« What's the suspicious Rundll32.exe processMicrosoft Sets Record With Monster Patch Tuesday »

Green Dam-Youth Escort

 'Green Dam-Youth Escort' Software

Applicability

Current versions only support Windows; effective only when used in conjunction with Internet Explorer or Google Chrome, it has no effect when used with Firefox. The harmful information screened by the software includes politically-related harmful information, and the software relies on non-conventional methods to install, also ineffective within Firefox, closing the browser and adding the website address onto a banned list without confirmation. In Internet Explorer, the software's ability to classify clearly political content as "harmful information" is unreliable; for pornographic content, Green Dam is able to make relatively accurate assessments. When used with Firefox, however, the software shows no response.

Application control and filtering

Screening of anticircumvention software, such as FreeGate. In system32 there can be found a filtport.dat file whose default content reads: FreeGate/8567/tcp Urf/9666/tcp. Two processes, xdaemon.exe and xnet2.exe, upon entering FreeGate will......
Following evaluation, three applications, XDaemon.exe, XNet2.exe and gn.exe, can be seen to be protecting one another, preventing each process from being deleted or interrupted, a kind of technique used by malware...

Possibly monitored programs (found in injlib.exe, offset 89e8H):

editplus.exe
uedit32.exe
emeditor.exe
wordpad.exe
notepad.exe
wps.exe
wpp.exe
et.exe
powerpnt.exe
frontpg.exe
excel.exe
msaccess.exe
outlook.exe
winword.exe
mailmagic.exe
popo.exe
qqmail.exe
aixmail.exe
imapp.exe
incmail.exe
msimn.exe
dm2005.exe
foxmail.exe
googletalk.exe
miranda32.exe
imu.exe
ypager.exe
tmshell.exe
start.exe
uc.exe
icqchatrobot.exe
qq.exe
msnmsgr.exe
gsfbwsr.exe
greenbrowser.exe 
touchnet.exe 
theworld.exe 
maxthon.exe 
ttraveler.exe 
netscp.exe 
ge.exe 
firefox.exe 
opera.exe 
netcaptor.exe 
myie.exe 
iexplore.exe 
mmc.exe 
regedit.exe 
taskmgr.exe

 
mpsvcc.exe 
xdaemon.exe 
xnet2.exe
 
Internet filtering
"Green Dam" utilizes the Winsock2 SPI port to obtain data from both sender and recipient, and through analyzing these data, obtains http data. Having obtained http data protocol and run through a URL detector, a harmful URL detector and a keyword detector, Green Dam decides based on those results whether or not image detection is needed, and through image detection, addresses of websites containing harmful information are delivered to system management.

A Technical Analysis of the 'Green Dam-Youth Escort' Software


  • Articles related:

Post comment:

◎welcome to give out your point。

Previous

Powered By Z-Blog 1.8 Spirit Build 80722 Code detection by Codefense

Copyright RUNDLL32.ORG. Some Rights Reserved.