And I still got nailed.

Discussion in 'other anti-malware software' started by Hugger, Feb 21, 2009.

Thread Status:
Not open for further replies.
  1. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    ah good that all it's ok:thumb:
     
  2. Hugger

    Hugger Registered Member

    Joined:
    Oct 27, 2007
    Posts:
    1,003
    Location:
    Hackensack, USA
    Blue screen doesn't equal panic. It's just an annoying pain in the butt.
     
  3. arran

    arran Registered Member

    Joined:
    Feb 5, 2008
    Posts:
    1,156
    OK so Shadow Protect blocked it like it should have and Returnil would have as well if you had that running.

    Avira and PC Tools Firewall I am not surprised that it bypassed these.

    But what I do find a bit surprising is that it some how bypassed Both defense wall and Mamutu on Paranoid mode. you must have done something wrong for this to have happened.
     
  4. aussiebear

    aussiebear Registered Member

    Joined:
    Jul 3, 2006
    Posts:
    8
    Is it normal to have that many anti-malware apps running at the same time?

    Wouldn't you suffer from compatibility or security issues caused by this scenario?

    It just seems crazy to load all this, when you can take the time to use the various access control mechanisms to prevent malware from running in the first place. (Its all built-in to Windows, and doesn't cost you money or system performance; compared to loading your system up with anti-malware apps.)
     
  5. Saraceno

    Saraceno Registered Member

    Joined:
    Mar 24, 2008
    Posts:
    2,405
    It bypassed Avira because it was most likely a system/driver/conflict, not a virus.

    But if it were a virus, Avira's the best there is at the moment, so if it gets past Avira, then you could say it'd get past most other security products.
     
  6. Saraceno

    Saraceno Registered Member

    Joined:
    Mar 24, 2008
    Posts:
    2,405
    Fellow aussie, we all have different internet-related behaviours, but I agree, sticking to the bare essentials, or a non-admin account, might not mean you're 100 per cent bulletproof, but at least your system has some zip/speed to it.
     
  7. zapjb

    zapjb Registered Member

    Joined:
    Nov 15, 2005
    Posts:
    5,556
    Location:
    USA still the best. But barely.
    Is this true? No rootkits on XP64 or Vista64?
     
  8. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    Vista64 doesn't allow unsigned kernel drivers. You can hide malware in 64 with virtualization but that's another story.
     
  9. PROROOTECT

    PROROOTECT Registered Member

    Joined:
    May 5, 2008
    Posts:
    1,102
    Location:
    HERE ...Fort Lee, NJ
  10. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    Then disable virt.

    Since nt 6.x no more usual ring0 rootkits. Only ring3 and specific malware, likely ring -1 too (but you should be able to disable this vector) and ring1 if you access to internet with a infested vm os, naturally all commercial spy/malware but in that case someone has or you have to access your system to manually install it. We don´t talk about exploits, thats another story. Keep in mind that you should disable Ipv6 and stay with Ipv4 for security reasons to prevent sniffer evasion.
     
    Last edited: Feb 22, 2009
  11. wat0114

    wat0114 Guest

    No it should not have. ShadowProtect is a backup/restore program.
     
  12. SIR****TMG

    SIR****TMG Registered Member

    Joined:
    May 31, 2004
    Posts:
    833
    Defensewall 2.49 is out with major update fixed
     
  13. Hugger

    Hugger Registered Member

    Joined:
    Oct 27, 2007
    Posts:
    1,003
    Location:
    Hackensack, USA
    Because of what someone else said earlier, I did some more checking into what fssfltr_tdi.sys is.
    My statement about it being a rootkit came from info given me on a different forum that deals more with os problems.
    However, I think that what really happened is what I referred to earlier.
    A problem with an update to Windows Live Messenger. The update was not successful.

    Do I have too much protection running. Perhaps. But I have far less than many others. Some of my programs are on demand and not always running.
    Thanks all for trying to help.
    Hugger
     
  14. wat0114

    wat0114 Guest

    Some of those running as on-demand is certainly a qualifier for having that number of programs. Also if they are not conflicting with one another, nor slowing down your machine or causing the bsod either directly or indirectly, then by all means it should be no problem. Sorry if I seemed blunt; I just saw the potential in that security setup to possibly cause system instability.
     
  15. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    Nothing was bypassed,it was a signed MS file.
     
    Last edited: Feb 22, 2009
  16. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    Effectively so outside of some of the more imaginative black-hat conference musings;)
     
  17. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    Everything can be undermined.
     
  18. n8chavez

    n8chavez Registered Member

    Joined:
    Jul 19, 2003
    Posts:
    3,347
    Location:
    Location Unknown

    That's What She Said....

    :)
     
  19. Sully

    Sully Registered Member

    Joined:
    Dec 23, 2005
    Posts:
    3,719
    Personally I think the easiest route would be to either run with some sort of LUA scheme, or go with Sandboxie for your surfing habits. All the security programs running will then compliment the main security, rather than trying to be the main security. Restricting or virtualizing are IMO the better security tool, leaving these 3rd party apps for 'just in case' events.

    Sul.
     
  20. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    agree
     
  21. Tony

    Tony Registered Member

    Joined:
    Feb 9, 2003
    Posts:
    725
    Location:
    Cumbria, England
    Love the Avatar jmonge :) :thumb:
     
  22. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    Oh, he is just copying Aigle.:isay:
     
  23. muf

    muf Registered Member

    Joined:
    Dec 30, 2003
    Posts:
    926
    Location:
    Manchester, England
    It took me just over an hour to think of and create that avatar in PhotoFiltre. I'm flattered that someone else has decided it's good enough to use but I do feel that the credit is being directed, shall we say, towards the wrong person!!!

    muf
     
  24. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    hey nice avatar buddy:D i copy from your avatar;) :D :) :thumb:
     
  25. Tony

    Tony Registered Member

    Joined:
    Feb 9, 2003
    Posts:
    725
    Location:
    Cumbria, England
    Love the avatar muf :) :thumb: :D ;)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.