Author Topic: Info on mysterious executable stonewalled by Symantec?  (Read 8046 times)

0 Members and 1 Guest are viewing this topic.

drhayden1

  • Guest
Re: Info on mysterious executable stonewalled by Symantec?
« Reply #15 on: March 11, 2009, 03:22:10 AM »
Quote
Now aren't you all glad now to be part of this big avast family?
Sure am :)
And Damian when are you going to invite the family all over for dinner ;D
Guess i will use the PCTools Firewall Plus until the Avast! one is available ;)
« Last Edit: March 11, 2009, 03:28:16 AM by drhayden1 »

Hally

  • Guest
Re: Info on mysterious executable stonewalled by Symantec?
« Reply #16 on: March 11, 2009, 12:55:40 PM »
Hi drhayden1  :)



Guess i will use the PCTools Firewall Plus until the Avast! one is available ;)

Please Note!
If you do install - PC Tools Firewall Plus
You should probably turn  - Enhanced Security Verification - OFF

Open ... PC Tools Firewall Plus
Click On - Settings
Click On - Filtering Tab
Un-Tick - Enable Enhanced Security Verification
Click On - Apply

I've got PC Tools Firewall Plus on both my Laptop and Desktop Computer ... But with ESV - OFF

Why?

Coz...
Starting Since Version 4 ... PC Tools Firewall Plus .. Now Comes With - Enhanced Security Verification ( ESV )
ESV .. Is a relatively new feature that PC Tools have added to their Firewall ... But It Has Problems  ::)
Can Cause.. High CPU Spikes, Manic Hard Drive, Freezes, Blue Screens  :o
So!
Even though - PC Tools Firewall Plus .. Is a great little Firewall  :D
Enhanced Security Verification .. Is Best Left -  OFF  .. Till they get it right!  ;)

Just remember to turn ESV - OFF .. And you should have No Problems at all  :)
« Last Edit: March 11, 2009, 12:57:31 PM by Hally »

drhayden1

  • Guest
Re: Info on mysterious executable stonewalled by Symantec?
« Reply #17 on: March 11, 2009, 02:25:44 PM »
Quote
Just remember to turn ESV - OFF .. And you should have No Problems at all

thanks-just did-but never had any problems with pctools firewall in the first place :)
« Last Edit: March 11, 2009, 02:27:59 PM by drhayden1 »

Hally

  • Guest
Re: Info on mysterious executable stonewalled by Symantec?
« Reply #18 on: March 11, 2009, 06:47:11 PM »
Hi drhayden1  :)


Quote
Just remember to turn ESV - OFF .. And you should have No Problems at all

thanks-just did-but never had any problems with pctools firewall in the first place :)

Sorry!  :-[
I didn't realise you already had PC Tools Firewall Plus installed.

That's why I wanted to warn you  ;)
Blue Screens ... Can be rather a Shock!  :o

Some people say their computers are OK with .. ESV - ON
But for most people...  :'(
See Here : http://www.pctools.com/forum/forumdisplay.php?f=30

drhayden1

  • Guest
Re: Info on mysterious executable stonewalled by Symantec?
« Reply #19 on: March 11, 2009, 07:06:01 PM »
Quote
I didn't realise you already had PC Tools Firewall Plus installed
Been using it since the beginning and waiting on the Avast! Firewall ::) ??? ;D
« Last Edit: March 11, 2009, 07:10:02 PM by drhayden1 »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Info on mysterious executable stonewalled by Symantec?
« Reply #20 on: March 15, 2009, 01:38:08 AM »
Hi malware fighters,

Explanation about the reaction to the executable here:
and this: http://pifts.blogspot.com/2009/03/found-very-interesting-post.html
Also the Anubis analysis link for it there: http://anubis.iseclab.org/?action=result&task_id=19d7659347c3ebcd4a5ba7e9faa60fa14&format=html
Why they did not allow it through the firewall is strange if this is not pure speculation by the blogger...
Unfortunately, the analysis of the program is not by a programmer and the reason why this program opens up so many of these folders is not because they are scraping the contents, but because the libraries and modules they are using to access the Internet automatically access them. I monitored all file access while running the program, and yes they did access the folders, but did not query the contents. Misinterpretation is the food of conspiracy....

pol
« Last Edit: March 15, 2009, 01:54:45 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!