Best HIPS For Windows Startup Protection?

Discussion in 'other anti-malware software' started by arran, Feb 16, 2009.

Thread Status:
Not open for further replies.
  1. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    @GE

    It's always a pleasure and a relief that you periodically but timely chime in to your great project MJ Registry Watcher

    I look for your opinion in this matter and appreciate your sincere recommedations.

    Compatible as it is, would you think it redundant at all to apply your app alongside and in tandem with the likes of #1 EQSecure ( HIPS ) as well as #2 MAMUTU (Behavioral Blocker) as yet another monitor in order to better double up coverage to the areas most vulnerable that your app covers, including file & especially registry monitoring?

    I have yet to find a single app that is capable in covering this vast array of so many areas of possible contention should that arise, and feel confident that MJ Registry Watcher would especially compliment either or both those apps aforementioned.

    Thanks and keep up the good work GE, it is greatly appreciated.

    EASTER
     
  2. Graphic Equaliser

    Graphic Equaliser Registered Member

    Joined:
    Nov 5, 2004
    Posts:
    421
    Location:
    London England UK
    I am already working on MJRW 1.2.6.5 and I have added a mass of keys to it, all from :-
    http://gladiator-antivirus.com/forum/index.php?showtopic=24610
    as well as other places. This is quite an exhaustive list and covers virtually any entrypoint. This would mean that MJRW should stop nearly any trojan attack in its tracks, and provide a log of changes made to your system so you can manually remove them, if MJRW failed to do so when the attack was launched.

    How MJRW sits with other types of security app, I'm not entirely sure, but it does little to upset the system. It installs nothing (no drivers or system table hooks) to the PC! It does set up hooks on changes to the registry and various directories, but does so using the standard Windows API functions to achieve this. It will fail gracefully with a relevant message if a hook fails to install and fall back to polling for changes. So, it is pretty robust.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.