Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Ghost Security Suite (GSS)
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 7th, 2005, 12:19 PM
TopperID's Avatar
TopperID TopperID is offline
Very Frequent Poster
 
Join Date: Oct 2004
Location: London
Posts: 1,527
Default How do you block a .dll trojan?

Supposing you want to create Application Rules to prevent a piece of malware on your system from making any changes to your Registry; I assume you would create a Group for the malware and include the keys:-

HKEY_CLASSES_ROOT\**
HKEY_CURRENT_USER\**
HKEY_LOCAL_MACHINE\**
HKEY_USERS\**
HKEY_CURRENT_CONFIG\**

and then, for each key, tick all the 'event' boxes and select 'block'.

But supposing you had a .dll trojan on your system, which had injected itself into, for example, Winlogon.exe; would you create the Group around Winlogon (and hence block that) or would you give the file path of the .dll trojan and block it directly?

I'm thinking of a situation where a .dll trojan is acting in tandem with another trojan .exe file which gets placed as an autorun in the Registry, and you want to stop it running next reboot.

Does anyone know whether you should be blocking the .dll itself or the legitimate .exe system file it has been injected into?
  #2  
Old October 8th, 2005, 07:48 PM
Rico's Avatar
Rico Rico is offline
Very Frequent Poster
 
Join Date: Aug 2004
Location: Texas
Posts: 1,407
Default Re: How do you block a .dll trojan?

Hi Topper, How about PG? How about Trojan Hunter? At least this is how I will hopefully avoid it.

Take Care
rico
__________________
"Fear is a poison provided by the mind, and courage is the antidote stored always ready in the soul." D. Koontz
  #3  
Old October 9th, 2005, 10:18 AM
TopperID's Avatar
TopperID TopperID is offline
Very Frequent Poster
 
Join Date: Oct 2004
Location: London
Posts: 1,527
Default Re: How do you block a .dll trojan?

Quote:
Hi Topper, How about PG?
Oh yes, that's true; but I was thinking more of a situation where a machine is already infected and you want to do something about it.

For example, if you disable PG/RD to do an install and get more than you bargained for! Or else you are simply working on an infected machine that didn't have PG/RD at the time of infection.

I just wondered how you could use RD to suppress a .dll trojan from making further changes to the Registry after you've got it on your comp.
  #4  
Old October 9th, 2005, 03:01 PM
tuatara's Avatar
tuatara tuatara is offline
Frequent Poster
 
Join Date: Apr 2004
Posts: 758
Default Re: How do you block a .dll trojan?

I don't believe it is possible to stop a .dll from starting from PG

I tried to ALLOW firefox to start, and to stop JAVA (dll) (started via Firefox) by PG
( i know there are other ways to stop this, but this is just for testing)
And whatever i did, i could not stop the java .dll by PG

But perhaps i have overlooked something, otherwise it is just not possible.

And i don't know if there are any other programs that allow you to
select which <file>.dll can be started, and which are blacklisted or so.

So if these java dll file(s) are replaced by malware, OR you don't trust the files anymore, it is very difficult to stop them.

Perhaps there is other software that can do this.
It should be possible with Tiny Personal Firewall , but i am not sure
and did not test it.
Perhaps with tools like Prevx ? or SSM ?
__________________
The old creature tuatara lived here, hundreds of years
before those malware creators arrived on the Internet


  #5  
Old October 10th, 2005, 09:22 AM
TopperID's Avatar
TopperID TopperID is offline
Very Frequent Poster
 
Join Date: Oct 2004
Location: London
Posts: 1,527
Default Re: How do you block a .dll trojan?

Reading from what you are saying tuatara, I think the answer to my question is going to be that you have to block the 'process' into which the .dll has been injected, rather than the .dll itself.

That seems logical I suppose!
  #6  
Old October 10th, 2005, 02:38 PM
deviladovcate
 
Posts: n/a
Default Re: How do you block a .dll trojan?

Quote:
Originally Posted by TopperID
Reading from what you are saying tuatara, I think the answer to my question is going to be that you have to block the 'process' into which the .dll has been injected, rather than the .dll itself.

That seems logical I suppose!

Hmm seems to me even in the "non-injected" form , I have never seen a dll request permission to change the registry in regdefend.......
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Ghost Security Suite (GSS) « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:59 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums