Gizmo's Freeware is Recruiting
We are currently looking for people with skills and/or interest in the following areas:
- Anonymous Surfing Service
- Mobile Apps contributors
- Mac Section contributors
If this sounds like you then click here for more details
Best Free Intrusion Prevention and Detection Utility for Home Use (HIPS)
|
In a Hurry?
|
|
|
|
Introduction
|
|
Gone are the days when a virus was a virus and everything else was - well – different! Now known collectively as “Malware” these threats are constantly evolving and pose a serious challenge to security software. Signature based scanners give the most reliable detection results but these are limited by the frequency of their database updates. To compliment signature recognition software HIPS programs were developed which look for behavior on your PC which is “characteristic of malware activity”. The user is then presented with an alert to either allow or block the event. Some programs automate this process which can occasionally lead to problems. See my article “HIPS Explained” which deals with this and other issues in more detail. Evaluating the performance of HIPS programs is far from easy and any so called “test results” should be viewed with a degree of caution. It is straightforward enough to feed malware files to a selection of signature scanners and then count what they find to arrive at a score. AV Comparatives provides an admirable service here and the results are always consistent and reliable. There is no such definition line possible for testing HIPS software and my feeling is that some of the vendors may possibly use this to their own advantage (“hype”). Review Criteria |
|
Discussion
|
|
With signature based scanners becoming less effective against new threats, programs like Threatfire have an increasing role to play in PC security. This has also been recognized by commercial vendors like F-Secure (DeepGuard) and Emsisoft (Mamutu) who have been using this technology for some time. Like these other programs, Threatfire constantly monitors your system for behavior typical of that exhibited by malware such as capturing your keystrokes etc. When used together with a traditional real-time anti virus and a good firewall, Threatfire provides the often missing link for behavioral based detection. Threatfire also contains a highly effective system activity monitor which will display your autoruns in addition to other useful information. The other tab on the advanced settings though is only for truly experienced users with a high degree of Windows system knowledge. Creating advanced rules with Threatfire can render your system unusable unless you know exactly what you are doing. In the hands of experienced users though this facility is a formidable tool. *Windows 2000 users please note that you need V4.1 of Threatfire. See footnote 3 and other useful information including the download link on this page.
Malware Defender was formerly a commercial program, but this excellent HIPS changed ownership a while back and a new version was released as freeware. The sequence of events relating to this event is set out quite nicely here if anyone is interested. Just follow the thread through. In addition to the usual file, registry and application modules, Malware Defender also provides network protection should you choose to enable it, including a connections monitor. This makes it the ideal companion for anyone using Windows own firewall, but wanting more detailed control. It also scores very highly in the Matousec tests for those inclined to value the results. It was difficult to know exactly where to place Malware Defender in terms of a review rating. For what it does it's an excellent performer but the complexities of using it make it unsuitable for average users. Mistakes can be rectified by changing rule permissions from the log entries, although if you've already denied a vital system function, your screen might now be empty!
WinPatrol has many advocates and has recently been upgraded to achieve greater compatibility for Vista and Windows 7 users. It's main objective is to warn you about alterations to your system which may be malware generated. It does this by taking a snapshot of your system settings and alerting you to any changes. WinPatrol operates using a heuristic approach which makes it more likely to find new malware than traditional signature based scanners which are heavily reliant on updates. WinPatrol will alert you to new program activations as well and is effective across a whole range of malware including worms, trojans, cookies, adware and spyware. Even stuff designed to replicate itself on your system is with WinPatrol's reach. You can also use WinPatrol to filter unwanted cookies and IE add-ons. An added bonus is that WinPatrol will also deal with the problems it finds so you won't need another program to do this for you. As of V19.0, WinPatrol becomes a "Cloud Edition". Mostly the extra features will only benefit users of the paid Plus version. One part of the WinPatrol Cloud though is a poll where the WinPatrol community of users can provide personal feedback on files that are detected. The poll data will be available to both FREE and PLUS users. The author, Bill Pytlovany, provides support and has an interesting comments and resource blog here: http://billpstudios.blogspot.com/
The program now also includes: Process Launch Monitoring, Folder and File Hooking, EMailing of Alerts and Quarantining of Files and Directories. There is an active thread for this software at Wilders forum here: http://www.wilderssecurity.com/showthread.php?t=54666 The author, Mark Jacobs, also maintains a range of other free software on his website and will respond to emails for support if requested. |
64 bit support for Vista only
- Article type:






Comments
Hi MC! I'm just curious if you have heard of or could find out if there is any plans for a 64-bit version of Malware Defender in the future? Thanks as always...D.
To my best knowledge no, but I would welcome comments from anyone who can understand Chinese if this information is contained on their site somewhere.
I believe that Malware Defender has been updated
Thank you. I've now changed the version details.
Btw, the installer is available at 360Labs. It's digitally signed and, according to VT, clean. Keep up the excellent work.
[Edit] Thanks for this but the site has a bad WOT rating so we are unable to post the link.
Np. I was misled by the green WOT mark. Just viewed the users comments. IMHO, the app itself should be safe, though.
Seems like Spyware Terminator has been taken over by Pcrx. Now when you try to open the Spyware Terminator site, it redirects to the site of pcrx which is rated red on WOT.
Yes, I've been following this for a while now since they also aligned with F-Prot. I was rather hoping for some better developments but under the circumstances probably best to remove it altogether.
Good decision I think. Best to remove, and keep a watch on further developments.
There are compatibility issues with Avast anti-virus and Threatfire,both HIPS conflict with each other. Avast's HIPS is sufficient but if Avast is not your choice of anti-virus then it might be a good choice to install Threatfire. Some swear by WinPatrol but I have found the program to be waaay too slow in detection and that makes it unsafe to use.
I am running WinPatrol at this time. Will there be a conflict also using the FF extension/add-on BrowserProtect? My AV also has some HIPS/behavioral detection ability. Thanks for this site.
There will always be a certain element of duplicated protection when running apps of a similar type together. WinPatrol is pretty good though at coexisting with other programs. The only potential issue (with your AV) is it could cause WinPatrol to freeze when it periodically checks your system. You will see if this happens because the WinPatrol icon will lock and become unresponsive.
I have been testing Threatfire for a few days and I have to say that I don't like it at all. It interfer and stop normal programs and games from working. Games like Planetside, Civ V and Skyrim is all having start up problems. I have tried to add custom rules and change default settings. I have added to the process lists multiple files from Planetside. Nothing seem to work. I will say that a security software should not make mistakes like this. This is probably the first software that Gizmo's have recommended that is not working well.
I am considering using the free version of SpyShelter. However with my current setup already including Panda Free AV, Windows XP firewall and WinPatrol will this be overkill keeping in mind that SpyShelter has a HIPS component? If not would they even be compatible? I also use Sandboxie from time to time.
It all depends on your risk exposure. If you use a reliable site ratings agent like WOT (Web Of Trust) in conjunction with Panda's URL filtering, this will be more than adequate for normal surfing. Also, SpyShelter is known to cause issues with other products, especially if the system in which they are both resident is not 100% stable. If you are still considering SpyShelter, I would Google around for some of these issues before making a decision. Many will argue that the permanent use of Sandboxie removes such a need altogether, but operating your system this way (or not) is of course a personal choice.
Thanks MC. I actually removed the Panda URL filter as it was interfering with access and loading of many sites. Now I wonder if it simply needed some tweaking and configuring. My question is how much security do I sacrifice if I leave this Panda feature off?
