Contact us - Horizon DataSys
Go Back   Horizon DataSys Community Forums > Horizon DataSys > Disaster Recovery Programs > RollBack Rx
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

MBR Protectors & RB Rx

This is a discussion on MBR Protectors & RB Rx within the RollBack Rx forums, part of the Disaster Recovery Programs category; Hi Graham Nice one. Think that your translations match up with what I have come across on the nProtect Offical ...

Reply
 
LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old 12-29-2011, 11:45 AM
Senior Member
 
Join Date: Feb 2009
Location: South Wales, UK
Posts: 189
Default

Hi Graham

Nice one. Think that your translations match up with what I have come across on the nProtect Offical Blog Site (as it is called ):

INCA Internet's Emergency Response Team's official blog.: Get our nProtect MBR Guard for free.

where they say:

"[MBR 보호][MBR Protection] is set by default and will protect from malicious access.
[자동시작][Auto Start] function is also set by default and will run on booting automatically.
When [MBR 보호][MBR Protection] is activated, our "nProtect MBR Guard" will protect all of attempts accessing MBR sector."

Might well give it a whirl over the weekend (following taking of full image/back up of MBR, etc.)...but I suppose that unless one has & runs an app that one knows will modify the MBR (which it should prevent), there is no way of testing it's operastion without throwing some malware at it (not advised of course without the propoer precautions).

Regards




Balders
Reply With Quote
  #12 (permalink)  
Old 12-29-2011, 11:53 AM
Senior Member
 
Join Date: Feb 2009
Posts: 367
Default

I'm impressed at my grasp of Korean .

I do know of some software which modifies the MBR and which we hope is not malware . So, I guess a good test is to run MBRGuard on a non-RB system and try and install RB which will fail if it is doing its job!

Graham
Reply With Quote
  #13 (permalink)  
Old 12-29-2011, 12:02 PM
Senior Member
 
Join Date: Feb 2009
Location: South Wales, UK
Posts: 189
Default

Others that I can think of are Truecrypt & ATI Home for starters, which should fail to install if MBRGuard is doing its job but if one wants to install legitimately then one would need to disable MBRGuard to allow that to happen...or the same in the cas eof wantingto uninstall them.

Balders
Reply With Quote
  #14 (permalink)  
Old 12-29-2011, 12:18 PM
Senior Member
 
Join Date: Feb 2009
Posts: 367
Default

Well, I've just tried it with RB which didn't seem to quite know what to do with it. It hung on the copying files screen for a while before the machine locked up solid .

However, after a forced power off, there was no evidence of RB having installed in the MBR. So I guess that's a definite plus for MBRGuard .

Graham
Reply With Quote
  #15 (permalink)  
Old 12-30-2011, 11:04 AM
Junior Member
 
Join Date: Dec 2011
Posts: 13
Default

I can tell you that AppGuard is not compatible on my Vista Business. The program was running but I encoutered a trouble with the shutdown process. I had to force manually the OFF button to shutdown my computer.

Another thing, is that TDS Killer detected on my computer 66 suspiscious files. Most of them are system files with a bad MD5 hash files. I can consider these suspicious files as false alerts. RB Rx probably modify the hash files to protect those system files.

Last edited by ramaflore; 12-30-2011 at 11:09 AM.
Reply With Quote
  #16 (permalink)  
Old 01-12-2012, 03:37 PM
Junior Member
 
Join Date: Jul 2010
Posts: 18
Default

Here's some FREEWARE stuff to copy/restore/backup MBR ..

As mentioned earlier, MBRWizard Command Line

and here's 3rd party MbrWhisky which is Graphical User Interface for the MbrWizard command line tools.

Then we have DIY DataRecovery MBRtool which includes boot diskette builder that will assist you in creating a diskette or bootable CD/DVD.

HDHacker is a stand-alone micro-utility that saves, visualizes, and restores the MBR (from a physical drive), the BootSector (from a logical drive) or any specified sector from any disk (even removable disks).

MbrFix - Perform several Master Boot Record (MBR) tasks, like backing up, restoring, fixing the boot code in the MBR, etc. The utility should not be used for GUID Partition Table (GPT) disks. The utility now, by popular demand, also come in a x64-version running unde x64-editions of Windows and PE.

Finally,Here's a very detailed information page by The Starman, with some download links also to freeware utilies,which some of them I already mentioned in this post.Certainly worth the reading.

