This article is a mirror article of machine translation, please click here to jump to the original article.

View: 36724|Reply: 7

[Technical Analysis] Rogue software haozip analysis

[Copy link]
Posted on 11/3/2018 11:20:30 AM | | | |
This morning, I turned on the computer to check the information on the Internet, and after a while, an advertisement for Double Eleven suddenly popped up on the desktop, and I didn't know that it was the advertisement that popped up by the software, as shown in the picture below:



I want to turn off this ad,I searched for a long time without the button off, my own computer, I don't have the permission to turn off ads? (This refers to the normal close button, please don't use technical killing processes to get rid of the horns)

In my opinion, this is a complete rogue behavior, a software, the user has no control over it, what is this not a rogue?

Let's take a look at which rogue company's software is it.

We open the Spy++ tool:



Through the "Find Window" function of the software, drag and drop the small circle to the "Double Eleven" adware interface. It shows that the process of the software is "Helper_Haozip", the process id is 0000337, the process id here is hexadecimal, to convert it to 10 processes, the process id after converting to decimal is 13176.



"Helper_Haozip" is a good software to guess, a piece of decompression tool developed by 2345 company, this company has always been a rogue company in my eyes, and it is not surprising that it can make such a disgusting advertisement!

The largest rogue on the 2345 network promotes mining tools through rogue software, turning users' computers into mining broilers.
The hyperlink login is visible.
(Source: 360 Community)


We use the PCHunter tool to find that the process id is 13176 and end the process, and the advertisement disappears immediately, as shown in the figure below:


Finally, decisively uninstall the good pressure software!

Article tool download

spy++:The hyperlink login is visible.
PCHunter:The hyperlink login is visible.





Previous:.net/c# assembly fails to load the dll solution for the network
Next:Shang Xuetang, Ma Soldier and many other gods detailed tutorial [300G resources allow you to learn enough...
Posted on 11/4/2018 8:13:24 AM |
I've been using good press, some of the tools in his toolbox are very easy to use, what compression software is there to replace good press?
Posted on 11/4/2018 1:53:53 PM |
Summer Posted on 2018-11-4 08:13
I've been using good press, some of the tools in his toolbox are very easy to use, what compression software is there to replace good press? ...
WinRAR v5.50 Chinese Simplified Registered No Ads No Modification Original (64-bit/32-bit)
https://www.itsvse.com/thread-4419-1-1.html
(Source: Architect_Programmer)
Use the above one.
Posted on 11/4/2018 4:23:54 PM |
Thank you scumbag, I also installed a good pressure, now there is a double 11 pop-up window every day when the computer is turned on, the pop-up window does not have a direct close button, all every time it is a click to open the browser to turn it off, 2345 is too rogue, 1 listed company forces us ordinary users to force us ordinary users to click on the pop-up every day to earn him click traffic money.
Posted on 1/6/2019 12:10:15 AM |
I blocked it directly
 Landlord| Posted on 5/29/2022 9:54:08 PM |
I recommend using Inspect instead of UISpy because with Inspect I was able to find the address bar. I switched to using the monitoring focus, then clicked on the address bar and Inspect to find it. Inspect is part of the Windows Toolkit and can be installed with the Windows 10 SDK.

Location: "C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x64\inspect.exe"
 Landlord| Posted on 9/25/2024 9:57:43 AM |
If your computer is equipped with VS 2022, you can open the spy++ software in "C:\Program Files\Microsoft Visual Studio\2022\Community\Common7\Tools\spyxx.exe".
 Landlord| Posted on 9/25/2024 10:08:40 AM |
Process Explorer tools are easier to find



ProcessExplorer.zip (3.3 MB, Number of downloads: 0, 售价: 5 粒MB)

Download Address:The hyperlink login is visible.

Disclaimer:
All software, programming materials or articles published by Code Farmer Network are only for learning and research purposes; The above content shall not be used for commercial or illegal purposes, otherwise, users shall bear all consequences. The information on this site comes from the Internet, and copyright disputes have nothing to do with this site. You must completely delete the above content from your computer within 24 hours of downloading. If you like the program, please support genuine software, purchase registration, and get better genuine services. If there is any infringement, please contact us by email.

Mail To:help@itsvse.com