各位大神,麻烦给看下,我已经在applocker中将e:\tool\OCR\*.*添加了例外,为什么还会阻止e:\tool\OCR\screencapture.exe,下面是事件查看器中日志信息?不胜感激
日志名称: Microsoft-Windows-AppLocker/EXE and DLL
来源: Microsoft-Windows-AppLocker
日期: 2023/8/9 9:24:23
事件 ID: 8004
任务类别: 无
级别: 错误
关键字:
用户: Lenovo-47343683\Administrator
计算机: Lenovo-47343683
描述:
已阻止运行 E:\TOOL\OCR\SCREENCAPTURE.EXE。
事件 Xml:
<Event xmlns="schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-AppLocker" Guid="{cbda4dbf-8d5d-4f69-9578-be14aa540d22}" />
<EventID>8004</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2023-08-09T01:24:23.219415000Z" />
<EventRecordID>128507</EventRecordID>
<Correlation />
<Execution ProcessID="1972" ThreadID="2624" />
<Channel>Microsoft-Windows-AppLocker/EXE and DLL</Channel>
<Computer>Lenovo-47343683</Computer>
<Security UserID="S-1-5-21-3393222883-2054421826-3838164142-500" />
</System>
<UserData>
<RuleAndFileData xmlns="schemas.microsoft.com/schemas/event/Microsoft.Windows/1.0.0.0">
<PolicyNameLength>3</PolicyNameLength>
<PolicyName>EXE</PolicyName>
<RuleId>{ec119b2e-1a54-4a27-a6b3-c0176cad2729}</RuleId>
<RuleNameLength>69</RuleNameLength>
<RuleName>签名人 O=BEIJING SOGOU TECHNOLOGY DEVELOPMENT CO., LTD., S=BEIJING, C=CN</RuleName>
<RuleSddlLength>145</RuleSddlLength>
<RuleSddl>D:(XD;;FX;;;S-1-1-0;((Exists APPID://FQBN) && ((APPID://FQBN) >= ({"O=BEIJING SOGOU TECHNOLOGY DEVELOPMENT CO., LTD., S=BEIJING, C=CN\*\*",0}))))</RuleSddl>
<TargetUser>S-1-5-21-3393222883-2054421826-3838164142-500</TargetUser>
<TargetProcessId>808</TargetProcessId>
<FilePathLength>29</FilePathLength>
<FilePath>E:\TOOL\OCR\SCREENCAPTURE.EXE</FilePath>
<FileHashLength>32</FileHashLength>
<FileHash>7AF1D682BFA15CE94ABB19B142B39A07B45CBE7A8FFA06C755A17DC710D68CCC</FileHash>
<FqbnLength>98</FqbnLength>
<Fqbn>O=BEIJING SOGOU TECHNOLOGY DEVELOPMENT CO., LTD., S=BEIJING, C=CN\屏幕截图\SCREENCAPTURE.EXE\1.0.0.220</Fqbn>
<TargetLogonId>0x1bf82e</TargetLogonId>
<FullFilePathLength>29</FullFilePathLength>
<FullFilePath>E:\tool\OCR\screencapture.exe</FullFilePath>
</RuleAndFileData>
</UserData>
</Event> |