Thank you for testing. You mentioned that CIS had passed all but stop 2. I am wondering what pop-up dialogs appeared when you run htaab, and did htaac terminate the explorer.exe? Did stop lock you mouse?
Remeber Im running CIS on Maximum security setting
i made!
Config: Proactive
Firewall: Safe Mode
(all settings on)D+ : Paranoid Mode
(all settings on)Oh and im on Windows XP Media Center!
It tryed to access all of this in this oder!
Htaaa ------> imm32.dll ----->(again) imm32.dll ------> \Device\KseDD ----->guard32.dll (failed to act)
Htaac ------> imm32.dll ----->(again) imm32.dll ------> \Device\KseDD ----->guard32.dll (failed to act)
Htaab ------> imm32.dll ----->(again) imm32.dll ------> \Device\KseDD ----->guard32.dll (failed to act)
Stop ------> imm32.dll ----->(again) imm32.dll ------> \Device\KseDD ----->guard32.dll (failed to act)
Limited user account (non admin) Had no effect they still tryed to lunch!
imm32.dll is a library used by the Microsoft Windows Input Method Manager (IMM).
DO not DELETE imm32.dll its critical to windows working ok With Imm32.dll blocked! (just blocked for one login)
It tryed to access all of this in this oder!
Htaaa ----->Device\KseDD -----> guard32.dll (failed to act)
Htaac ----->Device\KseDD -----> guard32.dll (failed to act)
Htaab ----->Device\KseDD -----> guard32.dll (failed to act)
Stop ----->Device\KseDD -----> guard32.dll (failed to act)
DO not DELETE imm32.dll its critical to windows working ok I will keep all of you updated on STOP2.exe Testing! What a nasty exploit!
STOP2 update:stop2 -----> imm32.dll -----> gaurd32.dll (worked)
With Imm32.dll off:
stop2 -----> gaurd32.dll (worked)
With Policy Isolated Application: IT STILL WORKED
My Blocked Files STOPS ITI
opened Stop2 In Notepad and it said on topline
"This program must be run under Win32" (i dont have a 64-bit to test on) Yes OR No?Also it has these DLL's meationed in the Notepad:
NEL32.DLL advapi32.dll user32.dllAnd it also said: Boÿûÿÿrland Edition © 2004,5 PierîoËÿre le Rich/rofessI have tryed everything I could THINK of!!!!
D+ has LOST a MATCH! against STOP2