Full Disclosure mailing list archives

Re: "Sample" not running but preventing Win2k from Shutdown


From: "Aditya, ALD [ Aditya Lalit Deshmukh ]" <aditya.deshmukh () online gateway technolabs net>
Date: Sun, 27 Jun 2004 06:39:08 +0530

I was fishing for some nice MSIE "plugins" on some porn sites and
found a mysterious one. It does not appear anywhere, neither in my
Firewall nor as a toolbar, and there is no new process running on
the sandbox machine. But whenever I try to shut it down or reboot
it, an application called "sample" does not want to terminate
voluntarily. As said before, there is no such app in the process
list before shutting down, and there is no unknown sample*.* file
on any of the sandbox'es hard disks. Does anyone know this "sample"?

in win2k there an  api which makes the process invisible. can you get the the exact plugin that is causing this. 
internet explorer has some browser objects that have access to all the to what ever IE has and there might be no 
visible tool bar ie it might be 1X1 pixels big. so you see nothing and there is no listed process as it is a partof 
internet explorer. is IE running all the time ? 

it also might be a out of process com server creeated by ie that reefuses to shut down. 

the sample*.* does not exist because it might be sprawned by some other process and clenaed up on execution or the 
sample might be the "window title" param and not the file name. please get a program that maps the programs that are 
running to file names on disk and that should be able to get what is going on ....


-aditya
ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ
éb½êÞvë"žaxZÞx÷«²‰Ú”Gb¶*'¡óŠ[kj¯ðÃæj)m­ªÿr‰ÿ

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: