![]() |
|
#26
|
|||
|
|||
|
Quote:
My whole security is partial based on restoration, the ultimate weapon against any infection. I only need more time to polish it. ![]() An extreme test for FDISR, would be a honeypot and then try to clean that honeypot with a clean snapshot. ![]() Unfortunately, none of the security people are interested to do such a test, they prefer to test scanners to prove how many infections they MISSED and how many false/positives they reported. That doesn't interest me, because I know this already. ![]()
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
Last edited by ErikAlbert : April 24th, 2007 at 10:04 AM. |
|
#27
|
||||
|
||||
|
Quote:
Isn't converting A Vista snapshot, into an XP snapshot using an FDISR archive enough of a test for you. ![]() |
|
#28
|
|||
|
|||
|
Quote:
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
|
|
#29
|
||||
|
||||
|
Quote:
Same principle. Okay I will screw up my system with DFK Threat Simulator, a bit later. |
|
#30
|
|||
|
|||
|
Quote:
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
|
|
#31
|
||||
|
||||
|
Quote:
Google it, and read the description. Sure makes a mess of the system, albeit with defanged stuff. Also comes with an uninstaller which I didn't bother with using. |
|
#32
|
|||
|
|||
|
Quote:
Nevertheless, I will try it myself one day, when I'm ready. I remember the BBC Honeypot and they admitted, that this honeypot couldn't be cleaned with the classical security softwares. The honeypot had to be re-installed from scratch to clean it completely. If FDISR is able to clean such a honeypot, I would feel more comfortable.
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
|
|
#33
|
||||
|
||||
|
Quote:
No matter how bad it is, it is still just files. Do you have a link to the BBC Honeypot. Pete |
|
#34
|
|||
|
|||
|
Quote:
http://news.bbc.co.uk/2/hi/technology/5414502.stm http://news.bbc.co.uk/1/hi/technology/6035455.stm These are the threads at Wilders about the BBC Honeypot : http://www.wilderssecurity.com/showt...light=Honeypot http://www.wilderssecurity.com/showt...479#post854479
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
Last edited by ErikAlbert : April 24th, 2007 at 01:06 PM. |
|
#35
|
||||
|
||||
|
Quote:
I found them, but since I sit behind a router, I can't really do a honeypot test. To much of a physical cabling mess to get around it. But I may play with some live malware in my VM machine. |
|
#36
|
|||
|
|||
|
Quote:
Your VISTA--->XP test was also very extreme, that's why I believe it will remove any infection as well, BUT I would feel more comfortable, if it also cleaned a HEAVY INFECTED honeypot without any failure. IBK (av-comparatives) has also an enormous test bed to test all these Anti-Virus softwares, so his test bed is also a very extreme test for FDISR. (hint) ![]()
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
Last edited by ErikAlbert : April 24th, 2007 at 03:00 PM. |
|
#37
|
||||
|
||||
|
A while ago I was listening to a 'Security Now!' episode about sandboxing applications over at GRC.com and I remember Steve Gibson comparing different sandboxing applications and coming to the conclusion that SandboxIE was one of his favorite in the way in which the programs were designed.
Some may find this episode interesting: http://www.grc.com/SecurityNow.htm#55
__________________
·▪¤•●"Mash For Our Dreams"●•¤▪·
|
|
#38
|
||||
|
||||
|
Is he using FDISR or u want him to push this way?
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#39
|
||||
|
||||
|
I think he was hinting that FDISR has yet to let down av-comparatives
![]()
__________________
·▪¤•●"Mash For Our Dreams"●•¤▪·
|
|
#40
|
||||
|
||||
|
lol...
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#41
|
|||
|
|||
|
Quote:
Maybe he will enjoy it, doing something else for a change.
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
|
|
#42
|
|||
|
|||
|
Well Sandboxie causes the first error on my computer, never had that before.
Suddenly a popup window appears on my desktop, when I want to open Firefox : Direct OCR Error (= Popup Window Title) An error with Direct OCR caused a memory conflict in your open applications. Please restart Windows. It happened several times today.
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
|
|
#43
|
||||
|
||||
|
OCR, is that Optical Character Recognition and relating to a document scanner software?
Had a look around SB's forum and couldn't find anything related.
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
|
#44
|
|||
|
|||
|
Quote:
![]()
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
|
|
#45
|
||||
|
||||
|
Quote:
True, for one Sandboxie can hold browser related, cache etc, so when you delete the sandbox the byproducts such as history disappears, but Sandboxie is more than that - and files can be undeleted.
__________________
Who controls the past controls the future Who controls the present controls the past vmworld |
|
#46
|
||||
|
||||
|
Quote:
Quote:
|
|
#47
|
|||
|
|||
|
Franklin and BobD,
Thanks for the info you gave me, because it did ring a bell. I posted this problem at SB-forum in my post "Direct OCR Error" and gave them more info concerning my all-in-one printer and the software of this printer installed a bar called "Canon Easy-WebPrint" and this bar could be the problem. Firefox doesn't have this bar, but I switched often between Firefox and MSIE, while I was running Sandboxie. I'm waiting for a reply of Tzuk and if necessary, I'm going to uninstall this bar and see if there is an improvement. I'm almost 100% sure that this bar IS the problem. Sandboxie is alot more important to me than this bar, which I don't use in practice.
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
|
|
#48
|
||||
|
||||
|
I've started testing some real malware to see how well I am protected both against the malware and myself. Programs I commonly run are SSM OA, KAV and sandboxie. Then also as Erik challenged recovery.
I started with Killdisk, and this thing is about as nasty as it gets. Both OA and SSM block it providing I am smart enough to not let it run. KAV even without PDM flat wouldn't let it run. Even when I said skip to it's alert of a virus it wouldn't let it run. I finally had to disable it. When I ran Killdisk inside the sandbox, it failed. Sandboxie effectly protected me against it. Excellent. THen I ran it an let it do it's evil deed to check on recovery. On reboot all I got was a fatal partition error. FDISR is out of the picture. Then I tried a simple restore with Shadow Protect and it also failed. I had to run DiskPart to delete the messed up partition that killdeed left behind. Then I was able to restore the Shadow Protect image. This test also showed just how effective VMware machines are. I took a vm snapshot before the test, and while in the damage state of the disk, revert to the snapshot. Everything was perfect. Pete |
|
#49
|
|||
|
|||
|
Quote:
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
|
|
#50
|
||||
|
||||
|
Quote:
If by zero it you mean format it no. I tried that first. I had to go in and use Diskpart to delete the partition. BTW, neither Acronis True Image or Disk Director could do anything with until DiskPart was run. This is indeed one nasty dude. But the bright side Sandboxie stopped it cold. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|