- Feb 15, 2012
- 2,128
I m usi g Voodoshield 2.75 and I like it as its ability to scan with 56 VT scanner when something unknown is detected.
I asked the above because I didn't know if Voodoshield worked at kernel level (thanks Hjlb for the info that v. 3 will be!) and exactly what kind of files are controlled.
I don't think they have a memory or folder, registry protection.
I read a lot about AG, but I'm still not sure what files are guarded.
NVT is where I have no infos. Does it wotk at kernel mode, what files does it guard, does it have memory protection?
yeah, me too... I tried NVT ERP, but I didn't get along with it... VooDooShield just does what I expect of it, and fits in very nicely with my setup....VooDoo Shield (paid) gets my vote.
I love the layout of the program and how well it works. PeAcE
Hjlbx,VooDooShield is a pure anti-executable; it provides no folder, memory or registry protection. Not sure if it will ever be added.
Basically, AppGuard protects everything except ProgramData and User Profiles (by blocking writes, memory injection into processes) ... however, you can customize it to get softs to work.
NVT ERP is a pure anti-executable; it provides no folder, memory or registry protection. Andreas the developer isn't going to add it. I know NVT ERP can block installation of kernel mode drivers. NVT ERP has nice feature where use can white-list command lines - like control panel command lines that use rundll32.exe. Can block\regulate any interpreter and vulnerable processes too.
If you want maximum security, then combine AppGuard and NVT ERP... or VooDooShield when stable v. 3 is released.
On top of anti-executable add virtualization and outbound firewall notifications and that is about as good as it gets. It isn't 100 % bullet proof but it is as close as you can get without turning your system into a tank - in which case it would be so loaded down that it won't work unless you have a Xeon core.
Hjlbx,
Thank you for the clear and informative answer!
My last question is, do they all check the same files(exe, script, dll, scr, ...) or what program covers more types?
In advance, nice weekend to all!
But I think talking to each other via PM might have been more successful. Then, if there was really a bypass against VS, then Dan or r41p41 could explain what happened. Then, the hole could have been patched without any dramas created.Scrutiny from an Inquisitive mind: "POC or didn't happen" for AppCert Bypass
In case some of you missed the discussion on Wilders.
The researcher was kind enough to register on the forum and explain things. That alone is a great thing, as it rarely ever happens. Because folks over there (including developers) didn't even understand what he was saying, he was constantly asked to proof his findings in a video, of course without being compensated for his time and work. When he initially refused, he was treated in a condescending way and then, and only then, responded in kind. Then his postings were being removed for being condescending and his rights to post further were taken away as well, the thread was also locked.
He then responded with a POC on his blog. It turns out he was right from the beginning. The flaws he is pointing out are really embarrassing. I guess other researchers will take this as a reinforcement of their practice to abstain from active participation in forums like this.
So once again, we poor average home users have to rely on the promises of the industry only, because researches will either abstain or get censored, should they be so kind to share their findings with us.
But I think talking to each other via PM might have been more successful.
I hear people say that there is a free version of "NoVirusThanks Exe Radar Pro" but, I can't find it.
I hear people say that there is a free version of "NoVirusThanks Exe Radar Pro" but, I can't find it.
And everyone of the above have been by pass accept, VooDooShield. Correct me if I am wrong?