Default/Deny and unusual file types?

When I used to develop government rootkits for Russia I used to mark the processes being protected by the rootkit as critical via RtlSetProcessIsCritical and laugh at the reactions from the live webcam when UK government officials terminated the processes and got landed with a BSOD crash. :D

This never really happened but that API does exist, but sometimes we need some humour :p
Your dark side! :p:D
 
I tried out NoVirusThanks ERP with a sample HTA file that I downloaded
http://www.htmlgoodies.com/legacy/beyond/reference/example.hta
I got a vulnerable process prompt (presumably because I manually added mshta to the list)
But after that, no prompt, no block, no nothing.
Looks like the ol' NVT EXE Radar Pro is true to its name: it monitors exe files.
 
  • Like
Reactions: Deleted member 2913

You may also like...