Research on Detection and Uninstall Method in Remote Thread Injection of DLL



Article Abstract: A trojan horse detection technology in the Windows operation system is investigaeted,which combines several advancing technologies including remote thread injection and dynamic-link library(DLL),etc.According to the latest technology of hidding the Trojan Horse through remote thread injection,a detection method for discovering whether a process is remotely injected into DLL is proposed.And furthermore,a corresponding DLL uninstall method is also given.The remarkable effects of the proposed method have been proved by the experiment results.

About Author:

Author: Wang Peihong Zhao Erdun Zhang Yu
Publisher: Department of Computer Science,Hua Zhong Normal University,Wuhan 430079
Keywords:remote thread injection, process, module, DLL