Virus Attack!

Discussion in 'FirstDefense-ISR Forum' started by alloucho, May 1, 2008.

Thread Status:
Not open for further replies.
  1. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    I agree with you. A separate partition = Windows + AV, doesn't make any difference. Like a malware can infect all snapshots, there is also malware that can infect all partitions.
    You have to work with clean images and clean archives, stored on an off-line external HDD.
    Anything what is constantly on-line is vulnerable and that's why you need something clean off-line to get back in business.
     
  2. chrome_sturmen

    chrome_sturmen Registered Member

    Joined:
    Apr 29, 2006
    Posts:
    875
    Location:
    Sverige
    well actually albert, you silly goose, i keep that partition hidden- in the event that a virus infects my snapshots, i will boot to my acronis disk director cd, unhide the partition, boot to it, and hence use the virus scanner to kill the malevolent offender attacking my isrs- what say ye? :thumb: :thumb:
     
  3. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    Still not good enough, because the cleaning of all your other partitions and snapshots is based on an AV. You depend too much on scanners and when they tell you "0 threats found", you believe it.
    The AV, you use, might not even find the malware, because it isn't discovered yet and what then ? Wait for a signature ?
     
  4. chrome_sturmen

    chrome_sturmen Registered Member

    Joined:
    Apr 29, 2006
    Posts:
    875
    Location:
    Sverige
    well in all good honesty, scanning plays only a granular role in my security schema- i use avast server, which doesn't employ heuristics, so i augment it's very good signature based approach with an ids, mamutu. online armor serves the role of classical h.i.p.s, along with the complementing and sometimes overlapping h.i.p.s. of the antileak control module of AGNITUM firewall, the true best...

    i also have a portable, full updatable version of the kaspersky scanning engine, with due respects, just to double check behind avast...

    superantispyware full, no resident, but one scheduled weekly scan, just for the hell of it...

    opera 9 via proxomitron, sandboxed...

    all unnecessary services turned off, all unrequired autostarts disabled, has my machine running like a hungry lean serengeti lion...

    several bmr images via acronis image server, as well as many fdisr snaps, of varying configs- with the failsafe os installed on hidden partition, for virus killing in event my fdisr gets infected.

    howd that do albert? you've any other questions? i'll gladly indulge you.

    Thanks,
    Chrome
     
  5. 19monty64

    19monty64 Registered Member

    Joined:
    Apr 10, 2006
    Posts:
    1,302
    Location:
    Nunya, BZ
    Wouldn't clean images and clean archives, stored on an off-line external HDD have been easier to set-up...and cheaper...and less over-kill...and left nothing to chanceo_O It's like 1/2 the police force protecting your house and the other 1/2 protecting the first half. It's just an observation, not a judgement...
     
  6. Huupi

    Huupi Registered Member

    Joined:
    Sep 2, 2006
    Posts:
    2,024
    Good observation !! the simpler the better. :thumb:
     
  7. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    My favority motto : "Simplicity is always brilliant."
     
  8. alloucho

    alloucho Registered Member

    Joined:
    Dec 26, 2007
    Posts:
    145
    Is it possible to create a snapshot on another partition or external hard drive??
     
  9. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    No, that is not possible, but you can store archives anywhere.
     
  10. osip

    osip Registered Member

    Joined:
    Oct 25, 2006
    Posts:
    610
    If you have FDISR archive on another internal drive and in addition to that want to have a stored copy of a certain snapshot on an external usb drive, use "Export", if the usb happens to be in FAT 32 use "split if needed", the copying is the same as to the "archive" in speed and only minor size difference in compression...
     
  11. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    That's how i practice matters anymore myself with FD-ISR archives, they keep 100% Safe with a fully unplugged internal after archiving to that disk which saves me really from even having to turn to my image backup, so with BOTH images & archives saved, theres double the rescue preserver in event of any serious trouble with main system operations.

    I'm not sure how reliable they still are but i even have archived to DVD since i haven't accessed them in many months.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.