Pumpernickel (FIDES)

Discussion in 'other anti-malware software' started by TheRollbackFrog, Dec 9, 2016.

  1. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    it is just a demo. and does not explain what that means.
     
  2. TheRollbackFrog

    TheRollbackFrog Imaging Specialist

    Joined:
    Mar 1, 2011
    Posts:
    4,954
    Location:
    The Pond - USA
    Pete, are you protecting the LOG or is it open?
     
  3. guest

    guest Guest

    • The trial version can be tested for private non-commercial use without any limitation.
    • In the logfile you'll see before each line: *** excubits.com beta ***
    • After 1 year you have to download a new version from the website.
    • The size of the .ini-file is limited to 3KB.
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I can open it and it is empty
     
  5. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hmm. I just noticed the same thing on the other desktop. So there had to be something in common that happened today. And the only thing that fits is Gotomypc updated itself. Don't know why that should effect it, but tomorrow, I am going to try uninstalling and reinstalling and see what happens.
     
  6. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Is [INSTALLMODE] enabled? That would show a yellow-ish icon.
     
  7. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I checked by turning it on, and then off. When I turned it off the icon went green and then back to beige. The driver is working and is protecting the drive, just with the wrong icon
     
  8. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Figured it out, with itman's words ringing in my ears. I had added sc.exe to my Appguard users list with a yes, so appguard was obediently blocky it. I did an uninstall off fides and when I saw the command a light bulb went off. Made the change on both machines. DUH. Changed SC from the user list to a guarded app and all is again well in FIDES land. Laughing is permissible. But hey it proves Appguard works.
     
  9. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    @Peter2150 Glad to see that you've troubleshooted and resolved the issue. :thumb:
    AppGuard and FIDES should play nicely together now.

    EDIT: This makes sense to me now as well, since the protection of the driver itself was working and protecting your drives, yet the tray icon was not reflecting the correct status since it was being blocked from retrieving status. I should have realized that sooner as well, but very glad it is resolved either way.
     
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Thanks WBD. Sometime we shoot ourselves in the foot. Trick can be figuring out the gun.
     
  11. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    You're welcome, my pleasure. Shooting ourselves in the foot is often one of the ways in which we learn and I've certainly done so many times over the years.

    I'm glad to see that you've embraced some non-GUI security protection with open arms and seems that you are fully able to realize the strength of these kernel-mode drivers (when implemented correctly with less attack surface, etc.). Often times in this day and age, users seem to need visual representation of security via a fancy UI to ensure that they "feel" protected, but as we have seen over the years some security companies can rely too heavily on these fancy and new UI changes year after to year to give the impression of security. When really what is most important is under-the-hood, so to speak.

    Is MemProtect the one which specifically did not work well with your system? If I remember correctly. That would be unfortunate because it compliments FIDES so well. Particularly in this modern age of security where attackers are utilizing built-in digitally signed Windows binaries to bypass many security mitigations. Although as I understand it, you do use AppGuard so there would be no need for using both AppGuard and MemProtect since there are many similarities there.
     
  12. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I think the conflict is with NVT's ERP. And that has been such a stalwart for me, combined with Appguard they are tight. But man I love FIDES
     
  13. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    WEll I was going to try this out today. first thing cylance quarantined tray.exe and admin tool.exe. I waved those two. then I was reading the readme file and it shows this.
    "The driver is for demo and educational and test purposes only. Use at your own risk. Demo version's .ini file is limited to 3KB. Demo driver will stop working on system time's year value > 2016."
     
  14. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    You don't need to worry about that. Besides the full package is only $12 It's biggest use will be if you additional internal drives.
     
  15. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    Ah ok, I only have one drive so most likely don't need it.
     
  16. kakaka

    kakaka Registered Member

    Joined:
    Oct 5, 2009
    Posts:
    84
    I think all we need just a rule editor to make making rules easier. Missing Malware Defender's UI @ https://www.wilderssecurity.com/threads/malware-defender-setup-tips.226940/
     
