PDA

View Full Version : PCAudit question


SimonW
February 22nd, 2004, 11:16 AM
Hi,
Can someone please explain to a beginner, why LnS fails to catch PCAudit? I'm using the 2.05 beta and have the enhanced ruleset loaded. I have enabled DLL detection in the advanced optoins.
My usage up to now has been to allow applications that I know need access to the web (obviously IE being the main one). Is this why PCAudit gets through - because IE is a 'trusted' application?

Thanks for your help...

Phant0m
February 22nd, 2004, 11:42 AM
Hey SimonW

You in reference to pcAudit v2 right?

SimonW
February 22nd, 2004, 12:05 PM
No - just the standard PCAudit :(
- I understand that no firewall can stop PCAudit2...

Phant0m
February 22nd, 2004, 12:32 PM
Hey SimonW

Hmmm Look ‘n’ Stop v2.05b1 sees the pcAudit v3.0.0.3 .DLL and successfully blocks it, pcAudit v3.0.0.3 fails on my System with Windows XP.

gkweb
February 22nd, 2004, 12:35 PM
With LNS 2.05 beta1, just enable the DLL components control.

Phant0m
February 22nd, 2004, 12:42 PM
"* I have enabled DLL detection in the advanced optoins. *" ;)

SimonW
February 22nd, 2004, 02:01 PM
Thanks for your help - I've realised my problem :-[

All these sites
http://www.hot4down.com/21/software_3002-2144-9034374.htm
http://www.lencom.com/desc/indexN16919.html
http://download.com.com/3001-2144-9034374.html

refer to the file to be downloaded as PCAudit v1.0

and to a newcomer like myself I didn't realise that what is actually being downloaded was v2.0...

this site
http://www.pestpatrol.com/pestinfo/p/pcaudit.asp

clearly shows screenshots of each version. The app itself doesn't clearly identify a difference, and it was only when checking file versions from Phant0m 's post that I guessed something was wrong

And, when I run this, LnS does identify the process correctly.

Once again, thanks for the help...

Phant0m
February 22nd, 2004, 02:11 PM
:D

gkweb
February 22nd, 2004, 02:34 PM
If you want correct leaktests names, may be you can take a look to my website ;) (in the sig).

SimonW
February 22nd, 2004, 02:44 PM
gkweb -
Excellent site - test info is very useful.

If only I'd checked your site first... :)

Kevin_b_er
February 22nd, 2004, 06:20 PM
Ok, I take back whatever I'd previously said

The thing is crafty pos.

I had task manger, the program to trap my keyboards specialty buttons, and winrar try to connect to the internet.

Its a nasty form of DLL Injection which LnS isn't trapping....