Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 29th, 2007, 10:21 PM
sunrise sunrise is offline
Regular Poster
 
Join Date: Mar 2007
Posts: 75
Default Which program for dll load/inject virtualization??

Hi,

please help, i need a security program that is able to cater for:

1. run a program, this program potentially will access a dll (call dll loading?), then modify the dll (dll injection?), resulting modified dill seems to be camouflage as indicdll.dll (keyboard lang shell hook extension, able to record inputs), injected to iexporer.exe for connection to internet.

2. Cant block the dll loading or maybe modification else program won't function.

3. But need to block the dll from internet connection.

4. After closing program, detect that malware and clean it or, going back to original state, either the cleaning is ok or actual modification of dll was prevented from taking place initially at all.(virtualization?)

5. Allow me to view the process, as in a log, what has taken place, instead of total silent, as i will not know if its really effective or not

I have tried using zonealarm pro with sas.
-> sas didnt detect real time. zonealarm pro block the program from running in component monitor. Once allow zonealarm to let program run, infected but sas cant start, sort of freeze, dont know why yet, maybe due to other reasons.

Tried comodo + spybotSD
-> program run, comodo alert me of indicdll possible keylogger, allow me to block it from internet. close program and run spybot but didnt detect. but i dont know if the indicdll is a camoflauge one, or it is the windows original dll which has been modified. so cant or do not know how to go back original state.

Tried comodo + sandboxie
-> program run, comodo alert me of indicdll possible keylogger, allow me to block it from internet. close program and run spybot but didnt detect. so cant or do not know how to go back original state.

some have advised me try cyberhawk/geswall/defensewall.
I want to know which one really can do the above as every time i tried once and didnt work, i have to clean my whole hdd and reinstall everything, but luckily using image.
__________________
Windows Vista Home Premium 32 Bit
Kaspersky Internet Security 7 | Mozilla Firefox 2 + NoScript | RoboForm | FirstDefense-ISR
  #2  
Old March 29th, 2007, 10:30 PM
dah145's Avatar
dah145 dah145 is offline
Frequent Poster
 
Join Date: Jul 2006
Location: n/a
Posts: 262
Default Re: Which program for dll load/inject virtualization??

Quote:
Originally Posted by sunrise
Hi,

please help, i need a security program that is able to cater for:

1. run a program, this program potentially will access a dll (call dll loading?), then modify the dll (dll injection?), resulting modified dill seems to be camouflage as indicdll.dll (keyboard lang shell hook extension, able to record inputs), injected to iexporer.exe for connection to internet.

2. Cant block the dll loading or maybe modification else program won't function.

3. But need to block the dll from internet connection.

4. After closing program, detect that malware and clean it or, going back to original state, either the cleaning is ok or actual modification of dll was prevented from taking place initially at all.(virtualization?)

5. Allow me to view the process, as in a log, what has taken place, instead of total silent, as i will not know if its really effective or not

I have tried using zonealarm pro with sas.
-> sas didnt detect real time. zonealarm pro block the program from running in component monitor. Once allow zonealarm to let program run, infected but sas cant start, sort of freeze, dont know why yet, maybe due to other reasons.

Tried comodo + spybotSD
-> program run, comodo alert me of indicdll possible keylogger, allow me to block it from internet. close program and run spybot but didnt detect. but i dont know if the indicdll is a camoflauge one, or it is the windows original dll which has been modified. so cant or do not know how to go back original state.

Tried comodo + sandboxie
-> program run, comodo alert me of indicdll possible keylogger, allow me to block it from internet. close program and run spybot but didnt detect. so cant or do not know how to go back original state.

some have advised me try cyberhawk/geswall/defensewall.
I want to know which one really can do the above as every time i tried once and didnt work, i have to clean my whole hdd and reinstall everything, but luckily using image.


KAV or KIS PDM could help you
__________________
Using: KIS 7 and Sandboxie
  #3  
Old March 29th, 2007, 10:39 PM
sunrise sunrise is offline
Regular Poster
 
Join Date: Mar 2007
Posts: 75
Default Re: Which program for dll load/inject virtualization??

Hi,

KAV/KIS for this scenario, it can prevent or allow the dll loading/modification/injection. But i do not think one can go back original state once you allowed it. means cant do scenario 4, and no 5 as well if im not wrong.. same as zonealarm pro
__________________
Windows Vista Home Premium 32 Bit
Kaspersky Internet Security 7 | Mozilla Firefox 2 + NoScript | RoboForm | FirstDefense-ISR
 

Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:16 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums