Old 04-23-2011, 04:16 AM   #21 (permalink)
Master Untangler
 
Join Date: Aug 2008
Posts: 178
gpeters is on a distinguished road
Default

Quote:
Originally Posted by sky-knight View Post
I just sell the customer the premium web filter. OpenDNS looses it's benefit when you have that filter present.
I now have a customer who is setup with the premium web filter and he has two PC's infected now with XP Antispyware 2011

I guess there is nothing that will stop this monster so far.

Last edited by gpeters; 04-23-2011 at 04:16 AM.. Reason: spelling
gpeters is offline  
Old 04-23-2011, 09:34 AM   #22 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,464
sky-knight is on a distinguished road
Default

What are you using for desktop AV?

Untangle Premium at the edge, and NOD32 on the desktop, and I don't see these infections. The only time a box gets sick is if the thing goes home and doesn't have UT's filters.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 04-23-2011, 07:02 PM   #23 (permalink)
Master Untangler
 
Join Date: Aug 2008
Posts: 178
gpeters is on a distinguished road
Default

Using trend WFBS on desktops
gpeters is offline  
Old 04-24-2011, 05:50 AM   #24 (permalink)
Master Untangler
 
Join Date: Apr 2007
URLs submitted: 1
Posts: 608
bigdessert is an unknown quantity at this point
Default

yeah we use wfbs on over 100 customers sites and it won't really stop any variant of this malware.
bigdessert is online now  
Old 04-24-2011, 06:23 AM   #25 (permalink)
Master Untangler
 
Join Date: Aug 2008
URLs submitted: 10
Posts: 316
blueshoes is on a distinguished road
Default

Trend is only a mid pack AV in detection.

Here is one month out of a four month real world "whole dynamic test" to see how an AV uses ALL it's Suite's resources to stop a compromise or attack. This is one of the best and real world tests out there.


http://chart.av-comparatives.org/chart2.php

.

Last edited by blueshoes; 04-24-2011 at 06:30 AM..
blueshoes is offline  
Old 04-24-2011, 08:09 AM   #26 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,464
sky-knight is on a distinguished road
Default

To be fair, NOD won't "stop" this infection by itself and it has a high rating according to that site. It does however contain things just enough that adding UT's defenses has built a wall strong enough that my ability to remove viruses is actually diminished thanks to a lack of demand for the skill reducing my need to practice it. Which I is the point I might add, that said, these tests are run using the default settings for the AV in most cases. I didn't dig in to see if that test was tweaked to enable heuristics and other advanced features some AV providers leave off.

I'd look into your central console and see if there are any settings you can use to harden the AV modules you have.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 07-21-2011, 05:05 AM   #27 (permalink)
Untanglit
 
Join Date: Sep 2008
Posts: 19
westgj is on a distinguished road
Default

Quote:
Originally Posted by YeOldeStonecat View Post
At clients that I have Untangle at...I have a huge drop in rogue/fake alert problems...but sometimes one still slips through. Yes...a huge drop! So Untangle does help substantially. And this claim is easily made because all other variables are usually quite equal among my clients.
Great summary.

I run Untangle Lite + Kaspersky at 3 sites. I am seeing a number of scareware malware still get through. Are you using the paid Web Filter and if so is that blocking most of these scareware trojans?
westgj is offline  
Old 07-21-2011, 05:57 AM   #28 (permalink)
Master Untangler
 
f1assistance's Avatar
 
Join Date: Apr 2009
Location: Holly Springs, NC
URLs submitted: 154
Posts: 218
f1assistance is on a distinguished road
Default Leading from behind...

Quote:
Originally Posted by westgj View Post
Great summary.

I run Untangle Lite + Kaspersky at 3 sites. I am seeing a number of scareware malware still get through. Are you using the paid Web Filter and if so is that blocking most of these scareware trojans?
The internet is a compilation of dynamic threats and basically we’re all attempting to mitigate risk with one hand tied behind our back. The question is what are we allowing through the gate which is serving the malicious content and allowing our “users” to compromise the domain?
Unfettered internet access cannot be defended and whitelisting works every time it’s tried. The key to information security is a dynamic balance between unlimited permissions and strict denial, and if this were easy anyone could do it...
I would use all the tools I can afford and spend the rest of my time attempting to educate users.

Last edited by f1assistance; 07-21-2011 at 06:23 AM..
f1assistance is offline  
Old 07-21-2011, 08:03 AM   #29 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,464
sky-knight is on a distinguished road
Default

I haven't seen this particular bug in a while, it's been a couple of months. So either my users haven't found a site with it, or Untangle Premium + NOD32 are dealing with it now.

Rogue Anti-Malware is still one of the more common issues on random new client boxes that come in.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 07-21-2011, 08:23 AM   #30 (permalink)
Master Untangler
 
Join Date: Aug 2008
Posts: 178
gpeters is on a distinguished road
Default

I have most of my customer on premium too and have not seen in three months now or so
gpeters is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 10:34 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2