Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #51  
Old September 26th, 2009, 04:10 AM
opaida opaida is offline
Regular Poster
 
Join Date: Sep 2009
Posts: 161
Default Re: pe guard

Thx all

@winHole7:
you are welcome
I'll try to add these suggestions in the next version

And you are right about richness

@StevieO
There are no options in installation.

@jdd58
I d'nt know .
  #52  
Old September 26th, 2009, 04:11 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: pe guard

is PeGuard or does it have protection againts termination?
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #53  
Old September 26th, 2009, 04:27 AM
opaida opaida is offline
Regular Poster
 
Join Date: Sep 2009
Posts: 161
Default Re: pe guard

Quote:
Originally Posted by jmonge
is PeGuard or does it have protection againts termination?
surely..
you can try
  #54  
Old September 26th, 2009, 10:08 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: pe guard

I spoke too soon lol.

Just about to remame the new folder to PE GUARD v1.1 and then put it in my installed Apps folder. Before i did i r-clicked on the PEG Setup file in that folder to try and find it's properties, file version etc. As it happens it's only the Installshield wrapper.

Anyways up pops PEG with this, and also intercepts and blocks setup properties from appearing

Name:  peg.png
Views: 945
Size:  50.7 KB

OK very good, these alerts last for several seconds before a 10 sec countdown starts. If you don't select anything it closes and then setup properties appears. When i was in the process of moving the folder to it's new location, i also got a PEG alert about the write attempt.

I repeated the process a number of times, and once i got a different alert after the first, warning of a System Restore point !

So all very good so far.

opaida

A suggestion, i think it might be better if there was no countdown, and the alert stayed there until a choice is made.

Quote:
There are no options in installation

Well i must have a special version lol.

Name:  peg1.png
Views: 949
Size:  33.9 KB

Only kidding, i presume that's just a generic message box that appears, and i initially thought something was missing, so i now realise you havn't included any options etc !

Are you using mchInjdrv.sys ?

Name:  mch.png
Views: 939
Size:  10.4 KB

I know it's usually safe as others use it, OA for eg.
  #55  
Old September 26th, 2009, 10:52 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: pe guard

Quote:
Originally Posted by opaida
surely..
you can try
cool yes it does indeed
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #56  
Old September 26th, 2009, 11:19 AM
opaida opaida is offline
Regular Poster
 
Join Date: Sep 2009
Posts: 161
Default Re: pe guard

A user had sent me a notice about the properties window of an exe file.
First he thought that PE Guard didn't work after revoking/denying access, becuase the properties window appeared.
I replyed that the Windows trys to get write access to the file when it shows its propereties and it will show the propereties even if there is no write access!!.

Thx for your suggestion.
I'll extend the value of timer.
I added the timer to prevent the program from bothering the users that playing games , or somthing like so.


Also, I don't know what mchInjdrv.sys is. And my program doesn't use it. :S
  #57  
Old September 26th, 2009, 12:19 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: pe guard

i believe that mchInjdrv.sys is part of the system files
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #58  
Old September 26th, 2009, 01:41 PM
winHole7 winHole7 is offline
Infrequent Poster
 
Join Date: Sep 2009
Posts: 12
Default Re: pe guard

Hi,

Thanks for your answers Opaida, it seems that StevieO agrees with me about the "auto-revoke timer" but, as You said, it may be useful when playing games so, an option to set the countdown time, from 0 second (disable) to what users want, might be appreciate by some of us...

Also, it warns You when You try to display the properties window of '*.exe', '*.sys' or '*.dll' files but, as mentionned in StevieO post, the window appears even if the "auto-revoke timer" reaches to zero.

About the 'PEG.exe' file termination protection: It doesn't work if You use the Windows Task Manager but, with Process Explorer from Sysinternals, You can kill it... Not directly by the "Kill Process" nor the "Kill Process Tree" function but, if You use the "Suspend" one before to click on "Kill Process" or "Kill Process Tree", it will be ended. (I didn't try with another software like Advanced Process Termination)
I don't know if this could be a problem against some malware...

Name:  PEG.PNG
Views: 918
Size:  24.9 KB

See You...
_ernestoG_
  #59  
Old September 26th, 2009, 03:07 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: pe guard

PEG can be killed by quite a few methods. Also those using Process Hacker instead of Task Manager or Process Explorer can terminate the process.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #60  
Old September 26th, 2009, 03:44 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: pe guard

i hope it is fix cause i am already puting this in my pc
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #61  
Old September 26th, 2009, 04:38 PM
clocks clocks is online now
Very Frequent Poster
 
Join Date: Aug 2007
Posts: 1,955
Default Re: pe guard

Can anyone comment on if this program gives more or less pop-ups that Comodo HIPS? thanks!
  #62  
Old September 26th, 2009, 04:40 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: pe guard

Quote:
Originally Posted by clocks
Can anyone comment on if this program gives more or less pop-ups that Comodo HIPS? thanks!
less i say way more less
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #63  
Old September 26th, 2009, 04:42 PM
PROROOTECT's Avatar
PROROOTECT PROROOTECT is offline
Very Frequent Poster
 
Join Date: May 2008
Location: HERE ...Fort Lee, NJ
Posts: 1,102
Default Re: pe guard

MchInjDrv by madshi: http://www.wilderssecurity.com/showp...8&postcount=42

MchInjDrv.sys is SAFE, no worry about.


