Alcyon's EQS RuleSets

Discussion in 'other anti-malware software' started by EASTER, May 14, 2008.

Thread Status:
Not open for further replies.
  1. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Well deserved.

    I'm already sort of doing that lately myself. Have to give my machine and me some time to come up for air once in a while. LoL

    You definitely increased the value of this HIPS several-fold when you contributed those rules for users of it.

    Brilliant Job!
     
  2. Alcyon

    Alcyon Registered Member

    Joined:
    Jan 16, 2008
    Posts:
    438
    Location:
    Montr?al, Canada
    Yeah some fresh air oversea in my case ;) I don,t know exactly where yet.
     
  3. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    @Alcyon

    Under the BlackList Rules in the Application Protection settings, while experimenting, can you explain if this section is of the lowest priority or reason why whenever i endeavor to checkmark to activate any of these blacklists, you can still execute them anyway, but with a RED warning message every time. Some screenshots for you to better detail what is showing. Is this normal activity and why the indications? Only on Application Protection BlackLists does this exhibit in this manner.

    Thanks EASTER
     

    Attached Files:

    • a.jpg
      a.jpg
      File size:
      28.5 KB
      Views:
      263
    • b.jpg
      b.jpg
      File size:
      29.2 KB
      Views:
      263
  4. Alcyon

    Alcyon Registered Member

    Joined:
    Jan 16, 2008
    Posts:
    438
    Location:
    Montr?al, Canada
    EASTER,

    I'm still unable to reproduce the problem, even if i set the specific rules you've shown to "prompt and block" and activate their MD5 checkup. Once enabled, the nomal behavior of "block cmd.exe" and "block regedit.exe" is no prompts at all and even if you modify those rules, you should not always have these red MD5 modification messages. There's something wrong on your side but I can't tell exactly what yet.

    Btw, there's a translation error in eqs and the blacklist section should instead be called "high-priority rules" as you can put whitelist & blacklist rules.
     
    Last edited: Aug 22, 2008
  5. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Good enough Alcyon, and thanks for your reply. I'll investigate THIS as time permits although this particular occurance in no way inhibits the OVERALL protections of EQS in any way, still is Rock Solid!!

    I suspect theres a mismatch of not your rules but of versions i;m using since i'm using several releases on different machines.

    Keep up the amazing effort and spring anything new again on us EQS loyals as you find them useful.

    EASTER
     
  6. Alcyon

    Alcyon Registered Member

    Joined:
    Jan 16, 2008
    Posts:
    438
    Location:
    Montr?al, Canada
    There's nothing much left to do with v3.41... Perhaps an English pdf guide!

    I've started a new project with Magic Shield (v4 Beta3) but I don't know when it'll be ready.
     
  7. Alcyon

    Alcyon Registered Member

    Joined:
    Jan 16, 2008
    Posts:
    438
    Location:
    Montr?al, Canada
    Good news, my English translation of EQSecure v4 Beta3 is almost done (with no Chinese characters left :) ).

    Just to make everybody salivate a little:
     

    Attached Files:

    Last edited: Aug 24, 2008
  8. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    P.E.R.F.E.C.T.

    This HIPS wouldn't be the same without your ambitious efforts time and again. Looking forward to it.

    Thanks Alcyon

    EASTER
     
  9. TVH

    TVH Registered Member

    Joined:
    Aug 9, 2007
    Posts:
    227
    A VERY BIG THANK YOU to Alcyon. Thanks to your efforts, EQSecure and Returnil are the only security apps installed on my nLited XP machine. It runs lightning quick and very secure.
     
    Last edited: Aug 24, 2008
  10. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Same here, plus it'll be nice to finally have a full englich version minus the squares in the sandbox configs. Never been able to shake off those boxes or have the time to dissect the .xml's enough to rid this fabulous HIPS of these distortions.

    I have however managed to dress up a lot of the alert information and double check and correct some things when they were not in sync where they needed to be.

    It's still been worth all the effort to go over this HIPS and custom configure it to taste. Alcyon's rules need no adjustments IMO, just a matter of which ones to apply and fit rules to suit areas of additional LOCKDOWNS.

    Gotta luv that blacklist, a better SRP then windows own one which i found bugs in. Not EQS however. Works like a charm.

    @Alcyon, be sure to throw us a nice surprise along the way again. You seem to have that uncanny knack. LoL

    EASTER
     
  11. Alcyon

    Alcyon Registered Member

    Joined:
    Jan 16, 2008
    Posts:
    438
    Location:
    Montr?al, Canada
    Something strange happened while translating so please be patient. It'll take more time than I thought. Btw, as English isn't my native language, I'll need help for the final touch. Please give me one more week.
     
  12. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Take the time you think is needed Alcyon.

    Shoot, a week is but a moment in time around here anyway.

    Best of luck, :thumb:

    EASTER
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.