Change font size
It is currently Sat May 25, 2013 12:42 am


Post a new topicPost a reply Page 2 of 3   [ 22 posts ]
Go to page Previous  1, 2, 3  Next
Author Message
 Post subject: Re: Definitive Malware Prevention
PostPosted: Tue May 03, 2011 4:55 pm 
User avatar

Joined: Sat Apr 11, 2009 9:04 am
Posts: 1111
I put the fear of God into my 70 year old mom about internet infections.
Now she's a religious SandboxIE user. :D

_________________
"That whenever any Form of Government becomes destructive of these ends, it is the Right of the People to alter or to abolish it, and to institute new Government..."


Top
 Profile  
 
 Post subject: Re: Definitive Malware Prevention
PostPosted: Tue May 03, 2011 5:05 pm 
User avatar

Joined: Mon Jan 18, 2010 6:30 pm
Posts: 124
Location: Kokomo, Indiana, USA
WARNING regarding Comodo Time Machine:

Don't ever boot using a liveCD/USB and write to the HD, or you will find your machine hosed. The only remedy is to return to the baseline snapshot. Any changes since the baseline are irrecoverably lost.
I lost 2 weeks of work (not data) and was reverted to an almost fresh install of Windows on my main laptop.

I plan on never using that product again.

_________________
Roger A. Hart
Mobile Tech Express, LLC
Kokomo, IN
765.419.7175
http://www.mobiletechexpress.com


Top
 Profile  
 
 Post subject: Re: Definitive Malware Prevention
PostPosted: Tue May 03, 2011 8:27 pm 
User avatar

Joined: Tue Oct 26, 2010 12:26 am
Posts: 470
Location: Winnipeg, MB, Canada
joemessman wrote:
Superantispyware did not prevent the ransomware install of the three ransomware variants I tested. The only security software I have tested that detects and foils installation of these rogue antivirus programs is Malwarebytes. However if you scan with Superantispyware after the infection it does remove it.
Thanks for the update. I've been considering this product.

Two things I'd be interested in you adding to your tests if you're willing.

1. OpenDNS - http://www.opendns.org
My understanding is that OpenDNS may not always block the installation of malware, but does its best to block known sites that common malware access once installed, essentially crippling the malware. From their malware information page ... 'This means even if the virus has penetrated machines on your network it is rendered useless because it cannot connect back to the botnet.' Would be interesting to see what the result is.

2. MVP hosts - http://winhelp2002.mvps.org/hosts.htm
I've used this with surprising success with some repeat customers. Had a client bring his malware infected machine back three times in two months with different infections. He uses porn sites that were aggregating content from other sites across the web. After installing this custom host file it stopped. The surprising part is that this hosts file has to be manually maintained so I was expecting limited success. I'm still in regular contact with him but he hasn't seen a re-occurance. The MVP host file I installed is probably 15 months old at this point. Just a little extra to help block the known stuff.

_________________
Image
Simpson Home Computer Support
Winnipeg, Manitoba, Canada | http://www.SimpsonHomeComputerSupport.com


Top
 Profile  
 
 Post subject: Re: Definitive Malware Prevention
PostPosted: Wed May 04, 2011 11:05 am 
User avatar

Joined: Thu Jun 12, 2008 4:16 pm
Posts: 1325
http://www.funkytoad.com/index.php?opti ... tent&id=13
This particular item, referenced by A1C-James, did not prevent me from going to my 3 rogue av sites that I use for testing.
In regard to Time Machine thanks for the information. I will also test with various boot discs. Who would have thunk it.


Top
 Profile  
 
 Post subject: Re: Definitive Malware Prevention
PostPosted: Tue May 10, 2011 9:04 am 
User avatar

Joined: Mon Sep 06, 2010 1:56 pm
Posts: 334
Location: Oshawa, Ontario, Canada
Hey SHCS,
Yea the MVP hosts are excellect in combination with a solid AV. As it was just mentioned it did not prevent the ransomeware it does however provide a frontline passive defence against %80 of all ads, popups, and various online scan malware. I love MVP but since it cuts the bad stuff out of the picture before it gets to the browser and refuses connection.

_________________
A1Computers
905-432-6862
Oshawa, Ontario, Canada
Sales@A1Computers.ca
http://www.a1computers.ca


Top
 Profile  
 
 Post subject: Re: Definitive Malware Prevention
PostPosted: Sun May 15, 2011 1:54 am 
User avatar

Joined: Sat Oct 24, 2009 2:28 pm
Posts: 234
I'm not familiar with the paid version of Malwarebytes. I know that it will automatically update and you can schedule scans, but I didn't realize that it worked proactively. Could you elaborate as to how it prevented you from going to these three sites. Does it just stop the browser and throw up a warning or what?
Also what browser did you use?
Thanks for providing the results of your research, BTW. Very interesting, T.

_________________

Thanks to everyone for helping me build my business, Tim.


Top
 Profile  
 
 Post subject: Re: Definitive Malware Prevention
PostPosted: Tue May 17, 2011 12:54 pm 
User avatar

Joined: Mon Sep 06, 2010 1:56 pm
Posts: 334
Location: Oshawa, Ontario, Canada
Ive actually noticed in the past that malware bytes installs a background process or service that runs all the time but does not use up barely any resources. I suspect this is the real time agent for they're advertised defenses. I really wanna try it but don't wanna fork out the doh lol.

on another note I looked into tests form other various sites for comparison on proactive AV suites. Current versions of kaspersky and Symantec are currently leading. It was a brief overview of some of those dynamic tests but from what I could tell is that they are both impenetrable to the strains of infections performed. I however, I did not look as to how many tests or strains were analyzed but from the 10 or 15 suites that were tested it seemed pretty on point in respect to the results I get here on my bench.

anyways check out the site http://www.av-comparatives.org
I did some background checking on them as well to see if they are in any way associated to any specific av products and they seemed to come up clean so take it with a grain of salt.

_________________
A1Computers
905-432-6862
Oshawa, Ontario, Canada
Sales@A1Computers.ca
http://www.a1computers.ca


Top
 Profile  
 
 Post subject: Re: Definitive Malware Prevention
PostPosted: Wed May 18, 2011 2:27 pm 
User avatar

Joined: Mon Sep 06, 2010 1:56 pm
Posts: 334
Location: Oshawa, Ontario, Canada
It appears that Malwarebytes and SAS are unable to detect and remove the TDSS tld4 rootkit. Combofix also claims it does however it returns through the spooler.

_________________
A1Computers
905-432-6862
Oshawa, Ontario, Canada
Sales@A1Computers.ca
http://www.a1computers.ca


Top
 Profile  
 
 Post subject: Re: Definitive Malware Prevention
PostPosted: Wed May 18, 2011 4:28 pm 
User avatar

Joined: Sun Dec 12, 2010 10:26 am
Posts: 252
Location: Charlotte, NC
I get machines that have kaspersky installed and up to date and still get infected.

Rafael Garces
MCSA, ACMT, CompTia A+, NET +, MCP


Top
 Profile  
 
 Post subject: Re: Definitive Malware Prevention
PostPosted: Wed May 18, 2011 7:43 pm 
User avatar

Joined: Thu Jun 12, 2008 4:16 pm
Posts: 1325
Could you elaborate as to how it prevented you from going to these three sites. Does it just stop the browser and throw up a warning or what?
Also what browser did you use?

Yes. You simply get a pop up dialogue from Malwarebytes that states:
"Malwarebytes successfully blocked access to 22.22.11.44 (example) and denied access".
And it does not care what browser you are using.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post a new topicPost a reply Page 2 of 3   [ 22 posts ]
Go to page Previous  1, 2, 3  Next


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

Learn How To Fix Laptops



Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
610nm Style by Daniel St. Jules of Gamexe.net
Change colors.