PROROOTECT
__________________
W.XPSP2,1GBRAM,13proc,17svc;IE8s ***
On-Demand
PowerTool XueTr NVT Ga S RFS
Preventive+
FW!! S.Mon. TinyW. JS SettingsX NoDs . =
URL checkZ Q W T U urlQ W IPduh DNS-info Sleuth
R W WPT BC WS M BShotSu C $ Rev IP
NoAV,Java JRE-Why Why|VOP MalwareTips-Turin Shroud PSus **READs!!! CATS!
  #64  
Old September 26th, 2009, 04:43 PM
clocks clocks is online now
Very Frequent Poster
 
Join Date: Aug 2007
Posts: 1,955
Default Re: pe guard

Quote:
Originally Posted by jmonge
less i say way more less

Thanks. I was going to say if it is the same, why not just run CIS, and get firewall and AV for only a few megs more. But if PE Guard is less of a annoyance, I can see the value in it.

opaida - thanks for the program and coming to the forums to answer peoples questions!
  #65  
Old September 26th, 2009, 04:48 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default pe guard

i am testing it and to tell you that this is very promising program

what i like about this peguard is that it has a count down from 10 to 0 and if you dont respond to the alert the ofending program/virus/etc will be block from writing/executing and the security alert will banish/fade away cool
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #66  
Old September 26th, 2009, 05:45 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: pe guard

Interesting, on trying out a few more r-click properties as i showed earlier, i noticed in Task Manager PEG was on Zero CPU cycles, and the Memory usage doesn't change from 7,816k either !

jmonge

Quote:
i believe that mchInjdrv.sys is part of the system files

Yes thanx i realise that, just wondered if PEG was using it. Must be something else, so i'll investigate.

Quote:
if you dont respond to the alert the ofending program/virus/etc will be block from writing/executing

Is that so ? See mine and winHole7's posts above regarding this. Can anyone clarify this one way or the other ?

winHole7

I didn't realise you'ld also made a suggestion about the timer, sorry !
  #67  
Old September 26th, 2009, 05:52 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: pe guard

10 seconds is long enough to decide to apply yes/no well at least for me
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #68  
Old September 26th, 2009, 05:57 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Exclamation Re: pe guard

jmonge

I wasn't talking about the 10 Secs timer in my last post, but this -


Quote:
if you dont respond to the alert the ofending program/virus/etc will be block from writing/executing

I'm not sure if whatever will be automatically blocked after the Timer ends, that's what i'm asking for clarification on, not the 10 Secs ?
  #69  
Old September 26th, 2009, 06:00 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: pe guard

ah i see it is very convinient this way in my opininon anyway the pop up will apear when drive by or when you are installing files why do you think or what do you think about it?
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #70  
Old September 26th, 2009, 06:18 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: pe guard

jmonge

Well the CPU cycles/Memory usage is remarkable for one thing ! Early days, but looking good so far.

opaida

Hi, can you clarify whether things will be automatically blocked after the Timer ends, or ?
  #71  
Old September 26th, 2009, 06:24 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: pe guard

i tested againts couple of malware and they were auto-block which is cool but opaida can confirm this
i will test it again to see
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #72  
Old September 26th, 2009, 11:10 PM
winHole7 winHole7 is offline
Infrequent Poster
 
Join Date: Sep 2009
Posts: 12
Default Re: pe guard

Hi again You all,

Lots of attractive posts; thanks for that "WSF" members

Here the results I found after some tests.

When the warning window is displayed, if we click on :

"ALLOW", then the process specified below "Process:" will be autorized to access to the file mentionned below "PE File:" but, only one time so, a new access of this process to this same file will warn us again.


"ALLOW" with "Apply to this pair always." checked, the process specified below "Process:" will always be autorized to access to the file mentionned below "PE File:" so, a new access of this process to this same file won't warn us anymore.


"ALLOW" with "Apply to this process always." checked, the process specified below "Process:" will always be autorized to access to any file and not only the one mentionned below "PE File:" so, a new access of this process to any file won't warn us.


