Текущее время: 28 апр 2024 03:44

Часовой пояс: UTC + 3 часа




Начать новую тему Ответить на тему  [ Сообщений: 4 ] 
Автор Сообщение
 Заголовок сообщения: system guard questions
СообщениеДобавлено: 29 авг 2011 03:01 
Не в сети

Зарегистрирован:
29 авг 2011 02:55
Сообщения: 2
Hello,

I have a question about the sytem guard options. The system guard found a file, and gave a pop up. In that pop up there were 3 options(if i remember right) one was cure, the 2nd was allow access, the 3rd was deny access. I didnt see a quarrantine option so I used cure, thinking it would move the file in question, It didnt, it just deleted it.

So My question is, how does one move the file to quarrantine when the system guard finds it? I read the help files and didnt really find my answer.

perhaps a move to quarrantine option would be less confusing.

Saty


Вернуться к началу
 Профиль  
 
 Заголовок сообщения: Re: system guard questions
СообщениеДобавлено: 30 авг 2011 14:26 
NanoAV Team
Не в сети

Зарегистрирован:
03 апр 2009 18:43
Сообщения: 488
Откуда:
Брянск
Hallo, Saty.
In current version when the system guard find a file, the pop up will not contain a quarrantine option if the file has a special cure in our base. And the cure can be just a deleting if the file is a type of trojan.
This scheme of work was assumed purposely. But you can show preference to another type of working. We`ll treat your suggestions.


Вернуться к началу
 Профиль  
 
 Заголовок сообщения: Re: system guard questions
СообщениеДобавлено: 31 авг 2011 01:33 
Не в сети

Зарегистрирован:
29 авг 2011 02:55
Сообщения: 2
Hello ya,

Thank you for your response. Im a little confused, that automatic delete would be used as a cure. What if its a false postive? If the file is gone it could cause numerous problems. I was taught to never delete as the first option, as there are no other options left. Its best to quarrantine and check the file to make sure i.e. virustotal etc etc. The file in question could be left in quarrantine indefinitly for that matter.

In my case it very may well be a false postive, I dont have the file (because it was automatically deleted) but its listed in the system guard log. In my quick lookup online it might have been a file that is used in windows updates. Ill know more if windows cant update.

Im going to change default system guard settings to quarrantine(I think i seen a way to do that) to be on the safe side in the future. (If not ill be ending my beta testing of this program)

I understand this is a beta program, and so far Im liking it, but if this wasnt a beta, and automatic delete if the file couldnt be cured was the default setting, I wouldnt trust the program and would uninstall it and move to something else.

thank you for your time

Saty


Вернуться к началу
 Профиль  
 
 Заголовок сообщения: Re: system guard questions
СообщениеДобавлено: 31 авг 2011 12:55 
NanoAV Team
Не в сети

Зарегистрирован:
03 апр 2009 18:43
Сообщения: 488
Откуда:
Брянск
Saty, your situation can`t be solved by moving the file to quarrantine because of the following things.

If you move the file to quarrantine it will be deleted from original directory. In this case if the file is a system file, the system can be crushed. Also you can send quarrantine files only to our laboratory, not to virustotal, etc.
Even if you have a quarrantine option the most correct chose in your situation is to deny access to file. In this case you save the file in original directory. If it`s realy harmful, you stop it`s work. Also you can send it not only to our laboratory but to virustotal, etc.

If the file is a trojan (not a virus) it will be deleted. Also the keys in registry which refer to the file will be deleted. And this operations are NOT automatic because of the file couldnt be cured. It IS the cure.

Surely we`ll discuss possibility of quarrantine option presence in system guard pop ups.


Вернуться к началу
 Профиль  
 
Показать сообщения за:  Поле сортировки  
Начать новую тему Ответить на тему  [ Сообщений: 4 ] 

Часовой пояс: UTC + 3 часа


Кто сейчас на конференции

Сейчас этот форум просматривают: нет зарегистрированных пользователей и гости: 1


Вы не можете начинать темы
Вы не можете отвечать на сообщения
Вы не можете редактировать свои сообщения
Вы не можете удалять свои сообщения
Вы не можете добавлять вложения

Найти:
Перейти:  
POWERED_BY
Русская поддержка phpBB