Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #101  
Old May 28th, 2012, 09:53 AM
No_script No_script is offline
Regular Poster
 
Join Date: May 2012
Posts: 97
Default Re: Av-comparatives April results

Yeah I did block those files, my mistake. But runddl32.exe is flagged anyway?

Still doesn't explain missing

NMC.INFOSTEALER.SCRAPKUT
NMC.SAULTY.G

I got a hit on those from other scanners.
  #102  
Old May 28th, 2012, 10:40 AM
TonyW TonyW is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: UK
Posts: 2,301
Default Re: Av-comparatives April results

Quote:
Originally Posted by No_script
But runddl32.exe is flagged anyway?
If the filename is exactly as you've typed it, I'm not surprised WSA flagged it. The legitimate Windows file is rundll32.exe.
  #103  
Old May 28th, 2012, 12:02 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: Av-comparatives April results

Quote:
Originally Posted by No_script
Yeah I did block those files, my mistake. But runddl32.exe is flagged anyway?

Still doesn't explain missing

NMC.INFOSTEALER.SCRAPKUT
NMC.SAULTY.G

I got a hit on those from other scanners.

I can't work through the noise in your scan log. You blocked and cleaned too many operating system components which made everything stop functioning properly. I wouldn't be surprised if the AV was detecting WSA as bad as it was told to delete so many critical files.
  #104  
Old May 28th, 2012, 12:39 PM
Mongol's Avatar
Mongol Mongol is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: Houston, TX
Posts: 1,581
Default Re: Av-comparatives April results

Heh...I go back to my post #82...
__________________
"We are here on Earth to fart around. Don't let anybody tell you any different." –Kurt Vonnegut

Look N' Stop Firewall, Webroot Security Essentials, and AD Muncher 4.93
  #105  
Old May 28th, 2012, 02:12 PM
ProTruckDriver's Avatar
ProTruckDriver ProTruckDriver is offline
Frequent Poster
 
Join Date: Sep 2008
Location: Chesapeake, Virginia
Posts: 208
Default Re: Av-comparatives April results

Quote:
Originally Posted by PrevxHelp
I can't work through the noise in your scan log. You blocked and cleaned too many operating system components which made everything stop functioning properly. I wouldn't be surprised if the AV was detecting WSA as bad as it was told to delete so many critical files.

Wow
__________________
WEBROOT SecureAnywhere Complete. Closed Beta Tester.
No Wait For Security Updates ~ It's Done In The "Cloud"
If Your NOT Using WSA: "Mine Is Shorter Than Yours" (Scan Time That Is).
  #106  
Old May 28th, 2012, 03:18 PM
superssjdan's Avatar
superssjdan superssjdan is offline
Regular Poster
 
Join Date: Dec 2011
Location: USA
Posts: 111
Default Re: Av-comparatives April results

You seem to have the worst luck with infections.From what i've seen,the least of your problems is Webroot.Something tells me no matter what av you run,you will wind up being infected.Some things should NEVER be changed.Too much tinkering is a horrible thing.Throwing stones constantly at Webroot won't fixed your self inflicted problems.I wonder,how much pirated software you might possess??Might be the answer to some of your infections
__________________
WSA-C 8.0.2.96
PrivateFirewall 7.0.29.1
Diskeeper 12 Pro /HitmanPro 3.7 Paid
Ad Muncher 4.93 paid/Acronis True Image Home 2013
corei5 650 8gddr3-1333 1tb int,1tb exter HD
XFX R7850 DDE 2Gig win8PROx64
  #107  
Old May 28th, 2012, 03:24 PM
Mongol's Avatar
Mongol Mongol is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: Houston, TX
Posts: 1,581
Default Re: Av-comparatives April results

Hate to say it but is sounds to me like re-format time...
__________________
"We are here on Earth to fart around. Don't let anybody tell you any different." –Kurt Vonnegut

Look N' Stop Firewall, Webroot Security Essentials, and AD Muncher 4.93
  #108  
Old May 28th, 2012, 10:08 PM
STV0726's Avatar
STV0726 STV0726 is offline
Frequent Poster
 
