which is the best way to run a suspicious file?

Discussion in 'other software & services' started by mantra, Feb 27, 2008.

Thread Status:
Not open for further replies.
  1. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Hi
    I have a question

    which the best way to run a suspicious file?

    well i agree " don't Run "

    but at work if i have to do it , to be safe what can i do ?

    run under a virtual system?
    or?
    i would like if you want to share with me your skill

    thanks
     
  2. MikeNAS

    MikeNAS Registered Member

    Joined:
    Sep 28, 2006
    Posts:
    697
    Location:
    FiNLAND
    Re: wich is the best way to run a suspicious file?

    Run it under VM or inside of Sandboxie.
     
  3. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Re: wich is the best way to run a suspicious file?

    is there vm free?
    or wich is the best virutal machine
     
  4. MikeNAS

    MikeNAS Registered Member

    Joined:
    Sep 28, 2006
    Posts:
    697
    Location:
    FiNLAND
    Re: wich is the best way to run a suspicious file?

    VirtualBox is free and also very good alternative to VMware.
     
  5. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Re: wich is the best way to run a suspicious file?

    thanks and there is a short tutorial how use virtualbox?

    what should i do?
    create a new virtual machine (xp)
    and the program inside the virutal machine

    and how can i know if it's dangerous?
     
  6. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Re: wich is the best way to run a suspicious file?

    or using Sandboxie i did understand how it works
    but how can i know if it's dangerous?
    have i a log of suspious operation?
     
  7. MikeNAS

    MikeNAS Registered Member

    Joined:
    Sep 28, 2006
    Posts:
    697
    Location:
    FiNLAND
    Re: wich is the best way to run a suspicious file?

    You can track what it do and of course scan it with some scanners.
     
  8. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Re: wich is the best way to run a suspicious file?

    thanks Mike
    is sandbox safe?
    which scanners do u use?
     
  9. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,784
    Re: wich is the best way to run a suspicious file?

    You can also scan the suspected file while sandboxed with a service such as Virus Total as well as with your on board tools.
     
  10. Chris12923

    Chris12923 Registered Member

    Joined:
    May 31, 2004
    Posts:
    1,097
    Re: wich is the best way to run a suspicious file?

    In my opinion a very safe way would be the following.

    use an isr software with defensewall installed as well.

    or

    use an isr and also use a virtualisation software like returnil, powershadow or the like.

    I'm sure there are many opinions but these are mine. As far as how you can tell if the file is dangerous or not after you have ran it with option 1 you could look at the logs in defensewall and see what actions the file took. option 2 there is no sure way.

    Thanks,

    Chris
     
  11. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Re: wich is the best way to run a suspicious file?

    thanks!
    what is a ISR?
     
  12. Chris12923

    Chris12923 Registered Member

    Joined:
    May 31, 2004
    Posts:
    1,097
  13. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Re: wich is the best way to run a suspicious file?

    thanks well rollback is more the more dangerous program
    to uninstall..:thumbd: :thumbd: it can screep up your system so much that you can't recovery
     
  14. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Re: wich is the best way to run a suspicious file?

    thanks !
    but the way is there alternative to DefenseWall
     
  15. Chris12923

    Chris12923 Registered Member

    Joined:
    May 31, 2004
    Posts:
    1,097
    Re: wich is the best way to run a suspicious file?

    I have uninstalled and reinstalled rollback more times than i can count since Dec 2005 and never had it mess my system up. Where did you get that info?

    As for alternative to defensewall GeSWall http://www.gentlesecurity.com/index.html . I have no experience with it but other users seem to like it.


    Thanks,

    Chris
     
  16. Mrkvonic

    Mrkvonic Linux Systems Expert

    Joined:
    May 9, 2005
    Posts:
    10,224
    Re: wich is the best way to run a suspicious file?

    Hello,
    Virtual machine ... or a dedicated test machine ...
    Mrk
     
  17. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Re: wich is the best way to run a suspicious file?

    Geshall for home use is free?
     
  18. MikeNAS

    MikeNAS Registered Member

    Joined:
    Sep 28, 2006
    Posts:
    697
    Location:
    FiNLAND
    Re: wich is the best way to run a suspicious file?

    Yes GeSWall is free.
     
  19. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    Re: wich is the best way to run a suspicious file?

    Scan at Virustotal, scan at an online sandbox and run the app in a VM loaded with tools (EULAliyzer, Process Explorer, TCPView, Process Monitor, debuggers, hex editors, Sandboxie, etc)
     
  20. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,784
    Re: wich is the best way to run a suspicious file?

    How so o_O

    GeSWall is an excellant app. :thumb:
    I only wish SandBoxie and GeSWall got along, but it's kinda hard to sandbox a sandbox. o_O
     
  21. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Re: wich is the best way to run a suspicious file?

    i mean do the malware deceive sandbox?

    you know i tried DefenseWall , but it need to install a service , and on work the pc doesn't let me to loadup in auto new programs
    so i can't try defensewall , i will try home
     
  22. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Re: wich is the best way to run a suspicious file?

    yes it's great but it runs at loadup and i can't shutdown :(

    i would a program to launch seldom, rarely
     
  23. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Re: wich is the best way to run a suspicious file?

    ProcessGuard 3.15 is death?
    or is in vain , i liked it
     
  24. Chris12923

    Chris12923 Registered Member

    Joined:
    May 31, 2004
    Posts:
    1,097
    Re: wich is the best way to run a suspicious file?

    Pretty much PG is dead. Besides that you have to answer the prompts correctly or you will suffer damage. This is the same with any hips.

    Thanks,

    Chris
     
  25. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,194
    Re: wich is the best way to run a suspicious file?

    thanks Chris
    you are very kind

    what's about a behavior blockers ?

    i mean i tell you what i need , a program that i will use seldom, rarely for unknow program or documents that i have to run

    i have nod32 and a firewall at home and at work , and i would like to have a program that i run only in seldom cases

    did you understand?
    because i don't run often such files
    i don't download files by the net , but could happen that i have to do or home or at work , and i would like to be pretected

    thanks have a nice day
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.