![]() |
|
#26
|
|||
|
|||
|
Quote:
![]()
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
|
|
#27
|
|||
|
|||
|
Quote:
Obviously not just text files it attacks. http://www.symantec.com/security_res...723-99&tabid=2 I guess the best I could do with EQS would be to limit access to these files types. Thinking of the number of pop-up's, don't think I'll bother. Do any behavioural blockers like Threatfire or Mamutu detect this kind of behaviour? What about Defensewall? Seems to me that protection from ransomware like this is something for a 'smart' behavioural blocker rather than a classical HIP's.
__________________
Online-Armor | Defensewall | EQSecure 3.41 | AntiVir | Returnil |Sandboxie | A-squared Anti-Malware |
|
#28
|
||||
|
||||
|
Seems you are right. I have not tried behav blockers with this malware but will try to test with TF.
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#29
|
||||
|
||||
|
Quote:
![]()
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#30
|
||||
|
||||
|
Quote:
Hello hammerman, I have personally tested the GPcode trojan in question against both DefenseWall and Primary Response SafeConnect. The former was able to successfully block and contain it while the latter was not. Peace & Gratitude, CogitoErgoSum
__________________
Current Vista 32 SP2 Resident Security Arsenal: (DefenseWall Personal Firewall v3.11 - KeyScrambler Pro) DefenseWall HIPS(http://www.softsphere.com/) *Loyal & diehard DefenseWall user since 1/06!* ~Living dangerously without a resident antivirus since late 2/07!~
|
|
#31
|
||||
|
||||
|
Quote:
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender |
|
#32
|
||||
|
||||
|
Quote:
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#33
|
||||
|
||||
|
Quote:
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#34
|
||||
|
||||
|
Quote:
__________________
"Pouvoir à l'Imagination. Power to the imagination. La imaginación al poder". "Perfect is the enemy of good enough". Voltaire. |
|
#35
|
|||
|
|||
|
Quote:
Thanks for test results. Didn't expect DW (or GW) to protect against this. I thought protection from ransomware would be more prominent in their feature list. Any chance you could PM me a link to GPcode. I'd like to test against OA's run safer and Mamutu.
__________________
Online-Armor | Defensewall | EQSecure 3.41 | AntiVir | Returnil |Sandboxie | A-squared Anti-Malware |
|
#36
|
|||
|
|||
|
Quote:
![]()
__________________
DefenseWall HIPS developer. www.softsphere.com |
|
#37
|
|||
|
|||
|
Quote:
Lesson learnt. Seems like this protection could be quite unique though. Looking forward to seeing if TF and Mamutu are up to the challenge. Response from OA is that this is a feature that may be added in future. Does DW protect against GPcode simply by running malware file untrusted or does the resource protection need to be used?
__________________
Online-Armor | Defensewall | EQSecure 3.41 | AntiVir | Returnil |Sandboxie | A-squared Anti-Malware |
|
#38
|
||||
|
||||
|
Quote:
If this threat is the KD.exe, then Sandboxie protects. Also OA actually does now in some ways. If the exe is downloaded from the web thru a drive by, and you are running your browsers with Run Safer, it will indeed not allow this thing to do damage. I've tested that. Also OA will have two new features. One is direct disk access, and other is automatically running an unknown program at lower rights. Test both in beta's and both work. Pete |
|
#39
|
|||
|
|||
|
Quote:
__________________
DefenseWall HIPS developer. www.softsphere.com |
|
#40
|
|||
|
|||
|
Tested sample of GPcodei courtesy CogitoErgoSum.
Sandboxie completely isolates infection OA run safer fails to protect Mamutu quiet as a mouse in Paranoid Mode (waste of good memory space IMO) AntiVir detects infection EQS 3.41 unable to do anything about it
__________________
Online-Armor | Defensewall | EQSecure 3.41 | AntiVir | Returnil |Sandboxie | A-squared Anti-Malware |
|
#41
|
|||
|
|||
|
Quote:
Thanks Ilya, I haven't used DW for a while since there is a conflict on my system when I run Sandboxie, OA and DW together. As I understand it, an untrusted process cannot modify any other files and this is how it protects against GPcode. Are you saying there are some exceptions to this rule for certain file types?
__________________
Online-Armor | Defensewall | EQSecure 3.41 | AntiVir | Returnil |Sandboxie | A-squared Anti-Malware |
|
#42
|
||||
|
||||
|
Quote:
No, it,s not.
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#43
|
||||
|
||||
|
Okay. Got a sample and tested. Nasty little critter.
ShadowDefender did it's job well as did Sandboxie. OA's Runsafer didn't and couldn't do anything. I would suspect none of the policy based sandbox will. I ran it with both OA and SSM on to see what it was doing. Both just alerted it wanted to run. It did nothing else, so clearly it didn't need system privileges. By the time the next pop up's came about the vbs file, it was too late. Pete |
|
#44
|
||||
|
||||
|
Quote:
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#45
|
||||
|
||||
|
Quote:
Okay, so they are protecting files also? |
|
#46
|
||||
|
||||
|
I would like to test this GPcode do not have sample though
![]()
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB. |
|
#47
|
||||
|
||||
|
Quote:
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#48
|
||||
|
||||
|
Quote:
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, Last edited by aigle : July 7th, 2008 at 10:44 PM. |
|
#49
|
||||
|
||||
|
thanks.I will post after test.Here is what I got from KAV.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB. Last edited by Dark Shadow : July 7th, 2008 at 10:41 PM. |
|
#50
|
||||
|
||||
|
I tried it with GW to be sure. Excellent job by GW on default settings.
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, Last edited by aigle : July 7th, 2008 at 10:37 PM. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|