Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Ghost Security Suite (GSS)
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 12th, 2005, 12:17 PM
Jason_R0's Avatar
Jason_R0 Jason_R0 is offline
Developer
 
Join Date: Feb 2005
Location: Australia
Posts: 1,038
Default RegDefend v1.300 Released!

http://www.ghostsecurity.com/index.php?page=regdefend

Please uninstall your current RegDefend version before installing this one, and make sure you reboot. You should not install over the top of an existing installation.

What is RegDefend?
RegDefend is a kernel based registry protection system, designed to use as few resources as possible. Instead of polling the registry looking for changes, RegDefend intercepts the changes before they occur. RegDefend comes installed to protect registry autostarts and some special registry keys, custom rules can also be added.

New features and changes since the last version :-

-Fast and powerful registry monitoring added with a full compliment of filtering abilities during and after capture
-If a registry item is set to "ASK USER" and the operation being performed is "set value" AND the data is the same as exists currently in the registry, then no alert will occur anymore. ie it now checks what is written to what is already there, if the same then it will "allow" the operation to occur.
-If the desktop is switched whilst an alert is being displayed or going to be displayed, then RegDefend will simply block the operation by default instead of asking the user.
-Fixed balloon alerts from not appearing due to "Show Ghosts in background option" which has now been removed. Also changed tooltips to balloons instead of simple rectangles.
-Fixed issue with regdefend.exe being suspended and not able to process "Ask User" requests
-Now log any registry actions which are allowed by the user, rather than only showing actions which are blocked
-Any log event which is blocked automatically due to inability to ask the user, will be shown with [AUTO RESPONSE] in the log
-GUI now selects first registry group upon startup
-Now show all information about registry items in the listview
-Now show which registry group a log event belongs to
-Optimized sorting
-Lots of other small fixes and tweaks, thanks to all testers.

Last edited by Jason_R0 : May 12th, 2005 at 12:35 PM.
  #2  
Old May 12th, 2005, 12:30 PM
Jason_R0's Avatar
Jason_R0 Jason_R0 is offline
Developer
 
Join Date: Feb 2005
Location: Australia
Posts: 1,038
Default Re: RegDefend v1.300 Released!

Just another note, if you have trialed RegDefend before and the 14 day trial has expired then you can have another trial starting from this release and on. Basically with every new "major" release the trial period will be set back to 14 days.
  #3  
Old May 12th, 2005, 01:20 PM
Infinity Infinity is offline
Very Frequent Poster
 
Join Date: May 2004
Posts: 2,651
Default Re: RegDefend v1.300 Released!

Thanx Jason, It felt like it was already finished lol, sometimes I am rather quickly satisfied
enjoy the evening and thanx for sticking with it.

Andy
__________________
... hmmmm .. so you're a signature reader ...
  #4  
Old May 12th, 2005, 01:21 PM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,638
Default Re: RegDefend v1.300 Released!

I would just like to point out that if you have any custom groups, you need to back them up as the uninstall will delete them .....
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #5  
Old May 12th, 2005, 01:23 PM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,638
Default Re: RegDefend v1.300 Released!

And my install went flawlessly and so far I am loving the new version..... Thanks to Jason and the beta team for another great version.....
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #6  
Old May 12th, 2005, 01:31 PM
richrf richrf is offline
Very Frequent Poster
 
Join Date: Dec 2003
Posts: 1,907
Default Re: RegDefend v1.300 Released!

Hi Jason and puff,

Thanks for the new release Jason.

Puff, are there any changes to the special RegRun group or do I leave them the same?

Thanks for a great program and program additions!

Rich
  #7  
Old May 12th, 2005, 01:40 PM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,638
Default Re: RegDefend v1.300 Released!

Hi Rich,

Quote:
Originally Posted by richrf
Puff, are there any changes to the special RegRun group or do I leave them the same?
So far, it does not appear that the new version affects the group in any way. If, during the next few days, I come across anything that may need to be changed, I will post it to the RegRun Entries thread, but I do not beleive there will be any...
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #8  
Old May 12th, 2005, 02:20 PM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re: RegDefend v1.300 Released!

