Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 3rd, 2009, 05:11 PM
trjam's Avatar
trjam trjam is offline
Incredibly Massive Poster
 
Join Date: Aug 2006
Location: North Carolina
Posts: 8,620
Default Geswall Question

I have been wanting to ask this. Say you are using Geswall and visit some malware sites. The malware is on your PC but is encased in Geswall. I have 2 questions actually.

Say you suspend Geswall for a moment, what happens to the malware, is it let go?

And it is on your PC for how long. A reboot does not get rid of it like a program like ShadowDefender, nor does it roll those files back like Defensewall after a period of time.

It is there, waiting for what? I mean in the end, I could have a PC that is full of malware but cant do anything.
__________________
Webroot SecureAnywhere
  #2  
Old August 3rd, 2009, 05:22 PM
dell boy dell boy is offline
Frequent Poster
 
Join Date: Apr 2009
Location: uk, england
Posts: 240
Default Re: Geswall Question

its on your computer but isnt allowed access to your files, note why you see every now and then "C:/program/so and so REDIRECTED access" which means it was trying to access your files but geswall stopped it.
when you see lots of other things like stopping access to critical files the box will get redder, then you needa terminate it. watch mrizos review, he tests malware with it..
__________________
The best protection a computer could ever have, proven by experts and professionals is Safe-Hex.
Guaranteed!
  #3  
Old August 3rd, 2009, 05:47 PM
trjam's Avatar
trjam trjam is offline
Incredibly Massive Poster
 
Join Date: Aug 2006
Location: North Carolina
Posts: 8,620
Default Re: Geswall Question

what I saw my friend dellboy, was a file he let run, and then went looking for remnants in task manager. He also looked elsewhere. Personally Matt does a good job, but not great. My point again is, what happens if you disable Geswall protection to download a file and other malware is already on your PC protected.
__________________
Webroot SecureAnywhere
  #4  
Old August 3rd, 2009, 06:21 PM
Henk1956 Henk1956 is offline
Regular Poster
 
Join Date: Dec 2007
Posts: 55
Default Re: Geswall Question

1. Say you suspend Geswall for a moment, what happens to the malware, is it let go?
If malware has been downloaded by an isolated application, it will be labeled as untrusted and run isolated. When running isolated, Geswall will prevent the malware from changing the registry and certain system files. This should prevent the malware to add itself to an autostart location, meaning that it will be present but dormant.
Of course, if you suspend or remove Geswall and deliberately start the malware yourself it will run unrestricted.

2. And it is on your PC for how long?
It will be there forever (unless see 3).

3. It is there, waiting for what?
For you to delete it manually or for an antivirus/antimalware doing this for you. In general Geswall is intended to be used together with an antivirus/antimalware application. Geswall will be protecting the system against zero-day exploits (by isolating them) until your antivirus/antimalware is updated and able to remove them. Alternatively, if your knowledgeable enough, you can take notice of the attack notifications provided by Geswall and take appropriate action yourself.
  #5  
Old August 3rd, 2009, 06:33 PM
trjam's Avatar
trjam trjam is offline
Incredibly Massive Poster
 
Join Date: Aug 2006
Location: North Carolina
Posts: 8,620
Default Re: Geswall Question

Quote:
Originally Posted by Henk1956
1. Say you suspend Geswall for a moment, what happens to the malware, is it let go?
If malware has been downloaded by an isolated application, it will be labeled as untrusted and run isolated. When running isolated, Geswall will prevent the malware from changing the registry and certain system files. This should prevent the malware to add itself to an autostart location, meaning that it will be present but dormant.
Of course, if you suspend or remove Geswall and deliberately start the malware yourself it will run unrestricted.

2. And it is on your PC for how long?
It will be there forever (unless see 3).

3. It is there, waiting for what?
For you to delete it manually or for an antivirus/antimalware doing this for you. In general Geswall is intended to be used together with an antivirus/antimalware application. Geswall will be protecting the system against zero-day exploits (by isolating them) until your antivirus/antimalware is updated and able to remove them. Alternatively, if your knowledgeable enough, you can take notice of the attack notifications provided by Geswall and take appropriate action yourself.
thank you sir. This one post answers more questions then 15 different threads. I thank you.
__________________
Webroot SecureAnywhere
  #6  
Old August 3rd, 2009, 08:29 PM
Greg S Greg S is offline
Very Frequent Poster
 
Join Date: Mar 2009
Location: A l a b a m a
Posts: 1,039
Default Re: Geswall Question

Quote:
Originally Posted by trjam
..was a file he let run, and then went looking for remnants in task manager. He also looked elsewhere. Personally Matt does a good job, but not great..
I've watched and re-watched his video and am left still not fully understanding. When he terminated the bad app, did it delete everything except the desktop shortcuts which he deleted manually? I guess I'm not understanding because as you say, he looked elsewhere and didn't find anything but the desktop shortcut. Is the bad installation and crap in his temp internet file cache waiting for deletion?
  #7  
Old August 4th, 2009, 04:53 AM
dell boy dell boy is offline
Frequent Poster
 
Join Date: Apr 2009
Location: uk, england
Posts: 240
Default Re: Geswall Question

no it didnt have any installation files because it cant install anything, its just a running process and a desktop shortcut, its hard to get your head round i know.
__________________
The best protection a computer could ever have, proven by experts and professionals is Safe-Hex.
Guaranteed!
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:59 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums