She-geeks Forum
May 28, 2012, 01:34:49 AM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Get your gear at the new She-Geeks shop:: http://www.cafepress.com/shegeeks
 
   Home   Help Search Login Register  
Pages: « 1 2   Go Down
  Print  
Author Topic: Anit-Spyware, Anit-Virus, & Firewalls.  (Read 1959 times)
0 Members and 2 Guests are viewing this topic.
fraggle
Honored Member
Full Member
**********

Karma: 722
Offline Offline

Posts: 205



WWW
« Reply #15 on: May 13, 2008, 04:02:38 PM »

i am not that familiar with rootkit injection techniques ( especially the mbr ), but the possibility of using API calls to manipulate specific system files could be high or not?
well, we could then monitor the API calls of the rootkit application in a sandbox environment with rohitab's api monitor ( http://www.rohitab.com/apimonitor/index.html ).
but thats not supposed to be the perfect solution, *imo* youll have to reverse engineer it to be more then 99% sure.
icesword is also a good rootkit scanner, you can watch :
- open ports
- autostart entries
- loaded kernel modules
- message hooks
- system service descriptor table ( a kernel-intern-table, contains the api-function addresses, rootkits hook mostly one of these functions )
-....
http://pjf.blogcn.com/index.shtml

the page is in chinese, you find it on the top of the site.
Logged

>>All the war-propaganda, all the screaming and lies and hatred, comes invariably from people who are not fighting.<<

George Orwell
seem
Newbie
***

Karma: 200
Offline Offline

Posts: 8



« Reply #16 on: May 14, 2008, 01:06:41 PM »

Some rootkits are not detectable until now in an running windows system, nearly the same then the Database Rootkits which could sometimes be found on an unsecured Oracle Database. For those systems youīll need a clean bootable system, like a live Linux Distro or simething like that. Also the newest, at the moment only PoC and not seen in wildlife until now, VM Rootkits can only then be detected.

A famous system for the last sort of rootkits can be found here http://bluepillproject.org/

bluepillproject is from Joanna Rutkowska, which have done a lot of saecurity engineering, written books and so on. Itīs open source and so imo we will see it in the internet in less then 2 years as a functional version, for testing purposes i had downloaded it and tested it with an Windows XP System, where no performance bugs or different API calls could be found, all Rootkit detection tools, AV and so on hasnīt found anything...

Possible we can try to start an internal project about that, where itīs possible to see changes to real hardware. One thing which should work for detecting is Virtualization on modern processors with hardware based virtualization, which isnīt usable under it, but hasnīt been tested by me

Regards,
seem
Logged
Divine Diva
Sr. Member
**********

Karma: 1695
Offline Offline

Posts: 589



« Reply #17 on: January 11, 2009, 06:06:10 PM »

i see that this thread is somewhat old but i need some ideas as to good anti virus and spyware programs. my puter is running slowly and all i do is get on the net. any ideas???
Logged

Love me or  hate me....either way you're thinking of me!
justy
Administrator
Hero Member
*************

Karma: 4588
Offline Offline

Posts: 1407


but then it's your life uh huh, it's your life. uh, huh. but, you've only got one.


WWW
« Reply #18 on: January 11, 2009, 06:15:38 PM »

i see that this thread is somewhat old but i need some ideas as to good anti virus and spyware programs. my puter is running slowly and all i do is get on the net. any ideas???

well, the ones we listed are the most current, widely used out there. the ones we listed are still the best out there. i would recommend doing a free scan with uniblue spyeraser. if you have any infections, let me know & i will send you the craq for the software so you dont have to pay.
Logged

01101010011101010111001101110100011010010110111001100001
swytch
GeekTastiC
Administrator
Sr. Member
************

Karma: 4020
Offline Offline

Posts: 726


"Quis custodiet ipsos custodes?"


WWW
« Reply #19 on: January 16, 2009, 12:03:56 AM »

@tootie-

My PC Repair kits still consists of 4 things:

1.  AVG Antivirus
2.  Spybot Search & Destroy
3.  CCleaner

...and the most often overlooked and potentially best tool...

4. GOOGLE  (we love you Google)

I swear by those 4 things.  I've yet to run into a PC I couldn't clean with them.


As for firewalls.. I tend to dabble with hardware firewalls.  I have used Zonealarm in the past but if you are looking for the best, i would check out what Steve Gibson suggests at the moment.  He has a good weekly podcast, "Security Now".  find out more about him here:
http://www.grc.com/default.htm

Podcast Link:  http://www.grc.com/securitynow.htm

Swytch~~   Cool
Logged

The present moment is your only reality...
tomron
Full Member
*******

Karma: 351
Offline Offline

Posts: 254



« Reply #20 on: February 16, 2009, 06:12:45 PM »

@seem

rootkits can be detected with F-Secure BlackLight
Logged

Click for Garfield, New Jersey Forecast" border="0" height="41" width="127
tomron
Full Member
*******

Karma: 351
Offline Offline

Posts: 254



« Reply #21 on: February 16, 2009, 06:20:40 PM »

The programs I use are:

Avira

Super antispyware

HJT

spyware blaster...which is not a scanner,but rather prevents an intrusion.

Windows built in firewall.

All are freebies... Wink





Logged

Click for Garfield, New Jersey Forecast" border="0" height="41" width="127
Pages: « 1 2   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
.
Custom Search