Join Date: Jul 2010
Posts: 868
Default Re: Av-comparatives April results

Maybe your "friend" tested his "hax skills" on you?
__________________
~ STV0726
OS: Windows 7|SRP|SUA|UAC|EFS|EMET|Firewall|Backup
Resident: Webroot SecureAnywhere 2013|Sandboxie
On-Demand: MBAM|SAS|HMP|Comodo CE|Secunia PSI
Browser: Firefox|Web of Trust|Adblock Plus|NoScript
Hardware/Other: Linksys Router|Norton ConnectSafe DNS
  #109  
Old May 29th, 2012, 03:21 AM
No_script No_script is offline
Regular Poster
 
Join Date: May 2012
Posts: 97
Default Re: Av-comparatives April results

Webroot shouldn't **** itself if you block a few processes. A few things, why is HTTPS protection off by default? At least on my system it is. The firewall basically lets everything in without exception! You MUST block ICMP echo pings, have this as a setting please.


Quote:
.I wonder,how much pirated software you might possess??Might be the answer to some of your infections

NONE, so rule that out. Webroot just hasn't picked up the infections I've got. But there are so many programs out there that are well respected as safe when they are not, Combofix & Bleechbit are 2 that are very very very dodgy to the point that they should be flagged as a malware.
  #110  
Old May 29th, 2012, 03:35 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: Av-comparatives April results

Quote:
Originally Posted by No_script
Webroot shouldn't **** itself if you block a few processes.

Well, it certainly won't break if you block a few processes. It's when you manually decide to block and manually delete Windows Explorer, rundll32, wuauclt, mscorsvw, wudfhost, wermgr, ... (the list goes on), that any operating system would get a bit angsty

Quote:
NONE, so rule that out. Webroot just hasn't picked up the infections I've got. But there are so many programs out there that are well respected as safe when they are not, Combofix & Bleechbit are 2 that are very very very dodgy to the point that they should be flagged as a malware.

Again, I haven't seen an actual infection on your PC, but there has been far too much clutter in the scan logs with incorrect actions to tell. If you could reimage and install Webroot but then do not change any configuration options or manually delete operating system files I'll gladly take a look at what remains in your scan log to see if you are indeed infected.
  #111  
Old May 29th, 2012, 08:19 AM
silverfox99 silverfox99 is offline
Regular Poster
 
Join Date: Jul 2006
Posts: 157
Default Re: Av-comparatives April results

Has the OP considered he may have been targeted by Flamer/SkyWiper...?

http://www.wilderssecurity.com/showthread.php?t=325011

Just sayin.
  #112  
Old May 29th, 2012, 09:25 AM
xXDarkStalkerxX xXDarkStalkerxX is offline
Frequent Poster
 
Join Date: Nov 2008
Posts: 272
Default Re: Av-comparatives April results

Joe , you sure got a saint 's patient. Professionalism all the way

Trolls nowadays are so easy to identify ...
  #113  
Old May 29th, 2012, 09:33 AM
No_script No_script is offline
Regular Poster
 
Join Date: May 2012
Posts: 97
Default Re: Av-comparatives April results

Knew it. I'm checking with the tool right now.

BTW Webroot turned off all settings on reboot, hmmmmm somethings up. Why would it turn itself off?

I think malware/attacker executing code in/to/through Webroot to shut itself down and infect the machine.
  #114  
Old May 29th, 2012, 10:54 AM
fax's Avatar
fax fax is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,562
Default Re: Av-comparatives April results

So far I have seen only the user getting heavily "infected"
  #115  
Old May 29th, 2012, 11:00 AM
Mongol's Avatar
Mongol Mongol is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: Houston, TX
Posts: 1,581
Default Re: Av-comparatives April results

Sounds to me like user error. Time to reformat or re-image...
__________________
"We are here on Earth to fart around. Don't let anybody tell you any different." –Kurt Vonnegut

Look N' Stop Firewall, Webroot Security Essentials, and AD Muncher 4.93
  #116  
Old May 29th, 2012, 11:07 AM
superssjdan's Avatar
superssjdan superssjdan is offline
Regular Poster
 
Join Date: Dec 2011
Location: USA
Posts: 111
Default Re: Av-comparatives April results

