PDA

View Full Version : Advanced Process Termination v1.9 released!


Wayne - DiamondCS
June 4th, 2004, 01:18 AM
Version 1.9 of APT (Advanced Process Termination) has been released, you can can download it here (http://www.diamondcs.com.au/downloads/apt.zip) (just 43kb - freeware).

This new build extends the number of termination methods (http://www.diamondcs.com.au/index.php?page=process-termination-methods) from 7 to 9, and includes the completely undocumented (http://www.google.com/search?q=WinStationTerminateProcess) WinStationTerminateProcess function.

There's no need for a Process Guard (http://www.diamondcs.com.au/processguard/) update as Process Guard already protects against all 9 termination methods. :)

Anti-hook capabilities have also been strengthened in this release, so if any trojans hook termination-related functions then APT will still be able to use those functions by bypassing the hooks. These anti-hook capabilities will also be included in TDS4.

We hope you enjoy this addition to your toolkit. :)

Pilli
June 4th, 2004, 05:10 AM
Thanks Wayne, I have tried against several Process Guard protected programmes with the necessary blocks and none were terminated by APT1.9
All were terminated when removed from the protected list, including Outpost, Task Manager, TDS3 & Port Explorer. :)

hojtsy
June 5th, 2004, 04:33 PM
I tested System Safety Monitor 1.9.4b1 against APT 1.9.
SSM catches Kill 1,3 and 5, and no other. I did not test Kill 9, as I already had Terminal Services disabled for good. This means SSM leaves big holes for trojans to terminate anything. So much for the SSM fans. It seems I will keep Process Guard :) even though it's instability. :(
-hojtsy-

Pilli
June 6th, 2004, 04:52 AM
-{ Quote: "It seems I will keep Process Guard :) even though it's instability " }-
It is true that a few people have stability issues with Process Guard but most do not. Jason is aware of these issues and will address them ASAP :)

SSM can always be added to PG's protection list.