<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Did Process Guard stop the Sony rootkit? in Security</title>
<link>http://www.dslreports.com/forum/r14852681</link>
<description></description>
<language>en</language>
<pubDate>Sat, 05 Dec 2009 20:05:22 EDT</pubDate>
<lastBuildDate>Sat, 05 Dec 2009 20:05:22 EDT</lastBuildDate>

<item>
<title>Re: Did Process Guard stop the Sony rootkit?</title>
<link>http://www.dslreports.com/forum/remark,14858183</link>
<description><![CDATA[<A HREF="/useremail/u/532849"><b>Wayne DCS</b></A> :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>I would have hoped that 95% of the people who have the nous to have ProcessGuard installed would also have sufficient knowledge and nous NOT to have installed the rootkit.<HR></BLOCKQUOTE><br>That's a good call Oremina. The ProcessGuard website and helpfile both have plenty of information about rootkits, and there are even Tips Of The Day in PG itself with such info - it's just as important to arm customers with good security knowledge as it is to arm them with good security software. One of the main options in ProcessGuard is "Block Rootkit/Driver/Service Installation" - a checkbox you can simply turn on or off at will, so ProcessGuard users are generally quite aware of drivers and their security implications.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14858183</guid>
<pubDate>Tue, 22 Nov 2005 04:26:52 EDT</pubDate>
</item>

<item>
<title>Re: Did Process Guard stop the Sony rootkit?</title>
<link>http://www.dslreports.com/forum/remark,14858166</link>
<description><![CDATA[<A HREF="/useremail/u/1017599"><b>Oremina</b></A> : <div class="bquote"><SMALL>said by tstop :</SMALL><br><br>I'll bet 95% of PG users would have allowed the Sony rootkit to install if it wasn't so widely publicized. <br> </DIV>I would have hoped that 95% of the people who have the nous to use ProcessGuard would also have sufficient knowledge and nous NOT to have installed the rootkit.<br><SMALL>--<br>Oremina<br><br></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14858166</guid>
<pubDate>Tue, 22 Nov 2005 04:13:15 EDT</pubDate>
</item>

<item>
<title>Re: Did Process Guard stop the Sony rootkit?</title>
<link>http://www.dslreports.com/forum/remark,14858106</link>
<description><![CDATA[<A HREF="/useremail/u/532849"><b>Wayne DCS</b></A> : Yes! <A HREF="http://www.diamondcs.com.au/processguard/">ProcessGuard</A> easily stops it - at many levels, and has had this capability for well over a year. :)<br> <br>If you want to allow the rootkit to install you actually have to tell ProcessGuard to allow the execution of several different programs and also the installation of a couple of drivers (you'd probably be suspicious of what is installing by this stage :)) in order for the installation to complete and the rootkit to install. If you simply say No to any of these you'll disrupt the installation process and the rootkit driver won't install.<br> <br>We'll add some more comprehensive info about this to the ProcessGuard website soon, but I'll attach a couple of screenshots.<br> <br>The first screenshot is what you see when you first put the CD in your machine, when autorun is enabled. Autorun.exe is launched, and ProcessGuard asks you if you want to allow it.<br> <br>At this stage you could simply click No, and ProcessGuard would block it from running and that's that - the installation process has been blocked, so even at that early stage it's easy to block it. However for this demo we'll say Yes to everything, to essentially allow the full installation so that we can monitor everything that happens.<br> <br>The second image shows one of the popup balloon windows youll see when a program attempts to install a driver.<br> <br>The third image is a composite of two images that were taken after allowing everything to install - you can see that the installation is quite vigorous, and we had to say Yes (Permit execution/installation) a lot of times.<br> <br>If you do permit everything to install then you will have installed the rootkit. The fourth image shows some of these files.<br> <br>:)<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14858106?c=927309&ret=L2ZvcnVtL3IxNDg1MjY4MS54bWw%3D"><IMG TITLE="25292 bytes" BORDER=0 WIDTH=402 HEIGHT=372 SRC="/r0/download/927309~0ef07bc05a37c09cae1607af40508772/pgsony1.gif"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/14858106?c=927310&ret=L2ZvcnVtL3IxNDg1MjY4MS54bWw%3D"><IMG TITLE="4508 bytes" BORDER=0 WIDTH=259 HEIGHT=84 SRC="/r0/download/927310~3a82e7eb4a3b334f7a4fa37f445d1915/pgsony2.gif"></A></TD><TD ALIGN=CENTER BGCOLOR=#000000 nowrap width=1%>&nbsp;</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14858106?c=927311&ret=L2ZvcnVtL3IxNDg1MjY4MS54bWw%3D"><IMG TITLE="39984 bytes" BORDER=0 WIDTH=596 HEIGHT=469 SRC="/r0/download/927311~92f7204908a0aafd9396c6cdd4971226/pgsony3.gif"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14858106?c=927312&ret=L2ZvcnVtL3IxNDg1MjY4MS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="19531 bytes" WIDTH=600 HEIGHT=484 SRC="/r0/download/927312.thumb600~3e110610626896ad8f124cf26bf26eef/pgsony4.gif/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14858106</guid>
<pubDate>Tue, 22 Nov 2005 03:37:39 EDT</pubDate>
</item>