Nice Job Jason, Love the new logging and monitoring

Regarding the groups, I believe only the default groups are altered by uninstalling and re-installing, any other groups that you have should be retained.

Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #9  
Old May 12th, 2005, 02:22 PM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,638
Default Re: RegDefend v1.300 Released!

Quote:
Originally Posted by Pilli
Regarding the groups, I believe only the default groups are altered by uninstalling and re-installing, any other groups that you have should be retained.
All I know is that mine were deleted but luckily I had them backed up.....
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #10  
Old May 12th, 2005, 02:40 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: RegDefend v1.300 Released!

Hi Jason,

Thanks for the release as well . The new monitoring feature is a great addition.

I did find a problem involving RD's checking for new version and Outpost Pro's Open Process Control protection. I get the typical OP tray alert as Windows is loading and a corresponding log entry (see the pic below). This is followed by OP crashing.

From the application event log:

The application, C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe, generated an application error The error occurred on 05/12/2005 @ 12:07:13.838 The exception generated was 80000007 at address 00000000 (ntdll!KiFastSystemCallRet)

From the Dr. Watson log:

Application exception occurred:
App: C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe (pid=1408 )
When: 5/12/2005 @ 12:17:05.402
Exception number: 80000004 (single step exception)


Disabling OP's Open Process Control eliminates the problem, although I would rather be able to disable RD's checking for new version.

Nick
Attached Images
 
  #11  
Old May 12th, 2005, 02:41 PM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re: RegDefend v1.300 Released!

Ah well, Best to back up just in case then

Cheers. Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #12  
Old May 12th, 2005, 04:30 PM
tuatara's Avatar
tuatara tuatara is offline
Frequent Poster
 
Join Date: Apr 2004
Posts: 758
Thumbs up Re: RegDefend v1.300 Released!

Quote:
All I know is that mine were deleted but luckily I had them backed up.....

I've just installed regrun.ghst today, before i found the new release,
so thanks Kent.

But i didn't have to reinstall this file.

New release seems to work great.
__________________
The old creature tuatara lived here, hundreds of years
before those malware creators arrived on the Internet


  #13  
Old May 12th, 2005, 04:33 PM
jvillas jvillas is offline
Infrequent Poster
 
Join Date: Nov 2004
Posts: 23
Wink Re: RegDefend v1.300 Released!

Thank you Jason, and beta testers. My problems with RegDefend hanging on log-off have been fixed. Once again, Thankx.
  #14  
Old May 12th, 2005, 10:42 PM
Jason_R0's Avatar
Jason_R0 Jason_R0 is offline
Developer
 
Join Date: Feb 2005
Location: Australia
Posts: 1,038
Default Re: RegDefend v1.300 Released!

Quote:
Originally Posted by nick s
Hi Jason,

Thanks for the release as well . The new monitoring feature is a great addition.

I did find a problem involving RD's checking for new version and Outpost Pro's Open Process Control protection. I get the typical OP tray alert as Windows is loading and a corresponding log entry (see the pic below). This is followed by OP crashing.

From the application event log:

The application, C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe, generated an application error The error occurred on 05/12/2005 @ 12:07:13.838 The exception generated was 80000007 at address 00000000 (ntdll!KiFastSystemCallRet)

From the Dr. Watson log:

Application exception occurred:
App: C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe (pid=1408 )
When: 5/12/2005 @ 12:17:05.402
Exception number: 80000004 (single step exception)


Disabling OP's Open Process Control eliminates the problem, although I would rather be able to disable RD's checking for new version.

Nick

Hi Nick, see the other thread relating to my Outpost concerns. They definately need to do some tweaking to their protection , but in the meantime I can send out a build which doesn't have quite as much protection in it which should solve that issue.
  #15  
Old May 12th, 2005, 10:50 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,602
Default Re: RegDefend v1.300 Released!

Installed it a couple of hours ago and it seems to be running just fine.
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #16  
Old May 12th, 2005, 10:57 PM
Triple Helix's Avatar
Triple Helix Triple Helix is online now
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
I Say! Re: RegDefend v1.300 Released!

