Anti-Executable

Discussion in 'other anti-malware software' started by LoneWolf, Apr 12, 2007.

Thread Status:
Not open for further replies.
  1. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    That folder is where some msi files reside, and one of the system files tries to open them and fails. Just annoying alerts.

    No mine doesn't revert back to low

    Pete
     
  2. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,618
    Location:
    Milan and Seoul
    Rather odd, I've reinstalled AE, and it just doesn't keep the 'high' setting over a normal reboot, I wonder whether this is happening to others or I should contact support about it.
     
  3. BlueZannetti

    BlueZannetti Registered Member

    Joined:
    Oct 19, 2003
    Posts:
    6,590
    No, this shouldn't occur. Now, have you configured your system (another application, policy) to force this type of behavior?

    Blue
     
  4. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,618
    Location:
    Milan and Seoul
    Not really. This has been happening with ShadowUser disabled, and I don't have much else that could interfere (LnS, RegDefend, AdMuncher). It's not the end of the world to to set it to 'high' for every session, but if it's not meant to happen, I wonder what else might behave erratically.

    I will definitely ask Faronics for advice.
     
  5. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    This is certainly not normal.
    It can't be LnS, because I had LnS on my computer, while AE was on HIGH.
    I don't know about the other softwares, you mentioned.
    What happens when you disable or even uninstall RegDefend for instance ?
     
  6. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    So Erik, with Anti-Executable on HIGH as your sig suggests you run, what are the basic folders/files to EXCLUDE if a user is also running FD-ISR? I never tried to go HIGH security with AE just LOW, but am curious as to not prevent something critical to normal operation getting blocked.
     
  7. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    Well, it will take some time to type them, because I can't copy/paste them.
    I can export them to a file, but I can't read that file. The purpose of that file is : when you re-install AE, you can import that file, so that you don't have to do it manually all over again.
    I also believe that not all files in that list need to be excluded, but I'm too lazy to find out, which ones need to be excluded and which ones don't need to be excluded.

    In those days I was already glad, I found a solution to turn AE on HIGH without having a bunch of errors in the copy/update function of FDISR. Since nobody else was interested in combining FDISR with AE in those days, I couldn't get any cooperation of other members to clean that list.
    A few files too many wasn't a problem, so I never cleaned the list, because I had more important problems to solve. :)

    The extension of that file is ".fzx" and its size = 1 KB.
     
  8. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,618
    Location:
    Milan and Seoul
    As far as I know to disable(and not exiting the program) RegDefend should have the same effect as uninstalling it. I'm still waiting for a reply from Faronics. If there is something worth reporting I certainly will.
     
  9. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,618
    Location:
    Milan and Seoul
    Problem solved: I uninstalled ShadowUser first, cleaning carefully all its debris (also found a lot of debris from Nod32), reinstalled AE first, and then ShadowUser. They both work well now.

    For the record, I had a prompt reply from Faronics suggesting to uninstall AE, clean the temp folder and reinstall it (good try). It's amazing how I had tested AE for the whole of the evaluation period, and didn't notice this problem then.

    I also have some second thoughts about registry cleaners (I use RegSupreme Pro). After cleaning with it, I checked the registry for left overs: It was full of them, I had to do it manually.
     
  10. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Anti-Executable is another of one of those very rare protection apps that once properly configured to it's database, Xtremely formidable. Additional coverages can't help but to strengthen it's already iron-shield guard against any attempt for malware or a virus to wreak it's dirty work and cost a user wasted time.

    It ranks right up there with my short list of INVINCIBLE protections.
     
  11. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    Another advantage of AE : it's an evergreen, no daily signature updates required, it works always with the same force and therefore ideal for boot-to-restore solutions, which are frozen most of the time. :cool:
     
  12. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Well Erik. How about re-reviewing at least some whitelist entries as a starter. You got me interested enough if i can add the right programs/folders/files where there'll be no problem then to running it to HIGH SECURITY along with FD-ISR. That HAS to be a very solid guard against potential intrusions since AE stops executables dead in their tracks at-once. LoL
     
  13. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    Easter,

    This list of trusted ISR-executables makes it possible to put AE on HIGH security +
    - Network Prevention = marked (Enable)
    - Delete Prevention = not marked (Disable). That is a pity.
    - Copy Prevention = marked (Enable)
    - Windows On Windows = not applicable (greyed out)

    To add this blue list, you have to do this :

    1. Open Anti-Executable
    2. Click on "Configuration"-tab
    3. Click on "Trusted Applications"-tab
    4. Add each exe-file in the text area one-by-one and click each time on "Add Application"-button

    c:\$isr\$app\setup\isrcopy2k.exe
    c:\$isr\$app\setup\isrcopy.exe
    c:\$isr\$app\setup\isrcopyrss.exe
    c:\$isr\$app\setup\isrcopyxp.exe
    c:\$isr\$app\setup\isrmonitor.exe
    c:\$isr\$app\setup\isrservice.exe
    c:\$isr\$app\setup\isrsetup.exe
    c:\$isr\$app\setup\mbrtool.exe
    c:\$isr\$app\setup\removeall.exe
    c:\$isr\$app\setup\setuprss.exe
    c:\$isr\$app\firstdefense-isr.exe
    c:\$isr\$app\isrcmd.exe
    c:\$isr\$app\isrcontrol.exe
    c:\$isr\$app\isrmonitor.exe
    c:\$isr\$app\isrviewlogs.exe
    c:\$isr\$app\isrwait.exe
    c:\$isr\$app\mbrbackup.exe
    c:\$isr\$app\supportinfo.exe
    c:\$isr\0\isrservice.exe
    c:\$isr\0\isrcopyrss.exe
    c:\$isr\0\isrcopyxp.exe


    5. When finished, click on "Apply"-button
    6. Click on "OK"-button

    You better use the function "Export To File" to store all these trusted applications, in case you have to re-install AE.
    The function "Import From File" lets you import them back.
    It works because I've tested this during my total re-installation from scratch in September. :)

    Happy typing. :D

    P.S.: the list might have too many executables, as I said earlier in this thread.
     
    Last edited: Nov 17, 2007
  14. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    Easter,
    In addition do also this :

    1. Open Anti-Executable
    2. Click on "Configuration"-tab
    3. Click on "Message"-tab and mark all these options

    - File name
    - Reason for blocking
    - Progam name
    - Bitmap

    4. When finished, click on "Apply"-button
    5. Click on "OK"-button

    The reason why you have to do this : when AE warns again during a FDISR-operation, AE will show a popup menu with an explanation and which executable is responsible.
    Write that executable down and put it in the list of "Trusted Applications".
    This might happen, when the list is still not complete.

    The last executable on the blue list "c:\$isr\0\isrcopyxp.exe" for instance was added much later. AE suddenly complained while I was doing something and I had to add this exe to make it work without errors.
     
    Last edited: Nov 17, 2007
  15. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Thats bizarre. I use AE with no ISR files added and it doesn't complain. Hmm
     
  16. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Pete, is that with HIGH SECURITY or LOW?

    And if HIGH, indeed this is something of interest to nail down. Thanks

    I already configure for this of course, i have to SEE just whats being blocked and it's locale. LoL
     
    Last edited: Nov 17, 2007
  17. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    Read post #373 and #374.
     
  18. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Exactly Erik. I did tick all the boxes so it shows what's being blocked. Thats how I knew about the installer folder and the msi files.

    I have no issues with FDISR on the high setting.
     
  19. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    Can you mark the "Delete Prevention" as well now ?
     
  20. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,618
    Location:
    Milan and Seoul
    Network Prevention won't let anything execute on the 'network drive'.

    "Network Prevention: When Network Prevention is checked, all executable files on a network drive are blocked from execution. The Exempted Folders tab allows access to executable files in specified network folders, even if Network Prevention is checked. If the option is unchecked, all executable files on a network can be executed normally." So that's the reason for all these alerts if one doesn't put C:\Windows\installer in the exempted folders. So this means that these are executables that are activated by the OS and not by the operator. (I find the wording a bit difficult to understand)

    With Copy Prevention, you can't download anything from the internet if it is checked, pretty tight.

    Am I right?

    The attachment shows what I had to put into the exempted folder tab.
     

    Attached Files:

  21. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    Haven't tried, as I suspect all the log files windows deletes and reopens on reboot will get snagged. Not sure I really need it.

    Pete
     
  22. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi Osaban

    Yes you are right as far as I know on most of your point. If you will notice most of the files you exempted are in the windows installer folder. Thats why I just exempted the folder to be done with it.

    Pete
     
  23. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    The only thing I can confirm is that my "Copy Prevention" is marked (enabled) and that I can't download any executable file from the internet.
    So if I want to download a software to install it, I have to turn off AE to download it and keep AE turned off to install it. Once I turn AE on, the new software is added to the whitelist.

    Turning off AE makes me vulnerable of course, but I don't care about that, because my frozen snapshot removes any change anyway.
    Frankly, I don't care about my system partition at all, even when my frozen snapshot would ever fail. I have an army of clean images to get my system back. System partition is peanuts.
    I was alot more worried about my unprotected data partition, but not anymore, because I lock it when I surf safely or dangerously. :)
     
  24. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    AE is bullet-proof against executables, spoofed executables (fake extension) and file with double extensions. I'm not sure how it would perform against data filetypes carrying shellcode (exploits).
     
  25. Rmus

    Rmus Exploit Analyst

    Joined:
    Mar 16, 2005
    Posts:
    4,020
    Location:
    California
    Hi lucas1985,

    It would depend on what the shell code did. In the MSWord exploits I've seen, the code attempts to install a trojan executable, which of course would be blocked by AE.

    In an article last year by Security Focus, the steps in this type of exploit were detailed, and included a nice graphic :

    http://www.securityfocus.com/images/infocus/msoff5.jpg

    Of course, Shellcode is capable of doing other things. However, to date, I've not seen in-the-wild examples of any.

    The money to be made is easier to come by with the installation of a trojan permitting control of the computer by the attacker.


    ----
    rich
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.