Definitely reformat.Reimage is ok assuming there was nothing screwed up in the first place and no changes made to critical system files before imaging,which i find hard to believe.Do yourself a favor and reformat unless somehow you think Webroot will get you infected after that as well
__________________
WSA-C 8.0.2.96
PrivateFirewall 7.0.29.1
Diskeeper 12 Pro /HitmanPro 3.7 Paid
Ad Muncher 4.93 paid/Acronis True Image Home 2013
corei5 650 8gddr3-1333 1tb int,1tb exter HD
XFX R7850 DDE 2Gig win8PROx64
  #117  
Old May 29th, 2012, 11:41 AM
Breakfastofchumps Breakfastofchumps is offline
Frequent Poster
 
Join Date: Jul 2011
Posts: 327
Default Re: Av-comparatives April results

I'd go a step further and zerofill.
__________________
Bitdefender internet security 2013
Emet
  #118  
Old May 29th, 2012, 03:19 PM
No_script No_script is offline
Regular Poster
 
Join Date: May 2012
Posts: 97
Default Re: Av-comparatives April results

There is no user error, I don't run crap programs like flash, java & harden my OS. Seriously so much fanboism going on.
  #119  
Old May 29th, 2012, 03:29 PM
Scoobs72 Scoobs72 is offline
Very Frequent Poster
 
Join Date: Jul 2007
Location: Sofa (left side)
Posts: 1,084
Default Re: Av-comparatives April results

Quote:
Originally Posted by No_script
There is no user error, I don't run crap programs like flash, java & harden my OS. Seriously so much fanboism going on.

But you did manually delete a bunch of operating system files as Joe states? Yes or no?
  #120  
Old May 29th, 2012, 03:40 PM
Sir Percy Sir Percy is offline
Regular Poster
 
Join Date: Apr 2010
Posts: 136
Default Re: Av-comparatives April results

Perhaps time to move the "No_script posts" to it's own thread, chances are he might learn something over the next weeks?

Then the rest of the world (fanboys the lot of them) can have this one to discuss the latest AV comparatives.
  #121  
Old May 29th, 2012, 04:41 PM
superssjdan's Avatar
superssjdan superssjdan is offline
Regular Poster
 
Join Date: Dec 2011
Location: USA
Posts: 111
Default Re: Av-comparatives April results

There is a big difference between hardening and breaking the os.It seems your hardening hasn't done you much good being you claim you are infected.I might suggest attending a Microsoft IT seminar nearest you.They are given all the time.You might learn a great deal
__________________
WSA-C 8.0.2.96
PrivateFirewall 7.0.29.1
Diskeeper 12 Pro /HitmanPro 3.7 Paid
Ad Muncher 4.93 paid/Acronis True Image Home 2013
corei5 650 8gddr3-1333 1tb int,1tb exter HD
XFX R7850 DDE 2Gig win8PROx64
  #122  
Old May 29th, 2012, 05:01 PM
No_script No_script is offline
Regular Poster
 
Join Date: May 2012
Posts: 97
Default Re: Av-comparatives April results

Quote:
Originally Posted by Scoobs72
But you did manually delete a bunch of operating system files as Joe states? Yes or no?

No, I installed a fresh image from the start. So there is no chance of anything being dirty or me deleting anything this time.


If you don't believe me explain this below. Seems a little fishy to me.
Quote:
[+] System Hijack

Value: Hidden
Data: 2
Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced

Value: EnableDCOM
Data: Y
Key: HKEY_LOCAL_MACHINE\Software\Microsoft\Ole

Value: Start
Data: 4
Key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess

Value: Wallpaper
Data: C:\Users\Consumer\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
Key: HKEY_CURRENT_USER\Control Panel\Desktop

Value: LoadAppInit_DLLs
Data: 1
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
  #123  
Old May 29th, 2012, 05:03 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: Av-comparatives April results

Those are all perfectly normal.....
  #124  
Old May 29th, 2012, 05:25 PM
fax's Avatar
fax fax is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,562
Default Re: Av-comparatives April results

LoL... this getting very funny... or tragic
PopCorn and beer ready here
  #125  
Old May 29th, 2012, 05:29 PM
Scoobs72 Scoobs72 is offline
Very Frequent Poster
 
Join Date: Jul 2007
Location: Sofa (left side)
Posts: 1,084
Default Re: Av-comparatives April results

Quote:
Originally Posted by No_script
...or me deleting anything this time.


So you did delete operating system files then? i.e. WSA's log is correct?
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:32 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums