Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Did Process Guard stop the Sony rootkit?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Critical IE security flaw: executes code »
« Tracking PC's Over the Internet  
AuthorAll Replies


Wayne DCS
Premium
join:2001-12-07
Australia

reply to tempnexus
Re: Did Process Guard stop the Sony rootkit?

 
Click for full size
Yes! ProcessGuard easily stops it - at many levels, and has had this capability for well over a year.

If you want to allow the rootkit to install you actually have to tell ProcessGuard to allow the execution of several different programs and also the installation of a couple of drivers (you'd probably be suspicious of what is installing by this stage ) in order for the installation to complete and the rootkit to install. If you simply say No to any of these you'll disrupt the installation process and the rootkit driver won't install.

We'll add some more comprehensive info about this to the ProcessGuard website soon, but I'll attach a couple of screenshots.

The first screenshot is what you see when you first put the CD in your machine, when autorun is enabled. Autorun.exe is launched, and ProcessGuard asks you if you want to allow it.

At this stage you could simply click No, and ProcessGuard would block it from running and that's that - the installation process has been blocked, so even at that early stage it's easy to block it. However for this demo we'll say Yes to everything, to essentially allow the full installation so that we can monitor everything that happens.

The second image shows one of the popup balloon windows youll see when a program attempts to install a driver.

The third image is a composite of two images that were taken after allowing everything to install - you can see that the installation is quite vigorous, and we had to say Yes (Permit execution/installation) a lot of times.

If you do permit everything to install then you will have installed the rootkit. The fourth image shows some of these files.

Forums » Up and Running » Security » SecurityCritical IE security flaw: executes code »
« Tracking PC's Over the Internet  


Tuesday, 10-Nov 19:48:48 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [116] Moto Sold About 100,000 Droids
· [93] Verizon Keeps Swinging At AT&T
· [86] VoIP Over 3G Still Not Working For iPhone
· [64] Government Will Release Some Telco Wiretap Lobbying Documents
· [55] Verizon's Hanging Up On Rural America
· [34] Bill Would Force ISPs To Block Financial Scams
· [32] Verizon's Higher ETFs Annoy Senator
· [25] Sprint Announces Job Cuts
· [24] Mediacom Hints At 50, 100 Mbps Speeds
· [21] Google Offers Free Holiday Airport Wi-Fi
Most people now reading
· Holy work line speeds!! [TekSavvy]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· Fishing [World of Warcraft]
· Massive Slowdowns? [cover,1584]
· Comcast Clear QAM Basic Cable $12.99/month [Comcast Cable TV]
· Windows 7 boot manager editing questions [Microsoft Help]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Slow speed lately? [TekSavvy]
· Spelling error on Bud Light commercial [Rants, Raves, and Praise]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]