<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.eeye.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Game Troubleshooting</title><link>http://forums.eeye.com/forums/11.aspx</link><description>Answers for Questions, problems, or solutions involving integration of Blink Personal Edition in regards to PC Games.</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 SP1 (Build: 30415.43)</generator><item><title>Re: Restarting process and switching windows identity</title><link>http://forums.eeye.com/forums/thread/4598.aspx</link><pubDate>Fri, 24 Jul 2009 18:09:57 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4598</guid><dc:creator>lnicula</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4598.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=11&amp;PostID=4598</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;This could be a bug. We will attempt to reproduce and let you know.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Restarting process and switching windows identity</title><link>http://forums.eeye.com/forums/thread/4597.aspx</link><pubDate>Fri, 24 Jul 2009 04:48:01 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4597</guid><dc:creator>Zerosu</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4597.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=11&amp;PostID=4597</wfw:commentRss><description>&lt;p&gt;Ok,&lt;/p&gt;
&lt;p&gt;Thanks anyways for the help&lt;/p&gt;
&lt;p&gt;Edit:&lt;/p&gt;
&lt;p&gt;On a side question, Is there a reason my current windows identity gets switched when the process restarts?&lt;/p&gt;
&lt;p&gt;If it didn&amp;#39;t switch the identity, I wouldnt have a problem with it restarting the process (The game still seems to startup fine even once the process is restarted and the identity is switched).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Restarting process and switching windows identity</title><link>http://forums.eeye.com/forums/thread/4587.aspx</link><pubDate>Wed, 22 Jul 2009 23:01:37 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4587</guid><dc:creator>Blue1978</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4587.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=11&amp;PostID=4587</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unfortunately, you do not want to exclude explorer.exe from Kevlar like you have done.&amp;nbsp; Quite frankly, I would recommend simply disabling the Application Protection while your playing games and then reenable it afterwards.&amp;nbsp; It is unfortunate that with the way games run their code, security applications sometimes trigger on these actions.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Restarting process and switching windows identity</title><link>http://forums.eeye.com/forums/thread/4578.aspx</link><pubDate>Wed, 22 Jul 2009 03:31:49 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4578</guid><dc:creator>lnicula</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4578.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=11&amp;PostID=4578</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Indeed explorer.exe is usually vulnerable to buffer overflow attacks through the various plugins/viewers, modules etc that run inside and handle files of various formats.&lt;/p&gt;
&lt;p&gt;Unfortunately that&amp;#39;s why it also has many false positives. Many applications (and many malware binaries as well) inject code in it and run it for whatever purpose. Application protection will trigger if code is executed from the heap or a return-to-libc is detected.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Restarting process and switching windows identity</title><link>http://forums.eeye.com/forums/thread/4530.aspx</link><pubDate>Fri, 17 Jul 2009 02:47:53 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4530</guid><dc:creator>Zerosu</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4530.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=11&amp;PostID=4530</wfw:commentRss><description>&lt;p&gt;I tryed adding the line to the apiex.ini file and got no results.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Next i tryed adding all three of these processes to the apiex.ini since these were the 3 process I found runing with the process explorer you suggested.&lt;/p&gt;
&lt;p&gt;In the explorer it would list GameGard.des, and GameMon.des under AION.bin for about a second and then that would dissapeair and i would get the flicker of the windows identity switching on me. then i get the blink warning. GameGard.des happens to run outside of AION.bin for about 10 seconds after what seems to be the flicker where it switches idenitys.&lt;/p&gt;
&lt;p&gt;*GameGard.des;;Kelvlar;0&lt;br /&gt;*GameMon.des;;Kelvlar;0&lt;br /&gt;*AION.bin;;Kelvlar;0&lt;/p&gt;
&lt;p&gt;Reading the message that blink gives me in the log its basicly telling me to put Explorer.exe into the apiex.ini file, however I dont think that would be a good idea?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;EDIT:&lt;/p&gt;
&lt;p&gt;I tryed adding &amp;quot;explorer.exe;;Kevlar;0&amp;quot; to the apiex.ini file temperarly to test it out.&amp;nbsp; What do you know it fixes it.&amp;nbsp; -_-&amp;nbsp;&amp;nbsp; Though I would guess it is not a good idea to leave it like that.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Restarting process and switching windows identity</title><link>http://forums.eeye.com/forums/thread/4510.aspx</link><pubDate>Sun, 12 Jul 2009 01:24:44 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4510</guid><dc:creator>Blue1978</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4510.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=11&amp;PostID=4510</wfw:commentRss><description>&lt;p&gt;Your trying to create a rule in the System Protection module itself to &amp;quot;detect&amp;quot; something based on a process, but you need to exclude that particular process from Blink&amp;#39;s Application Protection engine (aka &amp;quot;Kevlar&amp;quot;) instead.&amp;nbsp; To do this, you must modify an .ini file within Blink.&amp;nbsp; To do this complete the following:&lt;/p&gt;
&lt;p&gt;From an account that has Admin rights:&lt;/p&gt;
&lt;p&gt;1.&amp;nbsp; Navigate to:&amp;nbsp; C:\Program Files(&lt;b&gt;for Windows XP&lt;/b&gt;) or Program Files (x86) (&lt;b&gt;for Vista&lt;/b&gt;)\eEye Digital Security\Blink\config&lt;/p&gt;
&lt;p&gt;- under the config folder, double left click on the &amp;quot;apiex.ini&amp;quot; file to open it.&amp;nbsp; It should open in Notepad or something like that, if it asks you to choose what to open it in, choose Notepade or Wordpad if possible.&lt;/p&gt;
&lt;p&gt;2.&amp;nbsp; Once in this file, I would recommend reading the description given by eEye (anything that has a line that starts with a &amp;quot;#&amp;quot; sign) for your own information.&amp;nbsp; Otherwise, scroll all the way to the bottom of this page.&lt;/p&gt;
&lt;p&gt;3.&amp;nbsp; At the bottom directly on the next line directly under the last long line of &amp;quot;#############&amp;quot; enter:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;b&gt;&lt;span style="font-size:medium;"&gt;*GameGard.des;;Kelvlar;0&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;"&gt;This &amp;quot;should&amp;quot; exclude that process name you have given me from the Application Protection engine in Blink.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;"&gt;4.&amp;nbsp; When your done, go to the top of this window and select File &amp;gt;&amp;gt; Save&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;"&gt;5.&amp;nbsp; Shutdown Blink completely by going into its main window and&amp;nbsp;going to&amp;nbsp;(File &amp;gt;&amp;gt; Shutdown Blink Personal Edition)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;"&gt;6.&amp;nbsp; Restart Blink again and try your game once again.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;"&gt;=========================================&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;"&gt;If this does not help, get the nice little utility called &amp;quot;Process Explorer&amp;quot; found at microsoft&amp;#39;s technet&amp;nbsp;site:&amp;nbsp; &lt;a target="_blank" href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx"&gt;http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;"&gt;1.&amp;nbsp; Open up the zip file that you download for it and simply extract only the &amp;quot;procexp.exe&amp;quot; file to your desktop or wherever you want to run it from.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;"&gt;2.&amp;nbsp; Run the self contained executable to start it.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;"&gt;3.&amp;nbsp; Once running, go to: View &amp;gt;&amp;gt;&amp;nbsp;and select &amp;quot;Show New Processes&amp;quot; to place a check mark next to it.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;"&gt;Process Explorer is basically a Task Manager on Steroids containing many many more abilities.&amp;nbsp; IF you want, you can replace your Task Manager with it (until you revert back to Task Manager) by going to:&amp;nbsp; Options &amp;gt;&amp;gt; Replace Task Manager.&amp;nbsp; This will show was process or processes are running other processes and so forth.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;"&gt;Let us know if you need any more help.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Restarting process and switching windows identity</title><link>http://forums.eeye.com/forums/thread/4508.aspx</link><pubDate>Sat, 11 Jul 2009 19:48:15 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4508</guid><dc:creator>Zerosu</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4508.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=11&amp;PostID=4508</wfw:commentRss><description>&lt;p&gt;The only thing I can find for gamegard seems to be a name in the task manager when gamegard is starting up. &amp;quot;GameGard.des&amp;quot;&amp;nbsp; I can&amp;#39;t find any exe like punkbuster has.&lt;/p&gt;
&lt;p&gt;When i went into blink and tryed to add the system execution protection rule, I found it hard to figure out what each of the inputs was asking for.&amp;nbsp; First it asks for an executible.&amp;nbsp; Next it asks for a parent executible (caller).&amp;nbsp; If I am able to find out what was making the calls to explorer.exe, would you be able to discribe how I would create the rule in blink?&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Restarting process and switching windows identity</title><link>http://forums.eeye.com/forums/thread/4465.aspx</link><pubDate>Thu, 02 Jul 2009 02:14:26 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4465</guid><dc:creator>Blue1978</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4465.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=11&amp;PostID=4465</wfw:commentRss><description>&lt;p&gt;Is there an executable name associated with the anti-hack program (like the anti-hack program &amp;quot;Punkbuster&amp;quot; uses &lt;strong&gt;&lt;span style="color:#222222;"&gt;PnkBstrA.exe, etc&lt;/span&gt;&lt;/strong&gt;)?&lt;/p&gt;
&lt;p&gt;You could exclude the antihack program from Blink&amp;#39;s Application Protection engine (more on this later depending on your response).&lt;/p&gt;
&lt;p&gt;What particular&amp;nbsp;game (and anti-hack program) is causing this?&lt;/p&gt;
&lt;p&gt;==================================================&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eEye can correct me if I am wrong on this, but to me from what your telling us, Blink reacted this way because obviously whatever the anti-hack program was doing (obviously trying to send information about what is runnning on your system back to the game servers) it was trying to use Internet Explorer&amp;#39;s process to initiate contact back to its servers to report your system&amp;#39;s status (i.e your running software or devices on your system that could be use to cheat in a game etc).&amp;nbsp; Blink does this off and on simply because exploits (and other Malware) will attempt to hijack a process or take control of a process to complete their malicious intentions.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unfortunately, in your case this was a false-positive, however had it been something malicious it would have been stopped hence a good call by Blink.&amp;nbsp; Keep in mind a lot of the anti-hack programs display the behavior of a malicious process simply because of what they are doing.&lt;/p&gt;
&lt;p&gt;==================================================&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I moved this post to the games section of troubleshooting (since it dealt with games and such).&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Restarting process and switching windows identity</title><link>http://forums.eeye.com/forums/thread/4464.aspx</link><pubDate>Thu, 02 Jul 2009 01:57:43 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4464</guid><dc:creator>Zerosu</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4464.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=11&amp;PostID=4464</wfw:commentRss><description>&lt;p&gt;When I open up a new game a program starts with it called game gard (anti hack program), however when this program opens blink gets the below error and decides to restart the process.&amp;nbsp; Once the process is restarted my windows Identity gets switched and I have to logout and log back in to get my normal favorites/desktop icons.&lt;/p&gt;
&lt;p&gt;Description: Blink detected a suspicious system call. &lt;br /&gt;Program: C:\WINDOWS\explorer.exe &lt;br /&gt;Reason: KERNEL32.DLL!VirtualProtect &lt;br /&gt;Action: Restart process&lt;/p&gt;
&lt;p&gt;Is there any way to stop this from happening?&amp;nbsp; Right now i have to turn off the system protection to stop it from happening.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>