Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 26th, 2009, 02:28 PM
1boss1's Avatar
1boss1 1boss1 is offline
Frequent Poster
 
Join Date: Jun 2009
Location: Australia
Posts: 401
Default Malware Defender - Usage Tips & Tricks?

Hello everyone,

I've been lurking here just reading for a few weeks, and the wealth of information is fantastic Wilders is a great community. I won't name everyone who has posted advice that's helped me, because i am bound to miss somebody.

Anyhow, i have Malware Defender (awesome product Xiaolin) and i was wondering if anyone knew of any articles/posts that had tips for getting the most out of MD?

Such as how to use it to recognize rootkits, keyloggers, backdoors etc.

For instance under "Hooks" i have items in red with "Unknown Module" and listed as "Not Verified" and don't know if they are bad and how bad they are. Also what things should i look out for in "Autostarts" that may be problematic.

Also "Kernal Modules" i have items in red with no publisher, no description etc example: http://i41.tinypic.com/13z6a77.png

Also how about hardening of default Windows components in the rules?

I know this is quite broad, but everything i've encountered assumes a sound working knowledge of HIPS software and the usage of MD. I really want to understand MD and start using properly but without a gentle shove in the right direction it's hard to know if i'm doing the right thing.

I can see HIPS offers massive benefits over signature based programs, but only if the HIPS is used right so i want to persist until MD and i can protect this machine with confidence.

Note: After reading here, i now have Sandboxie for running untrusted software which launches with RegFromApp to see registry changes. I have Malwarebytes & SuperAntiSpyware for on-demand scanning. I also have Outpost Pro (not real fond of it) plus Norton 09 for real time stuff.

Thanks.
  #2  
Old June 26th, 2009, 03:41 PM
apathy's Avatar
apathy apathy is offline
Frequent Poster
 
Join Date: Dec 2004
Location: 9th Circle of Hell(Florida)
Posts: 366
Default Re: Malware Defender - Usage Tips & Tricks?

I could definately use that myself, this thread is informative:
__________________
Setup For My Lenovo Ideapad Z575 12992KU
OS: Opensuse 12.3(KDE)

Spideroak | Nvpy | syncBackup(Rsync) | AirVPN | Glippy | Clementine | Thunderbird | Chromium w/ Vimium | Autokey | LFTP
  #3  
Old June 26th, 2009, 03:55 PM
LoneWolf's Avatar
LoneWolf LoneWolf is offline
Massive Poster
 
Join Date: Jan 2006
Posts: 3,133
Default Re: Malware Defender - Usage Tips & Tricks?

Check this thread for some tips......
http://www.wilderssecurity.com/showt...3728&highlight

Don't think you need to config MD for keyloggers and such as posted here.......
http://www.wilderssecurity.com/showt...4519&highlight

I assume you have read MD's help file.
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness

Last edited by LoneWolf : June 26th, 2009 at 04:16 PM.
  #4  
Old June 28th, 2009, 06:33 PM
1boss1's Avatar
1boss1 1boss1 is offline
Frequent Poster
 
Join Date: Jun 2009
Location: Australia
Posts: 401
Default Re: Malware Defender - Usage Tips & Tricks?

Quote:
Originally Posted by apathy
I could definately use that myself, this thread is informative:

Yes Malware Defender is very powerful, it seems the articles and documentation only scratch the surface of this powerful app.

That's a good thread (screenshots are a bonus) although i did manage to BSOD my computer trying to follow it.

Many things in it are different than on my MD/System.

Quote:
Originally Posted by LoneWolf
Check this thread for some tips......
http://www.wilderssecurity.com/showt...3728&highlight

Don't think you need to config MD for keyloggers and such as posted here.......
http://www.wilderssecurity.com/showt...4519&highlight

I assume you have read MD's help file.

No i have not seen MD's help file, where is that? On the MD sites FAQ it just explains what is Malware and what is HIPS in 2 paragraphs and that's all the documentation.

Thanks for those 2 links also, it's going to take a while to get the hang of this i see. For now i've only got "File Protection" and "Registry Protection" running because enabling Network & Application protection was killing me with pop-ups and i'm not to sure how to handle the rules.

I'm starting to think for me (at least for now) MD is best used as a system inspection tool rather than a protection tool because without a grasp on the rules i'm likely just to approve malware.
  #5  
Old June 28th, 2009, 08:10 PM
arran's Avatar
arran arran is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 1,091
Default Re: Malware Defender - Usage Tips & Tricks?

unfortunately it's help file has limited information.

