Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 6th, 2010, 03:13 PM
Gullible Jones
 
Posts: n/a
Default Anything like Returnil 2008's anti-exec plugin?

I'm currently looking around in vain for something like R2008's anti-executable plugin. Why? Because it offers something very basic that many HIPS don't have... It's got both a query (Allow/Deny/Remember Decision) mode, and a whiltelist mode where it blocks everything not explicitly allowed.

I've tried some alternatives...

- Trust-No-Exe: has whitelisting, but no query mode.
- Winsonar: doesn't query for new executables during training, which from a security standpoint isn't as good (at least IMO).
- Privatefirewall/Outpost Free: no whitelist mode, only popups. Also, Outpost stupidly defaults to the "Allow" option for some popups.

Is there anything else like this, either free or reasonably priced for home use? Failing that, is the most recent version of Returnil 2008 secure enough to be usable?
  #2  
Old April 6th, 2010, 03:25 PM
Creer's Avatar
Creer Creer is offline
Very Frequent Poster
 
Join Date: Jun 2008
Posts: 1,203
Default Re: Anything like Returnil 2008's anti-exec plugin?

How about SRP built-in Windows tool:
http://www.mechbgon.com/srp/
  #3  
Old April 6th, 2010, 03:59 PM
ratwing
 
Posts: n/a
Default Re: Anything like Returnil 2008's anti-exec plugin?

Hello Gullible Jones


When I left Returnil after 2008 was phased out,, I was in the same position.
I tried Process Guard,but it seemed a pretty bulky solution to try
and replace the elegantly simple no-overhead Returnil 2008 AE module.

I would feel safe with Returnil 2008,but my licence is expired,and there is no
way to renew.

I made a sort mini white list based "anti-executable" out of my sandbox
for WindowsExplorer.

It takes a little time to file path "white list" what you want to allow,and it is default deny of course,no chance to allow/deny,on the fly,but it works ok.
  #4  
Old April 6th, 2010, 04:31 PM
Gullible Jones
 
Posts: n/a
Default Re: Anything like Returnil 2008's anti-exec plugin?

Re SRP: It's useful, but it's whitelist only, no prompting. Although, it would probably be an ideal base for an anti-executable app. (Which is why I proposed the SRP shell extension earlier. )

But yeah, I tend to test a fair amount of software, so no prompt pretty much means no go.
  #5  
Old April 6th, 2010, 08:01 PM
Gullible Jones
 
Posts: n/a
Default Re: Anything like Returnil 2008's anti-exec plugin?

Well FWIW Returnil 2008 Personal is right out, because it seems to have up and disappeared from the web. The only download link I was able to find (aside from the numerous links to pirated versions ) was on Brothersoft, which is itself infamous for distributing malware. C'mon guys, can't you even keep just the paid version of 2008 around?

Edit: oh one more thing... I just realized, to be actually secure a whitelist app would have to be based on checksums rather than path rules (since a subverted application could just replace something in C:\Program Files\whatever and run it from there). SRP *can* handle that, but unfortunately PGS can't, so it's out too.
  #6  
Old April 6th, 2010, 08:30 PM
nanana1's Avatar
nanana1 nanana1 is offline
Frequent Poster
 
Join Date: Jun 2007
Posts: 947
Default Re: Anything like Returnil 2008's anti-exec plugin?

Quote:
Originally Posted by ratwing
I would feel safe with Returnil 2008,but my licence is expired,and there is no way to renew.

@ratwing

Good news for you ! Returnil Subscription Giveaway now running for all forum members now.

http://www.wilderssecurity.com/showt...47#post1648347
  #7  
Old April 6th, 2010, 08:52 PM
ratwing
 
Posts: n/a
Default Re: Anything like Returnil 2008's anti-exec plugin?

Thank you nanana1!!

I have already taken advantage of this generous give-away,and while Returnil 2010 is a class act, I returned to ShadowDefender.

I know the GUI,I like right click commit,at least for small to moderate sized files,and the resource use is perfect for my machine.

But Returnil 2008 Premium,that was a classic.
  #8  
Old April 7th, 2010, 09:36 AM
1000db's Avatar
1000db 1000db is offline
Frequent Poster
 
Join Date: Jan 2009
Location: Missouri
Posts: 672
Default Re: Anything like Returnil 2008's anti-exec plugin?

AppGuard
  #9  
Old April 7th, 2010, 09:57 AM
noway noway is offline
Frequent Poster
 
Join Date: Apr 2005
Posts: 346
Default Re: Anything like Returnil 2008's anti-exec plugin?

Faronics Anti-Executable Standard

http://www.faronics.com/en/default.aspx
  #10  
Old April 7th, 2010, 12:18 PM
raven211's Avatar
raven211 raven211 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,567
Default Re: Anything like Returnil 2008's anti-exec plugin?

Quote:
Originally Posted by noway
Faronics Anti-Executable Standard

http://www.faronics.com/en/default.aspx

Every time I thought about that one.
  #11  
Old April 7th, 2010, 08:09 PM
jdd58's Avatar
jdd58 jdd58 is offline
Frequent Poster
 
Join Date: Jan 2008
Location: Iowa
Posts: 415
Default Re: Anything like Returnil 2008's anti-exec plugin?

I have been searching for the same thing. I just uninstalled Returnil 2008 free yesterday to try some of the others mentioned here already. The pc I'm experimenting with already has XP Pro with LUA, SRP, SuRun. Looking to cover any other bases. I wish Returnil would go back to this version and make it 64 bit compatible.

Quote:
Originally Posted by Gullible Jones
Well FWIW Returnil 2008 Personal is right out, because it seems to have up and disappeared from the web. The only download link I was able to find (aside from the numerous links to pirated versions ) was on Brothersoft, which is itself infamous for distributing malware. C'mon guys, can't you even keep just the paid version of 2008 around?

The Brothersoft file has the same md5 checksum as the one I've had on my pc for some time now. Mine was either downloaded from Returnil or Majorgeeks so the Brothersoft one is probably OK.
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:28 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums