![]() |
|
#26
|
||||
|
||||
|
Quote:
The big problem for Anti-execution security layer is social engineering. The hacker can just obfuscate his malware into something a victim would likely execute or click. [HIPS can probably catch suspicious behaviours like dll injections, driver loading, keystroke logging, etc.] The hacker also can use exploit to do the job. For e.g, the Duqu malware was pushed by a zero day kernel exploit after opening a seemingly innocuous Word document. They said all security layers are bypassable by any kernel exploit but Faronics claimed they can still catch the main dll of that malware from executing, which I doubt.
__________________
-http://www.veteranstoday.com/author/henderson/ -http://www.veteranstoday.com/2013/03/04/the-911-illusion-patsies-beneficiaries/ Last edited by trismegistos : April 22nd, 2012 at 11:54 PM. |
|
#27
|
||||
|
||||
|
interesting thread/topic
.....just to input info on how Dr. protect itself:Dr.Web is immune to any attempts by malicious programs to disrupt its operation. Dr.Web SelfPROtect is the unique anti-virus component that maintains the anti-virus’ security. * Dr.Web SelfPROtect is implemented as a driver that operates on the lowest system level. The driver can’t be stopped or unloaded without a system reboot. * Dr.Web SelfPROtect restricts access to a network, files and folders, certain branches of the Windows Registry and removable data-storage devices on the system driver level and protects the software from anti-antiviruses aiming to disrupt the operation of Dr.Web. * Some anti-viruses modify the Windows kernel through intercepting interrupts, changing vector tables or using other undocumented features. This may have a negative impact on the stability of a system and pave new ways for malicious programs to get into a system. At the same time, Dr.Web SelfPROtect maintains security of the anti-virus and doesn’t interfere with routines of the Windows kernel. * New! Automatic restoring of anti-virus modules
__________________
✓The first principle is that you must not fool yourself, and you are the easiest person to fool. ✓Science is the belief in the ignorance of experts. ✓I don't know anything, but I do know that everything is interesting if you go into it deeply enough. -------Richard P. Feynman--------- |
|
#28
|
||||
|
||||
|
wouldn't hurt to try Drweb protection
i will report back later BTW extremely helpful Post trismegistos's
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker "Uncommon sense will increase your privacy; common sense will just make you common." "The Worst Thing in the World is To look and not be able to Help " |
|
#29
|
||||
|
||||
|
I know WSA is password protected to stop services or uninstall.
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|