Sudown experiences anyone?

Discussion in 'other anti-malware software' started by Kees1958, Nov 18, 2007.

Thread Status:
Not open for further replies.
  1. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Great Thx Cerxes
     
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    No. Client calls, and the gal who works for me needs to immediately access software. Given messing with AE, and the number of times I've forgotten I have to disable it to download the first time:

    Right-click -> Run as = pain in the posterier, not a solution.
     
  3. TerryWood

    TerryWood Registered Member

    Joined:
    Jan 14, 2006
    Posts:
    1,039
    Hi All

    Read with interest your comments first time I heard about SUDown.

    I use DropMyRights on Firefox & T/Bird etc how does it differ from SUDown is SUDown better if so how?

    Do I need it I use Sandboxie and Comodo V3?

    Thanks for your help

    Terry
     
  4. CogitoErgoSum

    CogitoErgoSum Registered Member

    Joined:
    Aug 22, 2005
    Posts:
    641
    Location:
    Cerritos, California
    Hello Everybody,

    Although, a little bit off topic, Ilya has informed me that DefenseWall protects against malware that makes changes to NTFS access permissions as described by solcroft in post's #5 and #12 of this thread.


    Peace & Gratitude,

    CogitoErgoSum
     
  5. solcroft

    solcroft Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    1,639
    If you're not one of the afore-mentioned people who run multiple HIPS + dozens of scanners + miscellaneous utilities on your machines, then I might be inclined to believe you.
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    So you´re saying that none of the HIPS will alert you if malware tries to modify NTFS access permissions? Isn´t this probably some setting in the registry? Btw, a bit OT, but Neoava Guard guards against "creating of new Windows accounts", I just wonder, how can this be used by malware?

    What I meant is that what if you trust a tool and you decide to give it admin rights? Then it will still be able to do any damage, not? Of course the fact that a tool needs to have admin rights, for no good reason, is already suspicious. However, LUA will never tell you why a tool needs to have admin rights. That´s why I always rely on my HIPS.

    Nice to know, I wonder if other sandboxes also protect against this, but I´m not sure how to test this.
     
  7. solcroft

    solcroft Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    1,639
    Old topic bump.

    Just wanted to say I've had a very pleasant surprise while testing some malware earlier: ThreatFire now blocks this kind of attack.

    Kudos to the team. Now, if only they'd tackle that string of Pcclient backdoors... :D
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Solcroft, I´ve PM'ed you twice, did you receive them? ;)
     
    Last edited: Feb 27, 2008
  9. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    Pcclient backdoors? A family of RATs?
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.