三步抓住 HOOK 這支無效 抓住 HOOK 鉤子才是正確的
2007/9/23 上午 12:11:09 !**************************************************
Safe'n'Sec alert
Action
Date and time: 2007/9/23 上午 12:10:59
Type: Editing a file/folder
Risk: Moderate
Application
Process identifier: 1420
Parent process identifier: 3676
User identifier: XPSM1210\peter
File: C:\13\SHOW\SNOWN.EXE
Object
File/folder:C:\WINDOWS\SYSTEM32\SNOWNCLEAN.EXE
User action: Allow
***************************************************
2007/9/23 上午 12:11:13 !**************************************************
Safe'n'Sec alert
Action
Date and time: 2007/9/23 上午 12:11:09
Type: Editing a file/folder
Risk: Moderate
Application
Process identifier: 1420
Parent process identifier: 3676
User identifier: XPSM1210\peter
File: C:\13\SHOW\SNOWN.EXE
Object
File/folder:C:\WINDOWS\SYSTEM32\SNOWNCLEAN.EXE
User action: Allow
***************************************************
2007/9/23 上午 12:11:21 !**************************************************
Safe'n'Sec alert
Action
Date and time: 2007/9/23 上午 12:11:14
Type: Installation of a hook
Risk: High
Activity control rule
Name:
Application
Parent process Identifier: 3676
Parent process: TOTALCMD.EXE
Process identifier: 1420
File: C:\13\SHOW\SNOWN.EXE
User Identifier: XPSM1210\peter
Hook type: 13
Thread for event hook: 0
Technical description
The SetWindowsHookEx function allows defining a function that will be called every time an event occurs (receiving a notification, pressing a key on the keyboard, opening a dialog box, etc.). This function is mainly used by special software for monitoring user activities.
However, spyware applications can install their own event hooks to steal confidential data from a personal computer user.
Therefore, if the application is unknown to you, block any activity by this application.
User action: Block
Block 順便讓 SNS KILL 進程 根本過不去

***************************************************
[
本帖最後由 peter_yu 於 2007-9-23 00:31 編輯 ]