A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #1149  by gjf
 Fri May 21, 2010 3:46 pm
wraithdu
Ahh, I've also found a problem with BSA. It is blocking my call to GetModuleFileNameW. This causes a critical part of my DLL loading process to fail and causes the DLL to unload itself. If you had enabled the debugging messages (which I should have asked you to do in the first place), you would have seen where this occurs. Basically my DLL cannot build the list of Sandboxie processes to check against the name of the target process.

Please pass this onto the developer of BSA. If he fixes this problem, my DLL should start working again.
Logs are attached.
You do not have the required permissions to view the files attached to this post.
 #1184  by Buster_BSA
 Sun May 30, 2010 1:14 am
BSA´s actual host is going down soon. The new host is: http://bsa.netai.net

Released Buster Sandbox Analyzer 1.22.

Change list:

Added automatic malware analysis mode
Added digital signature verification
Removed "Check Ports"
Updated Buster Sandbox Analyzer GUI
Updated LOG_API library

It can be downloaded from: http://bsa.netai.net/bsa.rar
 #1197  by gjf
 Mon May 31, 2010 10:20 am
Screenshots of what? Let me explain what am I doing.
1. uTorrent is downloading files at host.
2. Let's start BSA and sandbox notepad.exe for instance.
3. Close sandboxed notepad window.
4. Press "Stop analysis" and "Viewer" - "View connections".

Now we can see some connections which belongs to uTorrent but surely not to notepad.

So what should I screenshot here? Please advise.
 #1198  by Buster_BSA
 Mon May 31, 2010 10:42 am
gjf wrote:Screenshots of what? Let me explain what am I doing.
1. uTorrent is downloading files at host.
2. Let's start BSA and sandbox notepad.exe for instance.
3. Close sandboxed notepad window.
4. Press "Stop analysis" and "Viewer" - "View connections".

Now we can see some connections which belongs to uTorrent but surely not to notepad.

So what should I screenshot here? Please advise.
You should screenshot "View connections", where I can see connections which belongs to uTorrent.
  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 32