![]() |
|
#276
|
||||
|
||||
|
Quote:
Best regards, KOR! P.S. Rollback Rx has neither an anti-virus nor a malware engine! |
|
#277
|
|||
|
|||
|
Quote:
If you are suggesting that you cannot rollback a system when you get hit by any type of malware, regardless of its sophistication then that is utterly untrue. Where rolling back to a previous snapshot may not work is with malware that modifies the MBR or performs low level disk access. |
|
#278
|
||||
|
||||
|
Quote:
Even programs like Acronis True Image or Acronis Disk Director, if they are uninstalled with let say Total Uninstall, can break Rollback Rx. Has happen to me before! Best regards, KOR! |
|
#279
|
|||
|
|||
|
Quote:
Glad you agree with me then. Rollback RX could recover your system as long as: 1. You still have a clean snapshot 2. The malware was not of the MBR-modifying or direct disk access type Quote:
I would never uninstall programs such as those with Total Uninstall - you're just asking for trouble. Don't blame Rollback RX for that. Bottom-line - Rollback RX is not a solution designed to protect you from malware, but depending on the type of infection you have, you have a reasonable chance of being able to recover a previous snapshot. |
|
#280
|
||||
|
||||
|
Quote:
Quote:
Does Rollback Rx advises as such to their regular users about uninstalling programs as I mentioned with Total Uninstall? Can you provide some kind of links on this from HDS? Best regards, KOR! |
|
#281
|
||||
|
||||
|
Guys, when I said "unsophisticated malware" I meant malware that do not modify the MBR and that are not aware of the existence of LV or of RX and its snapshots. There are a lot of crude malware out there which wouldn't have a clue that the system they have infected contains snapshots. Infections by such malware on RX or CTM systems can be easily undone just by restoring an older snapshot, for as long as the malware hasn't modified the MBR. It has happened to me in the past when I was testing CTM and RX with basic malware. All it took to get rid of them was to restore an older snapshot at next reboot, and all 'dumb' malware were history.
Of course CTM and RX cannot protect against malware. Protect is the wrong word to use when we talk about LV and snapshot apps. But such solutions can most definitely undo most 'dumb' infections. This is an absolute fact proven by empirical data, and as such it is non-debatable. BTW King, the CTM and RX snapshots are hidden in a much better way than the simple Windows restore points. Not even the OS is aware of their existence, so it is highly unlikely that any unsophisticated malware would ever know that there are snapshot data stored on the disk's free space.
__________________
I want to boldly go where no one has gone before. They just won't let me. Last edited by CyberMan969 : June 9th, 2012 at 07:26 PM. |
|
#282
|
||||
|
||||
|
Quote:
Of course is the protection.
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski SG.pl |
|
#283
|
||||
|
||||
|
after reading those 12 pages , i can say SD is still better
![]()
__________________
Win7 Firewall |Webroot SA Complete (Beta) |ExeRadarPro | Sandboxie Free | Shadow Defender | AX64 Time Machine | Rollback RX | My Reviews/Guides |
|
#284
|
|||
|
|||
|
Looks like it has been updated to:
1.8.6.0 Still no info about changes on the main page... rrrh1 (arch1) |
|
#285
|
||||
|
||||
|
V 1.9.0.0(June 20 2012)
•Enhanced MBR protection •Start the protection when driver is loaded •Add protection to the password file •Fixed the rename bug for File Locker. •Added one more virtulization engine to the kernel Still no RAM usage for the virtualization cache... How hard can it be?? OK guys, anyone willing to throw some malware to it, see if it works?
__________________
I want to boldly go where no one has gone before. They just won't let me. |
|
#286
|
||||
|
||||
|
Quote:
![]() BTW...it was also v. 1.8.7 beta...quote from forum TTF Quote:
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski SG.pl |
|
#287
|
||||
|
||||
|
OK...test for version 1.9.0.0 is ready. Unfortunately the result is still bad for TTF in protection against TDSS. Toolwiz again should to do something with this.
-http://www.youtube.com/watch?v=OLh9UKmP2YE-
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski SG.pl |
|
#288
|
||||
|
||||
|
Quote:
Can any LV program successfully contain the latest TDSS variants within its virtual space (infection-free on reboot)?
__________________
Shadow Defender, Avast AV, Privatefirewall, and Image For Windows are 'on the job' here. Last edited by The Shadow : June 23rd, 2012 at 10:09 AM. |
|
#289
|
||||
|
||||
|
In the inner test of SG BufferZone passed anti-TDSS test but it was in February 2011. I don't know some other latest similar test.
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski SG.pl |
|
#290
|
|||
|
|||
|
I'm not familiar with BufferZone. Is it similar in function to Sandboxie? Can you use it to test new software then get rid of it with a reboot, or isn't it that type of virtualization app?
Last edited by TomAZ : June 23rd, 2012 at 02:22 PM. |
|
#291
|
||||
|
||||
|
Anyone knows where can I can find a recent sample of TDSS or any similar rootkits? I have an older computer that I want to use as a test machine for LV software.
__________________
I want to boldly go where no one has gone before. They just won't let me. |
|
#292
|
||||
|
||||
|
Quote:
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski SG.pl |
|
#293
|
||||
|
||||
|
Quote:
From the light virtualisation programs Shadow Defender is still the only one that is successfull against TDL type rootkits. |
|
#294
|
||||
|
||||
|
Quote:
@ ichito, do you know of any tests that disprove or update the LV-rootkit tests that were performed 2 years ago? TS
__________________
Shadow Defender, Avast AV, Privatefirewall, and Image For Windows are 'on the job' here. Last edited by The Shadow : June 23rd, 2012 at 04:26 PM. |
|
#295
|
||||
|
||||
|
Quote:
I can't speak for the actual Toolwiz (but ichito showed), but for Returnil, Wondershare etc. it is still true, I testet some weeks ago. Returnil moderator here often claims their product protects, but that is only true if AE blocks the sample (not always in default settings) or AV signatures exist. But from virtualisation part Returnil is not successful against TDL3/4. @CyberMan969: You can use every TDL3 and TDL4 sample if you wanna test, just allow execution. The behaviour is the same, real new ones aren't there. |
|
#296
|
||||
|
||||
|
Quote:
I couldn't find any samples to download at all. Any links? Thanks in advance!
__________________
I want to boldly go where no one has gone before. They just won't let me. |
|
#297
|
||||
|
||||
|
Quote:
__________________
Shadow Defender, Avast AV, Privatefirewall, and Image For Windows are 'on the job' here. |
|
#298
|
||||
|
||||
|
Quote:
I've mentioned earlier in other places of forum about those tests but "all together now"Returnil -http://www.youtube.com/watch?v=dt3-y39FckA WTF -http://www.youtube.com/watch?v=dI-MdSIUtiY&feature=relmfu SD -http://www.youtube.com/watch?v=QFYHDMiot6U Now about WTF Quote:
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski SG.pl |
|
#299
|
|||
|
|||
|
According to the performed tests Toolwiz Time Freeze basically withstands TDSS. Yes, the file system is there but the rootkit itself is not so this is basically a "pass", not "fail", since the file system is harmless without the active rootkit. If I recall correctly the same thing happened during my tests of Returnil System Safe.
|
|
#300
|
||||
|
||||
|
Quote:
so WTF and SD seem to have to exact same results from malwarebytes. So did WTF withstand those rootkit infections? Would have been nice if they added another hitman pro scan to see if there's any difference.
__________________
AppGuard - Deep Freeze - EMET - Drive SnapShot - OpenDNS - NAT Router |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|