Malware Defender is not for the Faint Hearted. Its more for technical users. To learn how it works properly you have to have patience and spend time playing around with it.
__________________
Win7 64bit Ultimate
Sandboxie | Applocker | Admuncher | Macrium Reflect | TrueCrypt |
FF Add On's | Greasemonkey | Secure Login | Noscript | Ant Video downloader | Status 4 evar
  #6  
Old June 28th, 2009, 10:45 PM
xiaolin xiaolin is offline
Frequent Poster
 
Join Date: Aug 2008
Posts: 248
Default Re: Malware Defender - Usage Tips & Tricks?

Quote:
Originally Posted by arran
unfortunately it's help file has limited information.
You are right.

I will write some tutorials later.
  #7  
Old June 29th, 2009, 07:10 AM
LoneWolf's Avatar
LoneWolf LoneWolf is offline
Massive Poster
 
Join Date: Jan 2006
Posts: 3,133
Default Re: Malware Defender - Usage Tips & Tricks?

Quote:
Originally Posted by 1boss1
No i have not seen MD's help file, where is that? On the MD sites FAQ it just explains what is Malware and what is HIPS in 2 paragraphs and that's all the documentation.

Open MD, left click "help", left click "help topics".

Quote:
Originally Posted by 1boss1
Thanks for those 2 links also, it's going to take a while to get the hang of this i see. For now i've only got "File Protection" and "Registry Protection" running because enabling Network & Application protection was killing me with pop-ups and i'm not to sure how to handle the rules.

I'm starting to think for me (at least for now) MD is best used as a system inspection tool rather than a protection tool because without a grasp on the rules i'm likely just to approve malware.


There is a learning curve for understsnding MD as with any classical HIPS.
I would sugggest starting out in "learning mode" for a few days, running all your normal programs as well as rebooting a few times so MD can learn your system.
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness
  #8  
Old June 30th, 2009, 12:35 AM
JosephB JosephB is online now
Frequent Poster
 
Join Date: Jan 2008
Posts: 248
Default Re: Malware Defender - Usage Tips & Tricks?

Planning on trying MD very soon and I was wondering .....

Has anyone tried and tested running the 3rd party defragmenters of PerfectDisk and Diskeeper Pro on a pc running MD ?

... Do they get along without any issues ?
... When using PerfectDisk and Diskeeper Pro can one use their options of performing a "boot time - defrag" (aka defrag before windows loads) with MD without any potential conflicts or issues ?
  #9  
Old June 30th, 2009, 02:08 AM
mike21's Avatar
mike21 mike21 is offline
Frequent Poster
 
Join Date: Jun 2006
Posts: 404
Default Re: Malware Defender - Usage Tips & Tricks?

that won't be a problem

just use learning mode to automatically create rules about defrag & boot defrag
__________________
Webroot SecureAnywhere
  #10  
Old June 30th, 2009, 02:29 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,770
Default Re: Malware Defender - Usage Tips & Tricks?

Quote:
Originally Posted by mike21
that won't be a problem

just use learning mode to automatically create rules about defrag & boot defrag
that is what i call piece of cake
__________________
Emsisoft Anti-Malware 7.0
  #11  
Old July 1st, 2009, 05:05 AM
1boss1's Avatar
1boss1 1boss1 is offline
Frequent Poster
 
Join Date: Jun 2009
Location: Australia
Posts: 401
Default Re: Malware Defender - Usage Tips & Tricks?

Quote:
Originally Posted by xiaolin
You are right.

I will write some tutorials later.

Excellent thanks Xiaolin, keep up the great work

These ones have got me wondering/concerned:

Kernel Modules: http://i41.tinypic.com/13z6a77.png
Hooks: http://i42.tinypic.com/1zei4xf.png

For the Hooks, the ones without a description and that say "Unknown Module" i can't right click and "Locate in Windows Explorer" like i can with others so i can't find the .sys name to Google.

Are these Unknown Hooks safe to Right Click > Unhook?

Also for the "Kernel Modules" that are not found, for instance the first one awhrnf4m.sys it's 404 plus i Googled and there's zero results. Would it be safe to search in registry and delete the keys pertaining to it? (Backing up the registry state prior of course)

Quote:
Originally Posted by LoneWolf
Open MD, left click "help", left click "help topics".

There is a learning curve for understsnding MD as with any classical HIPS.
I would sugggest starting out in "learning mode" for a few days, running all your normal programs as well as rebooting a few times so MD can learn your system.

I'm usually a fan of RTFM, but i completely overlooked the inbuilt help topics. That's a mistake, there's tons of helpful info in there thanks LoneWolf.. So to anyone else new to Malware Defender first stop should be:

Help > Help Topics

Yes i run MD in learning mode for a few days, but i think that wasn't long enough for me. I have a "lot" of applications installed, i do SEO/Web Development so i have everything from Xampp to Photoshop to site architecture analysis tools.

I might throw MD back in learning mode for a week and make a conscious effort to open and use all tools.

BTW would the abbreviation for Classical HIPS be CHIPS?
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:10 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums