Expires In 5 Days

Discussion in 'other security issues & news' started by Rico, Jan 26, 2008.

Thread Status:
Not open for further replies.
  1. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    2,287
    Location:
    Canada
    Hi Guys,

    A little help please, regarding renewal of NOD32 AV.

    I use the following:

    1. NetGear wired router
    2. Anything that connects to the net does so through 'DropMyRights'
    3. NOD32 3.0 (no problems)
    4. Shadow Defender
    5. SpyBlaster
    6. MVPS Host
    7. Firefox
    8. McAfee SiteAdvisor
    9. Monthly Full weekly increments via Shadow Protect

    I've done some hardening using 'SeconfigXP'
    On Demand - Superantispyware


    With the above SAS & NOD never find anything, during there scans. I would like to ditch the AV, but NOD scans email, perhaps my weakest link. But I don't open attachement & Thunderbird is great at handling junk.

    I know about AVG AV free, & NOD's renewal fee does not bother me.

    Help

    Take Care
    Rico
     
  2. innerpeace

    innerpeace Registered Member

    Joined:
    Jan 15, 2007
    Posts:
    2,121
    Location:
    Mountaineer Country
    http://www.avast.com/eng/avast_4_home.html
    Hi Rico,

    I'm not familiar with Thunderbird, but Avast's resident shield takes care of the above. The home (free) version is very comparable with the paid (pro) version. http://www.avast.com/eng/av4_version_comp.html I've used Avast in the past and wouldn't hesitate using again. You can also pick and choose which shields are on and off.

    Also, some things aren't clear in your post. Do you run virtualized all the time? Do you read your emails as text only? Do you have a data partition that isn't virtualized? Running virtualized means your protected partitions should stay clean all the time, but doesn't protect you if something happens to get on you machine and steals or destroys your data during that virtualized session. There are many ways to mitigate this such as sandboxes, HIPS, AV's, LUA's etc. Let's us know a few more details and I'm sure the suggestions will flow like water.

    Take care,
    innerpeace
     
  3. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    2,287
    Location:
    Canada
    Hello Innerpeace,
    99.6%

    Not sure as I did not pay attention to this with T-Bird starting, limited + NOD32. But I will pay attention to this now that you've mentioned.

    Yes

    Thanks & Take Care
    Rico
     
  4. innerpeace

    innerpeace Registered Member

    Joined:
    Jan 15, 2007
    Posts:
    2,121
    Location:
    Mountaineer Country
    Greetings Rico,

    There's been a lot of talk lately about malware than can gain admin access when using DropMyRights. I have no idea how common it is. I also use DMR and a sandbox app for my internet facing applications.

    Your system partition is protected so your data partition needs some sort of protection. There are a few of us that use a sandbox program that can blocks access to other drives, partitions, folders or files. For example, I'm running Firefox through Sandboxie which is set to block access to my D: partition. There was an interesting thread posted by Peter2150 in the FD-ISR forum. It's called "The ErikAlbert approach - A test". It's a good read for anyone who has a boot to restore program and a data partition.

    https://www.wilderssecurity.com/showthread.php?t=192840

    As far as running an AV or not, IMO, it's important to run some kind of protection software. At the minimum, it should let you know if something bad is attempting to get on your machine. At that point you can reboot :). You could opt to try another AV for awhile or try a HIPS type program. Most of them run very light. Or, if you like your current set-up, then stay with it. After all, it's has kept you safe.
     
  5. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    2,287
    Location:
    Canada
    Hi Innerpeace,

    Your probably referring to the 'Su-Run' thread regarding DMR. I think DMR can be defeated only if you use the wrong shortcut to start, something with internet access. I find that situation highly unlikely as the full right shortcuts (this machine) are hard to get to.

    I took a look at Avast & AVG, NOD seems superior at AV comparatives, so if i keep an AV it most likely will be NOD.

    Protecting <D:\> I thought about just ticking <D:> in SD but the reboot thing. I've heard about 'locking' a partition, sounds intriguing. HiPs used PG, then tried SSM, both of those kind of take the fun out of computing.

    Take Care
    Rico

    PS. Well so much for 'lockdown' nevermind that.
     
    Last edited: Jan 28, 2008
  6. innerpeace

    innerpeace Registered Member

    Joined:
    Jan 15, 2007
    Posts:
    2,121
    Location:
    Mountaineer Country
    Hi Rico,

    Here was what I was talking about as far as DMR. If your running Vista, then this doesn't matter. Again, I have no idea if it's even worth worrying about.
    https://www.wilderssecurity.com/showpost.php?p=1156084&postcount=14

    I think your main concern is protecting your data from possible theft. Your AV should do that providing it has the proper signatures. Also, keeping your programs up to date is important and you can use the link in my signature to do an online check. I do an online check at least once a month.

    Sorry I couldn't help anymore. I'm all out of ideas for now. Let me know what you've decided or if you have other questions.

    Take care,
    innerpeace
     
  7. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    2,287
    Location:
    Canada
    Hello Innerpeace,

    You helped tremendously, I renewed NOD32. The vulnerability with DMR seems remote (I'll do some checking), also for the price & ease of use, it seems almost silly not to use on XP. Yes that was my concern protecting the data partition. I've read about some who go AV-less, had dreams of giving that a whirl. I have Secunia on my FF toolbar, I'm always up-t-date, I'm a little anal about it.
    Thanks:thumb:

    Take Care
    Rico
     
  8. innerpeace

    innerpeace Registered Member

    Joined:
    Jan 15, 2007
    Posts:
    2,121
    Location:
    Mountaineer Country
    Hi Rico,

    Your welcome and it's good to hear you've made your decision. You should be fine :).

    Take care,
    innerpeace
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.