[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-Disclosure] "Sample" not running but preventing Win2k from Shutdown



> I was fishing for some nice MSIE "plugins" on some porn sites and
> found a mysterious one. It does not appear anywhere, neither in my
> Firewall nor as a toolbar, and there is no new process running on
> the sandbox machine. But whenever I try to shut it down or reboot
> it, an application called "sample" does not want to terminate
> voluntarily. As said before, there is no such app in the process
> list before shutting down, and there is no unknown sample*.* file
> on any of the sandbox'es hard disks. Does anyone know this "sample"?

in win2k there an  api which makes the process invisible. can you get the the 
exact plugin that is causing this. internet explorer has some browser objects 
that have access to all the to what ever IE has and there might be no visible 
tool bar ie it might be 1X1 pixels big. so you see nothing and there is no 
listed process as it is a partof internet explorer. is IE running all the time 
? 

it also might be a out of process com server creeated by ie that reefuses to 
shut down. 

the sample*.* does not exist because it might be sprawned by some other process 
and clenaed up on execution or the sample might be the "window title" param and 
not the file name. please get a program that maps the programs that are running 
to file names on disk and that should be able to get what is going on ....


-aditya
ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ
éb½êÞvë"?axZÞx÷«²?Ú?Gb¶*'¡ó?[kj¯ðÃæj)m­ªÿr?ÿ

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html