Announcement

Collapse
No announcement yet.

firewall/HIPS

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • firewall/HIPS

    My firewall/HIPS program flags some suspicious behaviour from wirelessMon:

    - 'WirelessMon want to connect to another computer'
    - 'WirelessMon wants direct disk access'
    - 'WirelessMon wants to remotely control Explorer.exe'
    And on when closing the program:
    - 'WirelessMon wants to start an unknown process: ?????|?|? '
    then:
    - '/system32/?????.cmd wants to run'

    I can understand the first one, if WM needs to hook into the network card at low level, but then there are no firewall rules created for it and it doesn't show up in the list of allowed programs, like it's doing something sneaky to hide itself from being monitored by my firewall.

    Plus no other program I have unexpectedly triggers warnings like these. Can anyone explain why WirelessMon wants/needs these unusual permissions; techniques that a virus or rootkit would normally use? And what is the *.cmd thing on exit?

    Thanks.

  • #2
    What version of the Wireless software are you using and did you download it from our site, or elsewhere?

    What Firewall / HIPS solution are you using?

    When did it trigger these warnings? Except for the script you didn't mention if it was at startup or at another time, like when you tried to connect to a remote access point.

    Was "?????|?|?" the actual text that appeared on the screen. Or did you replace the real text with ???, If so what was the real text of the warning.

    I don't know under what conditions your software displays these warnings. But WirelessMon is a networking program, that writes logs to the disk. Which might account for the first two messages. I can't really comment on the other two as we don't have enough details.

    What I can assure you of is that a) we do nothing to hide any of the functions of the software, b) it doesn't need any unusual permissions to run c) there is nothing rootkit like in its behaviour d) it doesn't contain any malware. But it does use some low level functions to get access point lists etc from the network card.

    Comment


    • #3
      On startup WirelesssMon stops the Windows Zero Config (WZCSVC) service, otherwise it can't gain access to the network card, and on exit will attempt to restart the service. It's possible this is what's triggering the warnings.

      Comment

      Working...
      X