發新話題
打印

[分享] TO: Roger 關於 prueba.exe

TO: Roger 關於 prueba.exe







EXPLORER.EXE 透過 HOOK  調用 IE  是不是很奇怪

這支不准 HOOK就失效了 並  並請 HIPS 自動建立此新規則 結束進程



  Activity control rule
            Name: 
           
            Application
            Parent process Identifier: 2588
            Parent process: EXPLORER.EXE
            Process identifier: 316
            File: C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
            User Identifier: XPSM1210\peter
            Hook type: 0
            Thread for event iterception: 0


           
            Technical description
           
            The SetWindowsHookEx installs a hook into the system hook chain.  A hook is a point in the system message-handling mechanism where an application can install a subroutine to monitor the message traffic in the system and process certain types of messages before they reach the target window procedure.  This subroutine will be called every time an event occurs (receiving a notification, pressing a key on the keyboard, opening a dialog box, etc.). This function is mainly used by special software for monitoring user activities.
            However, spyware applications can install their own event interceptors to steal confidential data from a personal computer user.
            Therefore, if the application is unknown to you, block any activity by this application.
            User action:    Block, Remember this decision Always (create the rule)
           use event's parameters for creating a new rule
            Kill the application after blocking


[ 本帖最後由 peter_yu 於 2007-8-30 23:41 編輯 ]

TOP

ProSecurity  攔的更前面  完全 OK    SNS  成功一半


prueba.exe
[DEBUG AT SYSTEM LEVEL]              
[BLOCK]                                E:\Test\prueba.exe
                                        Command Line:"E:\Test\prueba.exe"
[ACCESS TO]                            Access: SysDbgCopyMemoryChunks_0

[ 本帖最後由 peter_yu 於 2007-8-31 00:03 編輯 ]

TOP



 

 

1.關鍵步驟,在於COMODO必須阻止運行ntoskrnl.exe,才能防得住這隻!

不過詢問框不是紅色,應該代表不在默認規則中,一般人會允許!

不過,一旦允許,鼠標可動,點擊東西瘸沒有反應,很像系統假死,

只好強制重啟了!

2.EQ必須阻止"Debug at system level"(直接操作系統內核),

才能阻止prueba.exe修改explorer.exe的進程內存!

順便附上prueba.exe在附件

已經有人上報給COMODO了!

[ 本帖最後由 Roger 於 2007-8-31 00:09 編輯 ]
附件: 您所在的用戶組無法下載或查看附件

TOP

發新話題