Well, if you only download files from trusted sources and scan them before execution, apart from the usual dangers associated with removable media, your biggest threat exposure is to online exploits. Panda's URL filter is very effective although I appreciate it gives problems for some users, but not everyone. You've therefore got two choices. You can either post for some advice direct to their forum:
http://www.cloudantivirus.com/forum/index.jspa
Or you can try something else. This one is marching up the VB RAP testing tables thanks to a lot of recent investment in the product and the web filter is top grade.
http://www.forticlient.com/lite.html
There's also a discussion about it here you might find interesting.
http://www.wilderssecurity.com/showthread.php?t=304393&highlight=forticl...
Thanks MC. I found what I needed on the Panda site you referenced.
Is there any other place to download forticlient Lite from, apart from c***net?
Not to my knowledge except one other site which has a poor WOT rating and is not used or recommended by us. VirusTotal gives five hits on the installer because of how it's compiled.
http://www.techsupportalert.com/content/cnet-downloadcom-wrapped-install...
A good third party firewall firewall will warn you of any potentially unwanted connections at install and give you the option to block these. Having WinPatrol installed will also enable you to prevent the execution of unwanted toolbars or other so called browser helper objects. Otherwise, I would just download the program and scan it with your resident antivirus and malwarebytes, and then make a final decision from that. Personally, I find Fortinet to be a responsible and trustworthy vendor, but I do wish they wouldn't associate themselves with cnet.
The FortiClient Standard full freeware suite is still available on Softpedia, but this is maybe not what you want. It's also debatable for how long they will make updates available to support this version.
http://www.softpedia.com/get/Security/Security-Related/FortiClient.shtml
I still have several folks around here running this suite and none of them have ever been infected or experienced system issues.
Many Thanks for your reply MidnightCowboy. Yes I wanted the 'lite' version really. I agree with your comments re the Cnet association. Is it still the case that if you register with them you can avoid their dubious installer and just get the required executable?
As far as I'm aware, although I haven't tested out this procedure myself.
Regarding FortiClient Lite. I downloaded the installer from freewareupdate dot com. I don't know if this was the site you were referring to or not. I found it from a search. Anyway, the installer scans as clean on VirusTotal and Jotti's. I just wondered if anybody had any experience with the aforementioned site?
All I know is this is a new site and attempts have been made to spam links for it here :)
And it looks like FileHippo. Many sites have come up lately, which are look alike of FileHippo. Why don't they come up with something original?
I suppose in a way it's a compliment to the original but yes, it would be nice to see something more innovative :)
Hi Midnight Cowboy, I am looking for a registry protection/shield program and I want to ask u about MJ Registry Watcher. I have very little knowledge of the Windows registry and do you believe by using that software is safe for me to use or do you think it could damage/harm my pc, which would result in a reformat.
If it is not safe do you know another safe alternative as I know Winpatrol has a Registry shield but not in the free version.
Hi James D. Unfortunately,there is quite a steep learning curve with MJ Registry Watcher, even when left at it's default settings. You're unlikely to wreck your system using it, but potentially not being able to respond to the alerts correctly could give you some unwanted issues.
So long as you are not running a 64 bit system, one alternative would be AVS Firewall.
http://www.avs4you.com/AVS-Firewall.aspx
I'm currently using this myself on Windows 7. Apart from the usual firewall functions, it also includes an ad-blocker, parental control and a registry protection component. All these extra components can be enabled separately. The registry protector will advise you in simple language that "component "X" is trying to modify your registry - do you allow this?" Mostly, it will be pretty obvious from what you are doing at the time what has triggered the alert and if it is safe to allow. Just be aware that some programs will throw up this type of alert when you are un-installing them. Usually this is because they need to run a component on reboot to tidy up after the removal. If you block these, it could lead to items being left behind.
i think threatfire should be reviewed again.
4.7 came out in 2009
A recent youtube test video suggest it doesnt contribute much to further protection
http://www.youtube.com/watch?v=Q_8oozyUPKc
Malware Defender gives the error 'failed to load Malware Defender driver'. Tried several times to run with no luck on Win7 64 bit....
Post new comment