  17. Kid Shamrock

    Kid Shamrock Registered Member

    Joined:
    Apr 3, 2007
    Posts:
    229
    I'm using FIDES to lock down my external backup drive. This works fine, but now whenever I reboot, I get a message that the recycle bin on drive E: is corrupt. I've tried giving read/write access to $Recycle.Bin, but still get the message. Does anyone know what else needs to be allowed to make the recycle bin function properly?
    Here's my config file if needed:
    [#INSTALLMODE]
    [LETHAL]
    [LOGGING]
    [WHITELISTMODIFY]
    !C:\Program Files\Macrium\Reflect\reflectbin.exe>E:*
    !*$Recycle.Bin
    [BLACKLISTMODIFY]
    $!*explorer.exe>E:*
    $!*SearchIndexer.exe>E:*
    $!*svchost.exe>E:*
    $!*dllhost.exe>E:*
    $!*WmiPrvSE.exe>E:*
    $!*chrome.exe>E:*
    *>E:*
    [WHITELISTREAD]
    !C:\Program Files\Macrium\Reflect\reflectbin.exe>E:*
    !C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe>E:*
    !C:\Program Files (x86)\Blue Ridge Networks\AppGuard\*>E:*
    !C:\Program Files (x86)\Zemana AntiLogger\ZAM.exe>E:*
    !*$Recycle.Bin
    [BLACKLISTREAD]
    $!*explorer.exe>E:*
    $!*SearchIndexer.exe>E:*
    $!*svchost.exe>E:*
    $!*smss.exe>E:*
    $!*WmiPrvSE.exe>E:*
    $!*sdiagnhost.exe>E:*
    $!*id_service.exe>E:*
    $!*dllhost.exe>E:*
    $!*chrome.exe>E:*
    *>E:*
    [EOF]
     
    Last edited: Mar 14, 2017
  18. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
  19. guest

    guest Guest

    I can see:
    !*$Recycle.Bin
    But > is missing.

    You can try this:
    !*>E:\$Recycle.Bin*
     
  20. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    @Kid Shamrock As mood pointed out, ensure that you add !*>E:\$Recycle.Bin* to both your [WHITELISTMODIFY] and [WHITELISTREAD] sections. Also, I don't think that the priority ! rules are necessary within your silenced [BLACKLISTMODIFY] and [BLACKLISTREAD] rules. Although if I am wrong on that, someone correct me please. You could always trial certain scenarios in non-lethal [#LETHAL] and see if anything shows up in the logs.

    So I would try something like the following:
    Code:
    [#INSTALLMODE]
    [LETHAL]
    [LOGGING]
    [WHITELISTMODIFY]
    !C:\Program Files\Macrium\Reflect\reflectbin.exe>E:*
    !*>E:\$Recycle.Bin*
    [BLACKLISTMODIFY]
    $*explorer.exe>E:*
    $*SearchIndexer.exe>E:*
    $*svchost.exe>E:*
    $*dllhost.exe>E:*
    $*WmiPrvSE.exe>E:*
    $*chrome.exe>E:*
    *>E:*
    [WHITELISTREAD]
    !C:\Program Files\Macrium\Reflect\reflectbin.exe>E:*
    !C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe>E:*
    !C:\Program Files (x86)\Blue Ridge Networks\AppGuard\*>E:*
    !C:\Program Files (x86)\Zemana AntiLogger\ZAM.exe>E:*
    !*>E:\$Recycle.Bin*
    [BLACKLISTREAD]
    $*explorer.exe>E:*
    $*SearchIndexer.exe>E:*
    $*svchost.exe>E:*
    $*smss.exe>E:*
    $*WmiPrvSE.exe>E:*
    $*sdiagnhost.exe>E:*
    $*id_service.exe>E:*
    $*dllhost.exe>E:*
    $*chrome.exe>E:*
    *>E:*
    [EOF]
    
     
  21. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    I am
     
  22. kakaka

    kakaka Registered Member

    Joined:
    Oct 5, 2009
    Posts:
    84
    Could be possible. Someone will write a GUI FrontEnd for editing rules, not necessarily by Pumpernickel's author.

    New ERP is going to have a rule editor.

    [​IMG]
     
    Last edited: Mar 14, 2017
  23. Kid Shamrock

    Kid Shamrock Registered Member

    Joined:
    Apr 3, 2007
    Posts:
    229
    I finally got it working. I had to specifically allow explorer.exe access to the recycle bin since it is also on the blacklist. Following line did the trick: !*explorer.exe>E:\$Recycle.Bin*

    Thanks @mood and @WildByDesign for pointing me in the right direction.
     
    Last edited: Mar 14, 2017
  24. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I see there is new demo version on the website dated 1st April.

    But I have the paid version, and my original order email reply has a link for downloading 'further versions and updates'.

    Is the full (paid) version also updated?
     
  25. Kid Shamrock

    Kid Shamrock Registered Member

    Joined:
    Apr 3, 2007
    Posts:
    229
    Yes, use the link and password from your email. You'll get the update, it worked for me anyway...
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.