Jump to content

LUSHER

Experienced Members
  • Posts

    89
  • Joined

  • Last visited

Posts posted by LUSHER

  1. There was thread about the new version of Hijackthis and in that thread it was said the there was no reason to keep the older version because the new one had many improvements. Now what?

     

    http://forum.piriform.com/index.php?showto...t=0&start=0

     

    This thread changes nothing. Hijackthis is not spyware. Pretty much everyone who is anyone has agreed that the blog content is wrong.

     

    JeanInMontana MSMVP and noted figure in antispyware circles summarised the reactions to this silly accusation at

     

    http://blog.malwareteks.com/?p=133

     

    "IMO calling it spyware is stretching the definition of what that word means to most of the community. There are several other reputable programs that have some sort of upload function. Some are for false positive reporting, others for submitting possible malicious files. What Trend Micro has done is really no different.

     

    The thing doesn’t work or didn’t when I tried it. It did nothing. I could get behind addressing that issue.

     

    I think it could be detrimental in the hands of a inexperienced person, but so can the older versions. HiJack This! has always been a tool if used improperly there is/was chance of disaster.

     

    I have actually used it since it was still in beta at Malwarebytes. Marcin instructs users to install and scan with it to remove the 022 lines not shown in older versions. I found no problems.

     

    There is a ruckus amongst the forums and most comments I’ve seen are opposing Blair’s opinion.

     

    http://www.castlecops.com/postlite196457-.html

     

    http://www.dslreports.com/foru.....ould-it-be"

     

    Others include dgosling , Security MSMVP and staff member at TomCoyotes among others says

     

    "I am also a member of the staff at TomCoyote and believe that this article does not represent the opinion of the staff at Tom Coyote but of one person - the author.

     

    It also seems to me that the user is given a choice of whether to upload their log or not just because they have to click on the button 'Analyze This' to do so.

     

    I also would like to point out that the text on the "Analyze This" button changes to "Send Log to Trend Micro" after the log is sent. This might be argued as being a little late for notification of the user, but as far as I'm concerned the average user would know they were uploading their log to Trend."

     

    There are many more who use their brains instead of blindly jumping onto the bandwagon. who think this accusation of spyware is insane.

  2. Come on guys. I know you hate big corporate Trend and you think the antispyware at TomCoyote are saints, but this time they are wrong.

     

    Okay, so when you upload something to Trend it gives you %tages of how common it is, which might be useless. Okay say I grant you that.

     

    How does that make Trend Spyware? The button is clearly labelled that it will upload it to Trendsecure. And it only does that if you press the button. How is this "Deceptive"?

     

    Besides how is this spyware? Similarly some antiviruses have features where you can choose to upload suspicious files to the vendors for checking but only if you click the button, so that's spyware too?

     

    Come on guys, Think! Resist spreading FUD.

  3. Cheers, very useful.

     

    Was looking at the vitual apps page HERE, not sure Returnil should be only in 'Partition virtualization' section?

     

    Where should it be then? I'm pretty sure it doesn't create a complete virtual machine.

     

    Also on that same page an amusing typo:

     

    Thanks fixed.

  4. Beyond the good freeware security listings I noticed some outdated info about Burnatonce in the cd burning section. The version of ProDVD required to enable DVD burning in Burnatonce doesn't time-out anymore to my knowledge, nor does it have to be registered anymore to get a key.

     

    Andavari, which page are you talking about? I'm not too familiar with the section you are talking about and searching doesn't seem to find anything. Even better if you would be kind enough to register and edit the page yourself. It's very simple, takes you 5 minutes tops once you registered.

  5. Hi LUSHER, nice find.

     

    I've downloaded that and I'm gonna give it a try.

     

    Thanks.

    :)

     

    Hi Dennis, thanks for trying it out. Feel free to post any comments on the runscanner forum or here if you wish.

  6. Yes that is quite a good app but I think Hijackthis is firmly entrenched as the mainstay app for security analysis.

     

    You are probably right inertia will definitely play a role. Plus currently it is a bit too complicated (too many buttons!), for use on ASAP forums where you want the user to be able to follow simple short steps/instructions and all you want is something barebones.

     

    But capability wise (barring bugs) it is already more capable than Hijackthis, particularly since it provides a more through "scan". Plus other helpful capabilities.

     

    but then again sometimes less is more.

  7. RunScanner

     

    RunScanner is a completely free windows system utility which scans your system for all configured running programs. You can use runscanner to detect autostart programs, spyware, adware, homepage hijackers, unverified drivers and other problems. You can import and export your results and let other people help you to solve your problems.

     

    post-11644-1184754920_thumb.png

     

    Very comprehensive autostart list

     

    *Scanning of 80+ hijack locations ,Host file editor

     

    Covers everything from autoruns, HJT, silentrunners and more. Malware will find it harder than ever to hide.

     

    Easier to use

     

    *Online malware analysis of results

     

    *Verification of file signatures (Microsoft signed, Other Signed, Whitelisted by online database )

     

    *MD5 hash calculation of files + online file rating

     

    *Online lookup of scanned entries. (Runscanner database + Google)

     

    RunScanner makes it easier to determine which entries are likely to be malicious.

     

    Log analysis made easy

     

    *Saving and importing of text files (all information available)

     

    *A user with problems can save the .run file, an expert can mark the items that need fixing and send the .run file back to the user

     

    If you are really worried, RunScanner also exports a easily readable textfile of all finding that can be sent to an expert for checking.

     

    Malware removal abilities and misc

     

    *Powerful process killer

    -Kill multiple processes at once

    -Kill and rename

    -Kill and delete

    -Delete at next reboot

    *Regedit jump

    *Explorer jump

    *Extended filters

    *Marking of items.

     

    Many other features that experts have come to expect in malware inspection and killing tools.

    post-11644-1184754920_thumb.png

  8. gmer seems to be the best rookit scanner program from what I've read. I really doubt he has a rootkit anyway considering all the scans he did

     

    I doubt he has a rootkit either. Just saying rootkit unhooker does seem to best based on the review of antirootkit tool done a while ago.

     

    GMER is perhaps more famous thanks to the whole DOS thing they got. And there is bad blood between the two authors...

  9. Actually was more worried about a rootkit, but Sophos, gmer, RKR, and Icesword show none. Learned about all those utilities on this forum, by the way. They are really useful and free. I appreciate all the knowledge that goes into these posts. :D

     

    try rootkit unhooker, from all the buzz it seems to be the best antirootkit around surpassing icesword, darkspy, rkr etc..

     

    http://wiki.castlecops.com/Online_antivirus_scans also has a very (perhaps too) complete list of online scanners.

  10. Shankira. :wub:

    Although, I don't actually like her music. :P

     

    Lusher look for TonyKlein at Castle Cops. I think you will find he knew what he was linking to.

     

    LOL. What makes you think I don't know who Tony Klein is? Look me up in castlecops wiki as well.... and you will see I know more about wikis and wikipedia than Tony... Hint, the pages he linked were created by me.

     

    BTW being knowledgeable (spyware) in one area doesn't' mean Tony can't be mistaken on the difference between a wiki and Wikipedia (a very common mistake for most people). to my knowledge Tony doesn't do wikis, while I'm a post graduate student doing a master thesis on Wikis...

     

    To call the castlecops wiki, Wikipedia is a mistake regardless of who is making the statement!

  11. Aargh, I'm unable to get my Wikikpedia 'HIPS' link to work; here it is: http://wiki.castlecops.com/HIPS_FAQ

     

    Excuse me, but the link does not go to Wikipedia but to CastleCopsWiki which is a totally different thing. Even though the same Wiki package is used (hence the similarity in look), the CastleCopswiki is totally unrelated to Wikipedia!

     

    http://wiki.castlecops.com/HIPS/IDP_programs/services

     

    Comparison of various HIPS , many of which are free, or have free versions indicated in the table.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.