1.397.101.0

    AV Signature Version: 1.397.101.0

    ************************************************************

    2023-08-31T18:59:32.995Z MpManagerEnable: setting DisableAS to 0 ...

    2023-08-31T18:59:32.995Z MpManagerEnable: setting DisableAV to 0 ...

    2023-08-31T18:59:32.995Z Scheduled scan configured CPU priority: normal (LowCpuPriority: 0)

    Internal signature match:subtype=Lowfi, sigseq=0x0000157EECC7829F, sigsha=988df01ffc332e9c60addbbe1c74b85f43b49817, cached=false, source=0, resourceid=0x0179b885

    Internal signature match:subtype=Lowfi, sigseq=0x00001080CF3DC54A, sigsha=dc7a9ea95ab1830307a97c696dec431373c25910, cached=false, source=0, resourceid=0x1e17b347

    Internal signature match:subtype=Lowfi, sigseq=0x0000157E98961FA8, sigsha=29727b199c33e2ba7beb863c494f3a822d8e7975, cached=false, source=0, resourceid=0x1e17b347

    Internal signature match:subtype=Lowfi, sigseq=0x0000157E7DA74CE2, sigsha=be4b045066adb117662addadfa72dfb59bf95f4a, cached=false, source=0, resourceid=0xebbb5019

    Internal signature match:subtype=Lowfi, sigseq=0x0000157EA88D91A9, sigsha=7b236713674a60036db07f5aacf97713795f971b, cached=false, source=0, resourceid=0xebbb5019

    Internal signature match:subtype=Lowfi, sigseq=0x0000157E3BAEFC7E, sigsha=b0a8beb1665493c99b94ee6937bbfd9cde0e115d, cached=false, source=0, resourceid=0xebbb5019

    Internal signature match:subtype=Lowfi, sigseq=0x0000157E90C02BA5, sigsha=2b4fbfe1f738b340a4d45f1eb904b0db2cec9e80, cached=false, source=0, resourceid=0x3105a5dd

    Internal signature match:subtype=Lowfi, sigseq=0x0000157EF20D1A7C, sigsha=aa5b9372f0ec225d6342e12ffb9db40b90cfd590, cached=false, source=0, resourceid=0x399405b1

    Internal signature match:subtype=Lowfi, sigseq=0x0000157EE45A0D42, sigsha=73f044c8433b867a62860948a23e8ab3d134e025, cached=false, source=0, resourceid=0x5b9dc1be

    Internal signature match:subtype=Lowfi, sigseq=0x0000157EFE404EE0, sigsha=d305323f56f3cf14dec20fcc80a8b76d2197d0db, cached=false, source=0, resourceid=0xbfe8f9b7

    2023-08-31T18:59:40.797Z [Cloud] Engine is requesting config to do cloud query [regular network].

    Engine:

    2023-08-31T19:00:16.151Z Setting original file name "control.exe" for "\?\c:\windows\syswow64\fontext.dll", hr=0x0

    2023-08-31T19:00:23.906Z Process scan (postsignatureupdatescan) started.

    2023-08-31T19:00:24.156Z Process scan (postsignatureupdatescan) completed.

    Internal signature match:subtype=Lowfi, sigseq=0x0000157E4A007D3D, sigsha=63c44c372481504bb7fb73e1489e29be34876793, cached=false, source=0, resourceid=0xa681fa81

    Engine:

    2023-08-31T19:00:37.063Z Setting original file name "mshta.exe" for "\?\c:\windows\syswow64\mshtml.dll", hr=0x0

    Internal signature match:subtype=Lowfi, sigseq=0x0000157E54114927, sigsha=b65e7387d9262d4ec12d80df586114a94463914a, cached=false, source=0, resourceid=0xde8c842f

    Internal signature match:subtype=Lowfi, sigseq=0x0000157EBA69AEFD, sigsha=572d748d4369bb207228c0910ae5a8692983d001, cached=false, source=0, resourceid=0xde8c842f