<item>
<title>Re: Did Process Guard stop the Sony rootkit?</title>
<link>http://www.dslreports.com/forum/remark,14855544</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : A lot of people are less... uh... 'careful' about installing software. But seriously, installing a player is one thing, but allowing something to install a driver is a massive no-no, if you don't even know what the driver does. <br><SMALL>--<br><A HREF="http://nonadmin.editme.com/">Want security? Run as limited user.</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14855544</guid>
<pubDate>Mon, 21 Nov 2005 19:35:04 EDT</pubDate>
</item>

<item>
<title>Re: Did Process Guard stop the Sony rootkit?</title>
<link>http://www.dslreports.com/forum/remark,14855433</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : <div class="bquote"><SMALL>said by tstop :</SMALL><br><br>I'll bet 95% of PG users would have allowed the Sony rootkit to install if it wasn't so widely publicized.<br> </DIV>That may be true. But who would allow a player to be installed? I have PG and yes, I might have allowed the driver to install, but I would never allow the player to install so what does it matter? I guess Sony thinks everyone wants some proprietary player. That is the kicker for me. I got rid of Quicktime, WMP (except version 6.4), Real Player, Rhapsody, etc. I have Winamp and WMP 6.4 and if something won't play on those then I don't want it.  People say DVD discs try to install the interactual player. Not on my computer they don't because Dell has antispyware to stop that. Again, why would anyone allow these proprietary players to install when you have your favorite player already and wish to use it?<br><SMALL>--<br>Around 2005 a sudden spark will catalyze a Crisis mood. The very survival of the nation will seem to be at stake.Sometime before 2025, America will pass through a great gate in history. The risk and promise will be very high. The Fourth Turning Wm. Straus</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14855433</guid>
<pubDate>Mon, 21 Nov 2005 19:21:28 EDT</pubDate>
</item>

<item>
<title>Re: Did Process Guard stop the Sony rootkit?</title>
<link>http://www.dslreports.com/forum/remark,14852681</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I'll bet 95% of PG users would have allowed the Sony rootkit to install if it wasn't so widely publicized. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14852681</guid>
<pubDate>Mon, 21 Nov 2005 12:52:51 EDT</pubDate>
</item>

<item>
<title>Re: Did Process Guard stop the Sony rootkit?</title>
<link>http://www.dslreports.com/forum/remark,14852229</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : Yes, Process Guard stops the rootkit from installing its driver. However, the user can also allow the installation in Process Guard. Process Guard can't decide whether the driver is malicious or not - that's up to the user, and in this case, since the user agreed to the EULA, the user would probably agree to installing the driver as well. Ultimately, it's all up to the user.<br><SMALL>--<br><A HREF="http://nonadmin.editme.com/">Want security? Run as limited user.</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14852229</guid>
<pubDate>Mon, 21 Nov 2005 11:44:30 EDT</pubDate>
</item>

<item>
<title>Re: Did Process Guard stop the Sony rootkit?</title>
<link>http://www.dslreports.com/forum/remark,14852223</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : According to Wayne, yes.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14852223</guid>
<pubDate>Mon, 21 Nov 2005 11:43:55 EDT</pubDate>
</item>

<item>
<title>Did Process Guard stop the Sony rootkit?</title>
<link>http://www.dslreports.com/forum/remark,14852197</link>
<description><![CDATA[<A HREF="/useremail/u/103090"><b>tempnexus</b></A> : Just wondering]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14852197</guid>
<pubDate>Mon, 21 Nov 2005 11:40:19 EDT</pubDate>
</item>

</channel>
</rss>
