Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy general
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 4th, 2005, 03:06 AM
Vikorr Vikorr is offline
Frequent Poster
 
Join Date: May 2005
Posts: 662
Default CWS vs RegDefend

Interesting article about the CoolWebSearch trojan, and Registry DLL Injection

http://www.thetechguide.com/forum/in...howtopic=10984
  #2  
Old June 4th, 2005, 04:35 AM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re: CWS vs RegDefend

Hi Vikorr, I have moved this thread to the privacy section as it is not directly a RegDefend support question.
Process Guard does prevent this sort of .dll injection specifically it protects the AppInit key.
RegDefend can prevent spyware making registry changes for any known malware that may not just use the Appinit key.

Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #3  
Old June 4th, 2005, 04:45 AM
Vikorr Vikorr is offline
Frequent Poster
 
Join Date: May 2005
Posts: 662
Default Re: CWS vs RegDefend

Hi Pilli, not a problem. I just thought the users of RD would find the info interesting
  #4  
Old June 4th, 2005, 05:15 AM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re: CWS vs RegDefend

Regarding AppInit, you will also find that one of RD's default "Extra protection keys" is: hkey_local_machine\software\microsoft\windows nt\currentversion\windows | AppInit_DLLs | None | Mod Value | Ask User

I notice that, amonst others, experts like Tony Klein are now taking an active interest in creating .gst files covering many malware and potential malware keys. This is very good news for all RD and other users as RD is now being used as an expert tool to help fight off these pests.

Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #5  
Old June 4th, 2005, 05:54 AM
Vikorr Vikorr is offline
Frequent Poster
 
Join Date: May 2005
Posts: 662
Default Re: CWS vs RegDefend

Noticed that, and I've added many of their keys.... and after reading many different sites on what registry keys trojans/worms etc manipulate, and finding that the basic + extra keys cover almost all of them...I'm glad for their efforts

I suppose this was of interest to me because the key to prevent dll injection was out of the box (if I remember right), and it's always good to find out what specific protection keys are doing.
  #6  
Old June 4th, 2005, 06:04 AM
richrf richrf is offline
Very Frequent Poster
 
Join Date: Dec 2003
Posts: 1,907
Default Re: CWS vs RegDefend

Thanks Vikorr for the article and Pilli for your follow-up comments. It is great that experts such as Tony are involved with the product to further solidify RegDefend's ability to pro-actively defend against infections.

"An ounce of prevention is worth a pound of detection/cleaning".

Rich
 

Wilders Security Forums > Privacy Related Topics > privacy general « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:23 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums