Hello
Will Mbam auto detect malware in pen drives?
Fyi:
I am having USB Virus Scan installed, with real time protection enabled, in my system.
I have disabled autoplay & OS is XP SP3.
#1
Posted 06 September 2009 - 10:21 AM
#2
Posted 06 September 2009 - 12:29 PM
I like Autorun Eater that is similar to USB Virus Scan I believe:
http://download.cnet.com/Autorun-Eater/300...4-10752777.html
I have not disabled autoplay but I do not let things auto-run from Flash drives.
Welcome to Honorary Members
http://download.cnet.com/Autorun-Eater/300...4-10752777.html
I have not disabled autoplay but I do not let things auto-run from Flash drives.
Welcome to Honorary Members
E5200 2.5GHZ, 4GB RAM, 320GB HD, Win7 Home Premium 64-bit, avast! V6.0 Free, IE9
P4 2.8GHZ, 1.5GB RAM, 40GB HD, XP Pro SP3, 32-bit, avast! V6.0 Pro, Macrium Reflect
with IE8 and Chrome, hpHosts, MVPS HOSTS files, MBAM Full, OpenDNS, SpeedFan, WinPatrol PLUS
P4 2.8GHZ, 1.5GB RAM, 40GB HD, XP Pro SP3, 32-bit, avast! V6.0 Pro, Macrium Reflect
with IE8 and Chrome, hpHosts, MVPS HOSTS files, MBAM Full, OpenDNS, SpeedFan, WinPatrol PLUS
#3
Posted 06 September 2009 - 02:22 PM
YoKenny1
Thanks for your response, but I want to know whether Mbam will auto detect malware in pen drives?
Thanks for your response, but I want to know whether Mbam will auto detect malware in pen drives?
#4
Posted 06 September 2009 - 02:36 PM
Select Perform full scan then un-select the main hard drive(s) then select the Flash drive.
E5200 2.5GHZ, 4GB RAM, 320GB HD, Win7 Home Premium 64-bit, avast! V6.0 Free, IE9
P4 2.8GHZ, 1.5GB RAM, 40GB HD, XP Pro SP3, 32-bit, avast! V6.0 Pro, Macrium Reflect
with IE8 and Chrome, hpHosts, MVPS HOSTS files, MBAM Full, OpenDNS, SpeedFan, WinPatrol PLUS
P4 2.8GHZ, 1.5GB RAM, 40GB HD, XP Pro SP3, 32-bit, avast! V6.0 Pro, Macrium Reflect
with IE8 and Chrome, hpHosts, MVPS HOSTS files, MBAM Full, OpenDNS, SpeedFan, WinPatrol PLUS
#5
Posted 06 September 2009 - 03:30 PM
YoKenny,
I think srtools wants to know if it will detect any malicious activity on the thumb drive automatically when plugged in or run from the drive. I'd say if it was run from the thumb drive and MBAM has the definitions for whatever nasty it is, it will detect it. Paid version with realtime protection of course.
I think srtools wants to know if it will detect any malicious activity on the thumb drive automatically when plugged in or run from the drive. I'd say if it was run from the thumb drive and MBAM has the definitions for whatever nasty it is, it will detect it. Paid version with realtime protection of course.
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#6
Posted 06 September 2009 - 04:20 PM
swagger
Your reply has cleared my doubt, but not fully. (fyi - mine's is paid version, with realtime protection checked).
I got this doubt because when I plug pendrives mbam is silent.
There is no indication whether it is scanning the drive or not.
I guess it will notify only if the drive is infected.
Am I right?
Can mbam staff answer me?
Fyi : USB Virus Scan immediately starts scanning & gives the report.
Your reply has cleared my doubt, but not fully. (fyi - mine's is paid version, with realtime protection checked).
I got this doubt because when I plug pendrives mbam is silent.
There is no indication whether it is scanning the drive or not.
I guess it will notify only if the drive is infected.
Am I right?
Can mbam staff answer me?
Fyi : USB Virus Scan immediately starts scanning & gives the report.
#7
Posted 06 September 2009 - 04:38 PM
I don't believe MBAM is going to scan automatically unless you actually execute something from the USB drive OR something executes itself. I hope that clears it up.
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#8
Posted 06 September 2009 - 04:48 PM
Yes I am clear now.
#9
Posted 07 September 2009 - 04:52 AM
Yes, MBAM leaves any sort of automatic scanning, aside from the scans you schedule using the Task Scheduler, to your anti-virus. The protection module only looks at processes in memory, not accessed files. This is to avoid system slowdowns as well as potential conflicts with antivirus software.
#10
Posted 07 September 2009 - 02:19 PM
exile360, on Sep 7 2009, 12:52 AM, said:
The protection module only looks at processes in memory, not accessed files.
Aren't they one in the same? Processes in memory and accessed files are both running, correct? I understand you're logic in that MBAM leaves the scanning up to the A/V when you plug a drive in for instance. But when that a file from that drive is executed, that file is therefore scanned. Please correct me if I am wrong so that I know for my own sake and that I don't tell others the wrong information.
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#11
Posted 07 September 2009 - 02:45 PM
Now I am confused.
Please somebody clearly tell me will Mbam auto detect malware in pen drives?
Please somebody clearly tell me will Mbam auto detect malware in pen drives?
#12
Posted 07 September 2009 - 04:21 PM
swagger, on Sep 7 2009, 09:19 AM, said:
Aren't they one in the same? Processes in memory and accessed files are both running, correct? I understand you're logic in that MBAM leaves the scanning up to the A/V when you plug a drive in for instance. But when that a file from that drive is executed, that file is therefore scanned. Please correct me if I am wrong so that I know for my own sake and that I don't tell others the wrong information.
The one exception is if you're using an av that has a built in execution emulator, meaning it executes files in a sandbox to determine an executable's behavior as part of a heuristic analyzation (Kaspersky does this, and I've seen MBAM catch inactive malware while being scanned by Kaspersky, but not when scanned by other tools as they don't have the emulation feature).
edit: So to clearly answer your question, no, MBAM will not automatically detect malware in pen drives, autochecking newly attached storage and files as they are accessed by anything (including explorer.exe) is the job of your antivirus, and MBAM is not designed to work this way, again, to avoid conflicts with your av as it would cause a serious performance hit to have 2 security programs checking each file and newly attached storage medium at once.
#13
Posted 07 September 2009 - 04:25 PM
@exile,
Understood. I was thinking of "accessed" as opened and not as "scanned" by A/V or any other security tool. That makes sense to me. So in an effort to make this clear for srtools, MBAM will only catch malicious activity if the file is actually run from the drive or automatically runs (ex. from the autorun.inf file). Correct?
Understood. I was thinking of "accessed" as opened and not as "scanned" by A/V or any other security tool. That makes sense to me. So in an effort to make this clear for srtools, MBAM will only catch malicious activity if the file is actually run from the drive or automatically runs (ex. from the autorun.inf file). Correct?
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#14
Posted 07 September 2009 - 04:28 PM
Exactly, and only then if the malicious exe on the pen drive is successfully executed. If you don't use autoplay to run what the autorun.inf file points to, it will not be automatically detected by MBAM because it is not running in memory, but if the malicious process does run, then MBAM will detect it as long as it's in MBAM's definitions
.
#15
Posted 07 September 2009 - 04:31 PM
Exactly what I thought, thanks for the clarification. 
srtools, is this presented clearly now?
srtools, is this presented clearly now?
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#16
Posted 07 September 2009 - 05:06 PM
I watched The debate from Post #12 to 15.
I am very clear now.
Thanks for your efforts swagger & exile360.
I am very clear now.
Thanks for your efforts swagger & exile360.
#17
Posted 07 September 2009 - 05:09 PM
No problem at all
Definitely not a debate though, just good ol fashioned intellectual conversation. I'm happy with the end result.
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#18
Posted 07 September 2009 - 05:15 PM
Me too, a good discussion to really root out the details never hurts, this way everyone who reads it can learn something
.
#19
Posted 07 September 2009 - 05:25 PM
Yes this topic is truly educative.
In future posts if anyone raises the same doubt/question, here is the answer.
In future posts if anyone raises the same doubt/question, here is the answer.
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account

Back to top