Running great here!! Thanks Cheers
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #17  
Old May 13th, 2005, 10:36 AM
Disciple's Avatar
Disciple Disciple is offline
Frequent Poster
 
Join Date: Nov 2002
Location: Ellijay, Georgia - USA
Posts: 292
Default Re: RegDefend v1.300 Released!

Quote:
Originally Posted by Pilli
Regarding thegroups, I believe only the default groups are altered by uninstalling and re-installing, any other groups that you have should be retained.


Quote:
Originally Posted by puff-m-d
All I know is that mine were deleted but luckily I had them backed up.....

Sorry to hear your additional groups were deleted. I know you don't want to hear this, In my uninstall/install the additional groups were left intact, and loaded. It may be a situtation of; your results may vary.
__________________
Disciple - Team Z
And now abide faith, hope, love, these three; but the greatest of these is love. 1 Cor. 13:13

Last edited by Disciple : May 13th, 2005 at 10:50 AM.
  #18  
Old May 13th, 2005, 10:49 AM
richrf richrf is offline
Very Frequent Poster
 
Join Date: Dec 2003
Posts: 1,907
Default Re: RegDefend v1.300 Released!

RegRun group was left intact when I installed V1.3. I had made a backup just in case.

Rich
  #19  
Old May 13th, 2005, 11:24 AM
siliconman01 siliconman01 is offline
Frequent Poster
 
Join Date: Mar 2003
Location: West Virginia (USA)
Posts: 770
Default Re: RegDefend v1.300 Released!

Smooth install...running excellent...really like new features...custom groups left alone on installation.

thanks much, as always
  #20  
Old May 13th, 2005, 12:21 PM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,638
Default Re: RegDefend v1.300 Released!

My custom groups must have been deleted by a glitch somehow, but I always keep backups so it was not a problem. I thought I remembered previously on an upgrade they had been left intact. I guess the motto is to back them up just in case... I might have been the only one that they were deleted ...
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #21  
Old May 13th, 2005, 01:48 PM
tlu's Avatar
tlu tlu is offline
Very Frequent Poster
 
Join Date: Sep 2004
Posts: 2,065
Default Re: RegDefend v1.300 Released!

Quote:
Originally Posted by jvillas
Thank you Jason, and beta testers. My problems with RegDefend hanging on log-off have been fixed. Once again, Thankx.

Yes, I'm happy to confirm this! No more hanging on log-offs. I'll try the new version for some days. Unless there are unexpected problems Jason will receive my registration.

Greetings, Thomas
  #22  
Old May 15th, 2005, 04:09 AM
Jason_R0's Avatar
Jason_R0 Jason_R0 is offline
Developer
 
Join Date: Feb 2005
Location: Australia
Posts: 1,038
Default Re: RegDefend v1.300 Released!

For all the Outpost users experiencing slowdown, please RE-download the setup again and all should be set right. Thanks to the Outpost users who tested the new build.
  #23  
Old May 15th, 2005, 06:33 AM
Antarctica's Avatar
Antarctica Antarctica is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,365
Default Re: RegDefend v1.300 Released!

Quote:
Originally Posted by Jason_R0
For all the Outpost users experiencing slowdown, please RE-download the setup again and all should be set right. Thanks to the Outpost users who tested the new build.

Hello Jason_RO,

Sorry for my dumb question, which setup to re-download are you refering to?

Thanks
__________________
One for all/All for one
  #24  
Old May 15th, 2005, 06:40 AM
Bowserman's Avatar
Bowserman Bowserman is offline
Infrequent Poster
 
Join Date: Apr 2003
Location: South Australia
Posts: 510
Default Re: RegDefend v1.300 Released!

Quote:
Originally Posted by Antarctica
Hello Jason_RO,

Sorry for my dumb question, which setup to re-download are you refering to?

Thanks

Hi Antartica .

The setup to re-download is available from here.


Regards,
Jade.
  #25  
Old May 15th, 2005, 06:50 AM
Antarctica's Avatar
Antarctica Antarctica is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,365
Default Re: RegDefend v1.300 Released!

Thanks Bowserman,
O.K. I understand now...
__________________
One for all/All for one
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Ghost Security Suite (GSS) « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:59 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums