Avenger77 | 09.09.2015 19:28 | Mir wären 90% Windows Defender lieber als 99% AVG, wobei dieses Tool mich dann noch womöglich ausspioniert und einfach zu erkennende Malware wie Sperrtrojaner nicht erkennt.
Reicht Dir das als persönliche Meinung :blabla:
Extra für Dich mal nachgeschaut im Regelwerk: das kleine Tool, die Setup gerade mal 1,5 Mb gross:
Schon vorgefertigt, hier die Blacklist im Behavioral Mode: Code:
//Block command-line strings used by Cryptolocker family
[%PROCESSCMDLINE%: *rundll32*Shell32.dll*Control_RunDLL*\*.exe*]
[%PROCESSCMDLINE%: *rundll32*javascript:*]
[%PROCESSCMDLINE%: *rundll32*;*eval*(*]
[%PROCESSCMDLINE%: *vssadmin*Delete*Shadows*/All*/Quiet*]
[%PROCESSCMDLINE%: *bcdedit*/set*recoveryenabled* No*]
[%PROCESSCMDLINE%: *bcdedit*/set*bootstatuspolicy*ignoreallfailures*]
[%PROCESSCMDLINE%: *bcdedit*-set*loadoptions*DDISABLE_INTEGRITY_CHECKS*]
[%PROCESSCMDLINE%: *bcdedit*/deletevalue*safeboot*/set*safebootalternateshell*false*]
//Block double file extensions
[REGEX:%FILENAME%: \.(\d|){1,2}pdf(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}doc(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}docx(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}xls(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}xlsx(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}jpeg(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}jpg(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}png(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}bmp(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}gif(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}sig(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}avi(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}mpeg(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}mpg(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}htm(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}txt(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}tif(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}ppt(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}wav(\d|){1,2}(\.sig|)(\.exe|\.scr)]
[REGEX:%FILENAME%: \.(\d|){1,2}mp3(\d|){1,2}(\.sig|)(\.exe|\.scr)] Und dieser hier verhindert Deinen AVG FAIL: Code:
//Prevent Java from executing processes
[%PARENTPROCESS%: *\javaw.exe] |