    Engine:

    2023-08-31T19:00:47.734Z Setting original file name "pcalua.exe" for "\?\c:\windows\syswow64\pcacli.dll", hr=0x0

    Engine:

    2023-08-31T19:00:47.814Z Setting original file name "pcalua.exe" for "\?\c:\windows\syswow64\pcaui.exe", hr=0x0

    Engine:

    2023-08-31T19:00:55.132Z Setting original file name "reg.exe" for "\?\c:\windows\syswow64\reg.exe", hr=0x0

    Engine:

    2023-08-31T19:00:55.398Z Setting original file name "register-cimprovider2.exe" for "\?\c:\windows\syswow64\register-cimprovider.exe", hr=0x0

    Engine:

    2023-08-31T19:00:57.141Z Setting original file name "rundll32.exe" for "\?\c:\windows\syswow64\rundll32.exe", hr=0x0

    Engine:

    2023-08-31T19:00:57.719Z Setting original file name "schtasks.exe" for "\?\c:\windows\syswow64\schtasks.exe", hr=0x0

    Internal signature match:subtype=Lowfi, sigseq=0x0000157EECC7829F, sigsha=988df01ffc332e9c60addbbe1c74b85f43b49817, cached=false, source=0, resourceid=0x0179b885

    Engine:

    2023-08-31T19:02:17.138Z Setting original file name "pcalua.exe" for "\?\c:\windows\system32\pcacli.dll", hr=0x0

    Engine:

    2023-08-31T19:02:17.169Z Setting original file name "pcalua.exe" for "\?\c:\windows\system32\pcadm.dll", hr=0x0

    Engine:

    2023-08-31T19:02:23.177Z Setting original file name "reg.exe" for "\?\c:\windows\system32\reg.exe", hr=0x0

    Engine:

    2023-08-31T19:02:23.318Z Setting original file name "register-cimprovider2.exe" for "\?\c:\windows\system32\register-cimprovider.exe", hr=0x0

    Engine:

    2023-08-31T19:02:25.488Z Setting original file name "rundll32.exe" for "\?\c:\windows\system32\rundll32.exe", hr=0x0

    Engine:

    2023-08-31T19:02:26.025Z Setting original file name "schtasks.exe" for "\?\c:\windows\system32\schtasks.exe", hr=0x0

    Internal signature match:subtype=Lowfi, sigseq=0x0000157EF20D1A7C, sigsha=aa5b9372f0ec225d6342e12ffb9db40b90cfd590, cached=false, source=0, resourceid=0x399405b1

    Engine:

    2023-08-31T19:02:41.303Z Setting original file name "vssadmin.exe" for "\?\c:\windows\system32\vssadmin.exe", hr=0x0

    Engine:

    2023-08-31T19:03:00.386Z Triggered AR EMS scan

    Engine:

    2023-08-31T19:03:00.386Z EMS scan for process: lsass pid: 668, sigseq: 0x0, sendMemoryScanReport: 0, source: 2

    Engine:

    2023-08-31T19:03:00.511Z EMS scan for process: svchost pid: 796, sigseq: 0x0, sendMemoryScanReport: 0, source: 2

    Engine:

    2023-08-31T19:03:00.594Z EMS scan for process: svchost pid: 892, sigseq: 0x0, sendMemoryScanReport: 0, source: 2

    Engine:

    2023-08-31T19:03:00.625Z EMS scan for process: svchost pid: 976, sigseq: 0x0, sendMemoryScanReport: 0, source: 2

    Engine:

    2023-08-31T19:03:00.747Z EMS scan for process: svchost pid: 1016, sigseq: 0x0, sendMemoryScanReport: 0, source: 2

    Engine:

    2023-08-31T19:03:00.832Z EMS scan for process: svchost pid: 428, sigseq: 0x0, sendMemoryScanReport: 0, source: 2

