Computer ForumsComputers  

Go Back   Computer Forums > PC Technology Zone > Windows Operating Systems and Software > Tips, Tricks & Tutorials

Reply
 
LinkBack Thread Tools Display Modes
Old 11-26-2007, 08:23 AM   #1 (permalink)
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 25,457
Default Prevent that unknown executables are started in Windows

Windows does not offer a way to prevent users from accessing executable files. While NTFS does offer a rights-system it is only valid of NTFS hard drives and does not come into effect if a user plugs in a USB drive, CD or floppy disk. Most computers get infected nowadays by executing email attachments followed by file downloads and Windows security holes.
Trust No Exe is a Windows security software that prevents any unknown executable from being started in Windows. It features a whitelist and blacklist and requires some time to fine tune the list so that no trusted programs get blocked from being started. The concept behind Trust No Exe is that it works as a content filter filtering all executable files even if they come with an unknown extension.
Trust-no-exe hooks into the operating systems routines for creating a process and loading it into memory. If the operating system attempts to load any compiled code into memory ready to give it execution as a process or thread, trust-no-exe will jump on it and prevent the code from being loaded into memory. Therefore trust-no-one doesn’t rely on the file extension and can not be easily fooled.
The Windows folder and the Program Files folder is added by default because these contain files that need to be accessible for Windows to start. The next steps require some time, you should add additional locations that contain executables that are trustworthy.
A good tip that I found in the Trust no Exe manual was to set read only rights for folders that do not require write rights to prevent malicious code from slipping in one of those trusted folders where it can be executed.
It does catch email attachments and supports networks and cloning settings as well. Strange that I never heard about this gem before.
__________________

www.MasterB365.com
www.Tech-Dump.com


"On 10-3-08 Obama Supporters Vandalized-Tresspassed and STOLE My Palin-McCain Sign Violating My First Amendment Right To Free Speech. Do It Again And You Will Find Out What The 2nd Amendment Is All ABOUT!"
Osiris is online now   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Download Windows Vista Service Pack 1 Beta Osiris Windows Operating Systems and Software 0 10-14-2007 11:57 AM
Windows Vienna (Blackcomb) mssssee2 Windows Operating Systems and Software 16 09-23-2007 03:57 AM
My log Max Power HijackThis Logs (finished) 4 08-23-2007 08:55 AM
Can Windows prevent POST? bengance Hardware Troubleshooting 2 07-26-2007 10:20 PM
Objecterror HJT Log objecterror Virus - Spyware Protection / Detection 4 05-18-2007 12:19 PM


All times are GMT -5. The time now is 09:01 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0