Analysé par: Mc Justine De Guzman   

 

HEUR:RiskTool.Win32.ProcHack.gen (KASPERSKY)

 Plate-forme:

Windows

 Overall Risk:
 Dommages potentiels:
 Distribution potentielle:
 Infection signalée:
 Information Exposure Rating:
Faible
Medium
Élevé
Critique

  • Type de grayware:
    Potentially Unwanted Application

  • Destructif:
    Non

  • Chiffrement:
     

  • In the wild:
    Oui

  Overview

It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  Détails techniques

File size: 1,719,840 bytes
File type: EXE
Date de réception des premiers échantillons: 05 janvier 2021

Précisions sur l'apparition de l'infection

It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Autres précisions

Il fait ce qui suit:

  • It accepts the following parameters:
    • -settings {filename of settings file} -> allows the user to specify the location of Process Hacker's settings file
    • -nosettings -> sets the settings to their defaults at startup, and no settings are saved
    • -noplugins -> disables plugins, even if the "Enable plugins" option is set
    • -newinstance -> starts a new instance of Process Hacker, even if the "Allow only one instance" option is set
    • -v -> forces Process Hacker's main window to be displayed at startup, even if the "Start hidden" option is enabled.
    • -hide -> hides Process Hacker's main window at startup, even if the "Start hidden" option is disabled
    • -elevate -> prompts for elevation if Process Hacker is not started with elevated privileges.
    • -c -ctype objecttype -cobject object -caction action -cvalue value -> enables command mode
      • Possible values of objecttype:
        • process
        • service
        • thread
      • Possible values of object:
        • process ID
        • service name
        • thread ID
      • Possible values of action:
        • For process:
          • terminate
          • suspend
          • resume
          • priority
          • iopriority
          • pagepriority
        • For service:
          • start
          • continue
          • pause
          • stop
          • delete
        • For thread:
          • terminate
          • suspend
          • resume
    • -s -> enables silent mode, no error messages are displayed for command mode, -installkph and -uninstallkph
    • -ras -> enters run-as-service mode
    • -nokph -> disables KProcessHacker, Process Hacker will not attempt to load the driver or connect to it
    • -installkph -> installs KProcessHacker as a System Start service
    • -uninstallkph -> deletes the KProcessHacker service
    • -debug -> shows the debug console early in the startup process
    • -showoptions -hwnd parentwindow -point x,y -> displays the Advanced tab of the options window only. parentwindow specifies the parent window handle in hexadecimal and x,y specifies the location of the options window.
    • -phsvc -> enters phsvc mode which exposes a LPC-based API currently used by Process Hacker for tasks that require elevation.
    • -priority r|h|n|l -> sets the priority of Process Hacker to realtime (r), high (h), normal (n) or idle (l).
    • -selectpid pid -> selects pid in a new or existing instance of Process Hacker.
    • -sysinfo section -> opens the System Information window at startup, and optionally navigates to the specified section.
  • It has the following display:
  • Due to its side-loading vulnerability, this tool has been abused by other malware to kill security-related software by loading a stager DLL via DLL search order hijacking.

  Solutions

Moteur de scan minimum: 9.800
SSAPI Pattern File: 2.373.00
SSAPI Pattern Release Date: 27 janvier 2021

Step 1

En cas d"utilisation de Windows ME ou XP, avant de procéder à un scan, assurez-vous de désactiver l’option de restauration du système afin que l’opération de scan soit complète sur votre ordinateur.

Step 2

Note that not all files, folders, and registry keys and entries are installed on your computer during this malware's/spyware's/grayware's execution. This may be due to incomplete installation or other operating system conditions. If you do not find the same files/folders/registry information, please proceed to the next step.

Step 3

Effectuez un scan de l’ordinateur à l’aide de votre produit Trend Micro pour supprimer les fichiers spécifiés comme étant PUA.Win64.ProcHack.AC Si les fichiers détectés ont déjà été nettoyés, supprimés ou placés en quarantaine par votre produit Trend Micro, aucune autre procédure n"est nécessaire. Vous pouvez simplement choisir de supprimer les fichiers en quarantaine. Veuillez consulter cette page de base de connaissances pour plus d"informations.


Participez à notre enquête!