    Engine:

    2023-08-31T19:03:00.879Z EMS scan for process: svchost pid: 448, sigseq: 0x0, sendMemoryScanReport: 0, source: 2

    Engine:

    2023-08-31T19:03:00.973Z EMS scan for process: svchost pid: 1328, sigseq: 0x0, sendMemoryScanReport: 0, source: 2

    Engine:

    2023-08-31T19:03:01.051Z EMS scan for process: svchost pid: 1424, sigseq: 0x0, sendMemoryScanReport: 0, source: 2

    Engine:

    2023-08-31T19:03:01.098Z EMS scan for process: svchost pid: 1572, sigseq: 0x0, sendMemoryScanReport: 0, source: 2

    Engine:

    2023-08-31T19:03:01.145Z EMS scan for process: svchost pid: 1636, sigseq: 0x0, sendMemoryScanReport: 0, source: 2

    Engine:

    2023-08-31T19:03:02.922Z Setting original file name "powershell.exe" for "\?\c:\windows\system32\windowspowershell\v1.0\powershell.exe", hr=0x0

    Engine:

    2023-08-31T19:03:02.969Z Setting original file name "powershell.exe" for "\?\c:\windows\syswow64\windowspowershell\v1.0\powershell.exe", hr=0x0

    Internal signature match:subtype=Lowfi, sigseq=0x0000157E4A007D3D, sigsha=63c44c372481504bb7fb73e1489e29be34876793, cached=true, source=0, resourceid=0xa681fa81

    Internal signature match:subtype=Lowfi, sigseq=0x0000157EFE404EE0, sigsha=d305323f56f3cf14dec20fcc80a8b76d2197d0db, cached=false, source=0, resourceid=0xbfe8f9b7

    2023-08-31T19:03:27.246Z [Cloud] Engine is requesting config to do cloud query [regular network].

    Internal signature match:subtype=Lowfi, sigseq=0x0000157EECC7829F, sigsha=988df01ffc332e9c60addbbe1c74b85f43b49817, cached=true, source=0, resourceid=0x0179b885

    Internal signature match:subtype=Lowfi, sigseq=0x00005BE7D967BD5A, sigsha=5a4d1a98d2a4cf463a562f95fc9eb8bb83207c6f, cached=false, source=0, resourceid=0x3c04fe46

    2023-08-31T19:03:41.423Z [Cloud] Engine is requesting config to do cloud query [regular network].

    2023-08-31T19:03:41.423Z Service stop requested (ServiceError: 0x0). Calling CleanupMpService ...

    2023-08-31T19:03:41.663Z Unloaded module#0 MpComServer.

    Microsoft Antimalware (F7F4CD20-7371-4319-B1DB-6FCFC68573EC) Log

    Stopped On 08-31-2023 19:03:41 (Exit Code = 0x0)

    ************************************************************

    La risposta è stata utile?

    0 commenti Nessun commento
  3. Anonimo
    2023-08-31T17:04:58+00:00

    crashata al 91% con 47000 file scansionati circa, dove trovo il log?

    La risposta è stata utile?

    0 commenti Nessun commento
  4. Spigolo 136.2K Punti di reputazione Moderatore volontario
    2023-08-31T14:36:47+00:00

    Windows Defender si è bloccato così

    Effettua una scansione offline e vedi se la porta a termine.

    La risposta è stata utile?

    0 commenti Nessun commento
  5. Spigolo 136.2K Punti di reputazione Moderatore volontario
    2023-08-31T14:33:45+00:00

    Vabbè...comunque per essere più sicuro con l'EFI/CompuTrace.A voglio cambiare scheda madre.

    Nessun virus sopravvive a una reinstallazione pulita, con eliminazione delle partizioni.

    Nello specifico, si tratta solo di un'applicazione potenzialmente indesiderata, nulla di veramente pericoloso.

    La risposta è stata utile?

    0 commenti Nessun commento