Sigh....anothere exe_virus has bypassed SD v1.1.0.262

Discussion in 'sandboxing & virtualization' started by nanana1, Jun 16, 2008.

Thread Status:
Not open for further replies.
  1. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    It's a logical reaction of the bad guys to write such malware. More and more users (+ companies) are using ISR.
    ISR makes all their malware disappear during reboot, no matter how hard they worked on it. That must drive them crazy and I find that very amusing. :D
    One thing they can't beat : Zero tool + Image Backup, which is usually done offline.

    Like you I hope one day they create something that does protect certain areas of the disk, like MBR, etc. permanently in order to prevent low level changes. :)
     
    Last edited: Jun 18, 2008
  2. Perman

    Perman Registered Member

    Joined:
    Nov 23, 2005
    Posts:
    2,161
    Hi, folks:

    Just learn that these so called build 260, 261, and 262 are merely SD's internal testing alpha versions, needing some tweaking/adjustments.

    Failing to achieve some sort of protections is not unexpected.

    The last available( bona fide official) version build IS 259.

    Users(like myself) other than keen alpha/beta testers, do not need to be concerned.

    when new build is ripe, it will roll out smoothly before you even know it. :-*
     
  3. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Here is the GesWall log, stopping the malware form damage. :thumb:
     

    Attached Files:

    • log.txt
      File size:
      2.9 KB
      Views:
      13
    Last edited by a moderator: Jun 26, 2008
  4. chris2busy

    chris2busy Registered Member

    Joined:
    Jun 14, 2007
    Posts:
    477
    i think eqs has an option to monitor for low level disk changes..how well this works?any tests vs such threat families?
     
  5. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    I am curious too. All HIPS like SSM, NG, CFP and PS have such filters. I expect them to work good as they had worked against KillDisk Virus etc.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.