ThreatFire custom rules why use?

Discussion in 'other anti-malware software' started by Kees1958, Nov 17, 2007.

Thread Status:
Not open for further replies.
  1. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    Totally understand and like the product straight out of the box.;)
     
  2. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Kees can u post some screen shots of TF popups on trigger of custom rules?
    I tried flle protection rules in past and popups were just too vague and useless, then I never bothered.
     
  3. solcroft

    solcroft Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    1,639
    You pretty much got it spot-on. TF is currently virtually helpless against malicious VBS/BAT scripts, only partially effective against file infectors/overwriters, and some rogue apps which may or may not fall into the definition of malware. I don't count time bombs as a weakness because TF will quarantine them when they trigger anyway, and lastly, TF is amazingly effective against worms, thanks to an anti-self-copy rule.
     
  4. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Aigle,

    It only displays the description/explain you entered yourself when making the rule, see post https://www.wilderssecurity.com/showpost.php?p=1059748&postcount=13

    They are not informative, but in the example below, the custom rule warns when a test program tries to import the advapi32.dll. Advapi32 is the DLL containing the LsaRemoveAccountRights API

    So have to make it informative yourself (basically the warning says
    RISK = HIGH
    A program which handles the accessfunctions of your PC is started. Choose Quarantine

    Syntax
    When any process
    tries to write or delete or create or execute|TriggerAccessFlags a file
    named advapi32.dll|TriggerFiles
    in C:\WINDOWS\system32|TriggerFolders

    Regards Kees
     

    Attached Files:

    • vb.JPG
      vb.JPG
      File size:
      42.1 KB
      Views:
      237
    Last edited: Nov 20, 2007
  5. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    Thanks guys :)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.