Detection of hiding a process by HIPS

Discussion in 'other anti-malware software' started by aigle, Jul 18, 2008.

Thread Status:
Not open for further replies.
  1. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Seems an interesting filter that is present in ThreatFire. Any othet HIPS can do this? I tried CFP and there were no alarms. GesWall of course stopped it.
     

    Attached Files:

  2. baerzake

    baerzake Registered Member

    Joined:
    Aug 18, 2007
    Posts:
    44
    where is the download link?
     
  3. Pseudo

    Pseudo Registered Member

    Joined:
    May 4, 2008
    Posts:
    193
  4. baerzake

    baerzake Registered Member

    Joined:
    Aug 18, 2007
    Posts:
    44
    thank you
     
  5. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    A2's IDs does that (Mamutu), the HIPS of Rising checks by default for every hour on hidden processes (which is not so strong as TF and Mamutu).
     
  6. bman412

    bman412 Registered Member

    Joined:
    Mar 4, 2008
    Posts:
    261
    A2 didn't block the processes from being hidden but will prompt the user for driver installation when HideProc.exe is run.
     

    Attached Files:

  7. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    IS because it is initiated via a user interaction A2 with IDS will warn for processes going under (hiding) tested with real malware so 100% sure on that
     
  8. rolarocka

    rolarocka Guest

    Wow i get a BSOD with IRQ LESS... problem running this program. What a fast way to turn off my pc lol.
     
  9. HURST

    HURST Registered Member

    Joined:
    Jul 20, 2007
    Posts:
    1,419
    Just tested with SandboxIE. As expected, no alert, but hiding process is NOT SUCCESFULL.
    Once again, SBIE passes the test.:D
     
  10. korb

    korb Registered Member

    Joined:
    Mar 13, 2006
    Posts:
    150
    Location:
    singapore-thailand
    EQ and drive sentry not no alert to it. btw geswall free also no alert to it
     
  11. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    GesWall will not alert as it,s not a classical HIPS. It will just stop it from hiding the process.
     
  12. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Can you post a screenshot? Strangely no alert from CFP about driver loading.
     
  13. tepe2

    tepe2 Registered Member

    Joined:
    Jan 18, 2006
    Posts:
    558
    I hope OA also pass this one. (I do not always use SBIE)
     
  14. subset

    subset Registered Member

    Joined:
    Nov 17, 2007
    Posts:
    825
    Location:
    Austria
    HideProc can hide processes without OA prompts, if the HideProc.exe is Unknown or Trusted in OA Programs, even if the driver HideProcDrv.sys is Unknown.
    If you use Run safer for HideProc.exe, then OA blocks all attempts to hide processes.

    But there is no single prompt from OA (paid) related to the Process > Hide operation from HideProc.

    Cheers
     
    Last edited: Jul 20, 2008
  15. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Even for driver install/ loading?
     
  16. bman412

    bman412 Registered Member

    Joined:
    Mar 4, 2008
    Posts:
    261
    here's the pop up alert from a2
     

    Attached Files:

  17. subset

    subset Registered Member

    Joined:
    Nov 17, 2007
    Posts:
    825
    Location:
    Austria
    There are no prompts about process hiding.
    But of course there are prompts about driver installing and loading.

    HideProcDrvAutorun.png

    HideProcDrvRun.png

    Cheers
     
  18. BILL G

    BILL G Registered Member

    Joined:
    Nov 16, 2004
    Posts:
    80
    Location:
    MN USA
    I get 2 Alerts from PG; 2 from GSS and 1 from TF.
     
  19. erreale

    erreale Registered Member

    Joined:
    May 2, 2004
    Posts:
    27
    Location:
    Italy
    3 allert from ProSecurity. Test passed:D
     
  20. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    What were the alets?
     
  21. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Hi,

    Anyone willing to test SSM Pro? I wonder if it could spot the hidden process. I will check it out later. And keep in mind guys, if you stop the driver from loading, of course the test won´t work, I think you need to allow the driver to load and then see how HIPS react.
     
  22. zopzop

    zopzop Registered Member

    Joined:
    Apr 6, 2006
    Posts:
    642
    hey aigle, i tired testing this app against rising AV/hips but all i got was a BSOD.
     
  23. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    hmmmm... so there was a conflict.
     
  24. Pedro

    Pedro Registered Member

    Joined:
    Nov 2, 2006
    Posts:
    3,502
    It needs admin rights.
    With admin rights (..) SSM pro detects the driver loading, but not the hiding of notepad.
    At least with default rules, i don't know if there's something to tweak in SSM. I installed it in VM for the purpose.
     
  25. subset

    subset Registered Member

    Joined:
    Nov 17, 2007
    Posts:
    825
    Location:
    Austria
    It seems to be not really clear.
    "3 allert from ProSecurity." sounds like HideProc starts, then the driver is installed and loads.

    But only to detect the hiding process seems to be the objective of this test.

    Cheers
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.