f3x
December 10th, 2005, 09:22 PM
I did some forum seach but it look like somtething everyone already know or doesnt bother knowing.
First i caugth svchost.exe that was trying to do
[memory protect] on internet explorer
Then when i was playing in the menus of intenet explorer it promted me for MSG GLOBAL HOOK each time i changed of menu (File, Edit, .... )
That anoyed me so i put alwais accept.. after all teh stric minimum i should be able to do is to use the software without interuption on each click.
But then i realised that this would allow iexplore to do more advanced thing like [memory protect] or other thing even worse that i dont know of (since i'm sure that memory protect was innofensive)
Anywais you get the point ... just to be able to browse the menu I give really powerfull rigths to iexplore. And we all know iexplore and explorer are kind of trojan horse ( the are not viruses but every action made by a ie toolbar or a explorer add-on get charged on the ie/explorer process so behind a conforting know figure migth hide a malware )
Rigth now i really feel like process modification is a "everything else" category that migth gain from being split to more better organised categorie. ( ie Global Hooks, Memory management, etc)
Aside from that i have two question. Anyone know what are " all " the actions covered by this "process modification" category, what else is there after hooks? and my second question ... what are the meaning of the different global hooks intercepted by appDefend ? some are obvious like mouse / keyboard ... other are way less
First i caugth svchost.exe that was trying to do
[memory protect] on internet explorer
Then when i was playing in the menus of intenet explorer it promted me for MSG GLOBAL HOOK each time i changed of menu (File, Edit, .... )
That anoyed me so i put alwais accept.. after all teh stric minimum i should be able to do is to use the software without interuption on each click.
But then i realised that this would allow iexplore to do more advanced thing like [memory protect] or other thing even worse that i dont know of (since i'm sure that memory protect was innofensive)
Anywais you get the point ... just to be able to browse the menu I give really powerfull rigths to iexplore. And we all know iexplore and explorer are kind of trojan horse ( the are not viruses but every action made by a ie toolbar or a explorer add-on get charged on the ie/explorer process so behind a conforting know figure migth hide a malware )
Rigth now i really feel like process modification is a "everything else" category that migth gain from being split to more better organised categorie. ( ie Global Hooks, Memory management, etc)
Aside from that i have two question. Anyone know what are " all " the actions covered by this "process modification" category, what else is there after hooks? and my second question ... what are the meaning of the different global hooks intercepted by appDefend ? some are obvious like mouse / keyboard ... other are way less