"REVOKE WRITE ACCESS", the process specified below "Process:" isn't autorized to access to the file mentionned after "PE File:" (only one time so, new access means new warning) and it seems that any process won't be able to get a write access to it too.


"REVOKE WRITE ACCESS" with "Apply to this pair always." checked... Same as above but there will be no warning window anymore (same "Process:", same "PE File:")


"REVOKE WRITE ACCESS" with "Apply to this process always." checked... Same as above (same "Process:") but for all files and not only the one stated after "PE File:".


"PREVENT ANY ACCESS"... Same as "REVOKE WRITE ACCESS" but all access types are denied (read, write...)


"PREVENT ANY ACCESS" with "Apply to this pair always." checked... Same as "REVOKE WRITE ACCESS" with "Apply to this pair always." checked but all access types are denied (read, write...)


"PREVENT ANY ACCESS" with "Apply to this process always." checked... Same as "REVOKE WRITE ACCESS" with "Apply to this process always." checked but all access types are denied (read, write...)

-

I'm not sure to be really right so, if someone gets different outcomes, please let us know...

-

The properties window of a file is displayed even if we block (revoke/prevent) the "explorer.exe" process... See a previous message from StevieO for details.

Last thing, about the "REVOKE WRITE ACCESS", it seems to occur the same thing if we click on it or if we wait for the timer's end...
The "Apply to this pair always." or "Apply to this process always." boxes can also be checked before the countdown reaches to zero, it works.

-

Quote:
Originally Posted by StevieO
I didn't realise you'ld also made a suggestion about the timer, sorry !
No problem, it's interesting to see that I'm not the only one to request for a timer setting (enabled and set at 10 seconds for jmonge and quick men / increased or disabled for slow ones like us )
And, for a full screen application (video players, games...), an "always allowed mode/always denied mode" setting could maybe be useful.

See You all...
_ernestoG_
  #73  
Old September 27th, 2009, 07:13 AM
opaida opaida is offline
Regular Poster
 
Join Date: Sep 2009
Posts: 161
Exclamation Re: pe guard

Hi,
About termination: It's not a problem at all, cause there are two cases:
1. a virus trying to kill PE Guard, and it will fail like Task Manager.
2. a rootkit trying to kill PE Guard, and it will fail because it need to write a .sys file to do that.

It's user problem if he wants to kill my program(manually by Process Hacker for example). But he won't because there is Exit option .

.
.
I'll explain the options and timer in the alert window:
When an alert appears, The user can choose one action from three available actions:
1. "ALLOW": Allow the process to get write access to the requested file.
2. "REVOKE WRITE ACCESS": The process is allowed only to get a read access to the requested file.
3. "PREVENT ANY ACCESS": Send Access Denied to the process.
Now, the default action is "REVOKE WRITE ACCESS", so when the countdown timer reaches 0, the default action will be selected automatically(that is why the offending process blocks after countdown timer ).

The timer length = 10 sec (before appear) + 10 sec (countdown).

The 2 checkboxes are independent of the selected action:
1. "Apply to this pair always.": by "this pair", I mean this process only and this file only.
2. "Apply to this process always.": this process only and any file.


examples:
You have an alert about process "X" and file "Y":
*if you choose "ALLOW" without checking any checkbox then process "X" will be allowed to access the file for one time only, if it try to do so, the alert will re-appear.
*if you choose "ALLOW" and check "Apply to this pair always.", then whenever process "X" trying to access file "Y" it will be allowed. (if you choose "revoke"/"deny" it will be "revoked"/"denied" always). If process "X' try to access another file, the alert will appear.
*if you choose "ALLOW" and check "Apply to this process always", then process "X" will be allowed to access any file.(if you choose "revoke"/"deny" it will be "revoked"/"denied" always).
*if you choose "ALLOW" and check "Apply to this prcoess always" and "Apply to this process always", then we are in the last case.


NOTE: although I display the full path of the exe file of the process, I identify the process by its PID(Process ID), So if the process was killed and rerun it will have a new PID and PE Guard will identify it as a new process.


GOOD NEWS: I've changed the countdown timer. Now it will be stopped if the ueser move the mouse over the alert window, I think that's batter.
THX all .

-sorry for bad English-

Best Regards.
Opaida.
  #74  
Old September 27th, 2009, 08:03 AM
Saraceno's Avatar
Saraceno Saraceno is offline
Very Frequent Poster
 
Join Date: Mar 2008
Posts: 2,395
Default Re: pe guard

Nothing wrong with your english Opaida. I can understand you just fine.

From what I've read in this thread, this program seems to be very simple to use. Great work.
__________________
Fine Art Landscape Photography
  #75  
Old September 27th, 2009, 12:58 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: pe guard

good job opaida ,by the way do we have to install the program to get it updated?thanks
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:34 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums