[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-Disclosure] "Sample" not running but preventing Win2k from Shutdown
- To: "Marcel Krause" <marcel_k@xxxxxx>, "Full Disclosure" <full-disclosure@xxxxxxxxxxxxxxxx>
- Subject: Re: [Full-Disclosure] "Sample" not running but preventing Win2k from Shutdown
- From: "Aditya, ALD [ Aditya Lalit Deshmukh ]" <aditya.deshmukh@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Sun, 27 Jun 2004 06:39:08 +0530
> I was fishing for some nice MSIE "plugins" on some porn sites and
> found a mysterious one. It does not appear anywhere, neither in my
> Firewall nor as a toolbar, and there is no new process running on
> the sandbox machine. But whenever I try to shut it down or reboot
> it, an application called "sample" does not want to terminate
> voluntarily. As said before, there is no such app in the process
> list before shutting down, and there is no unknown sample*.* file
> on any of the sandbox'es hard disks. Does anyone know this "sample"?
in win2k there an api which makes the process invisible. can you get the the
exact plugin that is causing this. internet explorer has some browser objects
that have access to all the to what ever IE has and there might be no visible
tool bar ie it might be 1X1 pixels big. so you see nothing and there is no
listed process as it is a partof internet explorer. is IE running all the time
?
it also might be a out of process com server creeated by ie that reefuses to
shut down.
the sample*.* does not exist because it might be sprawned by some other process
and clenaed up on execution or the sample might be the "window title" param and
not the file name. please get a program that maps the programs that are running
to file names on disk and that should be able to get what is going on ....
-aditya
ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ
éb½êÞvë"?axZÞx÷«²?Ú?Gb¶*'¡ó?[kj¯ðÃæj)mªÿr?ÿ
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html