Re: Using ZwCreateFile to Launch embedded exe

Tech-Archive recommends: Fix windows errors by optimizing your registry



This is going to be part of the security package that I am writing.
When it is executing, a user allows only the applications that they
want to execute. If any othe .exe tries to run that the user has not
allowed, then another .exe will execute in it's place. It is not
malware.

-Jay
(patelj27b at gmail dot com)


anton bassov wrote:
What a "driver that will replace a file that is executing with another
exe" is, apart from being just a piece of MALWARE???

Anton Bassov


.
Jay wrote:
Hey There,
I have some code that is written for a driver that will replace a
file that is executing with another exe. For most .exes it will work,
but for the executables that are, in essence, wrappers, like the
self-extracting zip file, will not work. What is different in the flow
of execution of a regular exe with one that is essentially just a
wrapper exe? Any information that can point me in the right direction
would be greatly appreciated!

-Jay
(patelj27b at gmail dot com)

.



Relevant Pages

  • Re: web based database
    ... That application is not running online. ... the users computer and executing from there. ... pushing the EXE to their system. ... the database and use something that identifies where ...
    (microsoft.public.vb.general.discussion)
  • RE: .Net Remoting problem: No connection could be made because the tar
    ... As you say, if the server isn't running, then you get the error message. ... Are you trying to start up and shut down a remoting exe at will, ... I am facing problem while executing the exe on ... > the remote machine. ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: web based database
    ... You website is hosted on a server hosting 756 other websites. ... damage you could do or information you could gain by executing an EXE on ... > the users computer and executing from there. ...
    (microsoft.public.vb.general.discussion)
  • Re: web based database
    ... You website is hosted on a server hosting 756 other websites. ... damage you could do or information you could gain by executing an EXE on ... > the users computer and executing from there. ...
    (microsoft.public.vb.general.discussion)
  • Re: IIS 6 and executables
    ... looks like our script is executing the file" ... How is the cgi-bin exe trying to serve the wraped exe as a download. ...
    (microsoft.public.inetserver.iis)