Hope this helps..
Reply With Quote
  #17 (permalink)  
Old 01-12-2012, 04:45 PM
Junior Member
 
Join Date: Jul 2010
Posts: 18
Default

Quote:
Originally Posted by Baldrick View Post
Hi Graham

Nice one. Think that your translations match up with what I have come across on the nProtect Offical Blog Site (as it is called ):

INCA Internet's Emergency Response Team's official blog.: Get our nProtect MBR Guard for free.

where they say:

"[MBR 보호][MBR Protection] is set by default and will protect from malicious access.
[자동시작][Auto Start] function is also set by default and will run on booting automatically.
When [MBR 보호][MBR Protection] is activated, our "nProtect MBR Guard" will protect all of attempts accessing MBR sector."

Might well give it a whirl over the weekend (following taking of full image/back up of MBR, etc.)...but I suppose that unless one has & runs an app that one knows will modify the MBR (which it should prevent), there is no way of testing it's operastion without throwing some malware at it (not advised of course without the propoer precautions).

Regards




Balders

Since it's a freeware program,and does not come with any EULA to accept on, I decided to modify the system tray menu text into ENGLISH..

You can download it at:

English_file.zip - 228.2 Kb
Click here to visit the download site! (Oron.com)

unzip the package,and replace the modified exe with the original file in the installation directory!

Virustotal.com report: https://www.virustotal.com/file/59c7...is/1334491935/

IT GIVES THE SAME FALSE-POSITIVE ALERT ON THE ORIGINAL EXE ASWELL,TRY IT YOURSELF!


Sorry to MODS/STAFF if this is against the rules to post this in here.
Delete it and warn me. :O

Last edited by Harakka; 04-15-2012 at 04:14 AM.
Reply With Quote
  #18 (permalink)  
Old 01-12-2012, 07:10 PM
Senior Member
 
Join Date: Feb 2009
Posts: 367
Default

Quote:
Originally Posted by Harakka View Post
Since it's a freeware program,and does not come with any EULA to accept on, I decided to modify the system tray menu text into ENGLISH..
Thanks for sharing that, Harakka. I don't feel as daring now using the english version but at least I can read it .

I've been using it on two pc's for the past two weeks without any issues at all but I guess it is how it deals with an attack on the mbr which is most important!

Graham
Reply With Quote
  #19 (permalink)  
Old 04-15-2012, 04:19 AM
Junior Member
 
Join Date: Jul 2010
Posts: 18
Default

Re-modified the translations, and also updated the download link+virustotal report link,since the old download link was dead.
Look at my post above.
It's a bit odd the authors do not want to translate it into english, eventho
it is requested by users on their page..


Edit: Would be nice if the coming new version of Rollback RX would have somekinda self-protection possibility turned on/off, to protect the Rollback RX
pre-windows loader being over-written by some malicious virus, so this kinda 3rd party software would not be needed..

Last edited by Harakka; 04-15-2012 at 04:23 AM.
Reply With Quote
  #20 (permalink)  
Old 04-15-2012, 02:38 PM
Senior Member
 
Join Date: Feb 2009
Posts: 367
Default

Quote:
Originally Posted by Harakka View Post
Re-modified the translations, and also updated the download link+virustotal report link,since the old download link was dead.
Look at my post above.
It's a bit odd the authors do not want to translate it into english, eventho
it is requested by users on their page..
Thanks for the update on this, Harakka. It has been duly downloaded and installed .

I've been using it for nearly 4 months now with no problems at all and I still tend to forget it is running until I go to uninstall RollBack and find it can't update the MBR!

It does seem a bit odd not to do an english version as I guess it would give it a much wider user base and so potentially bring them more custom. Especially odd as the nProtect site and blog are all in english.

Quote:
Originally Posted by Harakka View Post
Edit: Would be nice if the coming new version of Rollback RX would have somekinda self-protection possibility turned on/off, to protect the Rollback RX
pre-windows loader being over-written by some malicious virus, so this kinda 3rd party software would not be needed..
Yes, it would be good if RB had this sort of self-protecting technology built-in and I would think it should be well within the developer's capabilities to implement it. But, while we wait for that to happen, I shall carry on with MBR Guard .

Thanks again.

Graham
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -8. The time now is 02:52 AM.


Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Site content Copyright (C) 2009 by Horizon DataSys