CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

System Safety Monitor . . .

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 171
Location: USA

PostPosted: Thu Jun 07, 2007 1:45 pm    Post subject: System Safety Monitor . . .
Reply with quote

I have some software on my system that seems to be one way to go for monitoring all system functions and operations.

SSM v2.0.8.583, anyone have any info on this software? I am a full blooded "DUMMY" and have been very lucky in finding software that is NOT a threat. Installing it and making many attempts to learn how to use it. This one uses many 'hooks' and some that must be a little unorthodox to monitor your system giving warnings when some app is about to launch itself or another program. It has many features and one should know alot about their system or learn real quick so you can set it up to give you the maximum protection. It has a learning mode to assist in setting up some of your rules for allowed or blocked apps.

I have seen in other forums where some find it giving them trouble with some of the AV software. Working with SSM and your AV software Co. would be a better method of operation to inform them of problems and give them a chance to maybe illiminate the problem.

Thank you for reading my post and any reply would be greatly appreciated,


_________________
TIA, CU L8R, >'Lkkb'<Inspiron D531s Vista HE Pre SP1 AMD Athlon 64 Dual Core Processor O/S 32Bit 2.3G RAM 3.0Gb, IE v7.0, FFv3.0.3/w/PWM v1.7.2 & NoScript v1.8.4.1; CFP v3.5.54375.427/w CFP AV updated daily; AntiVir v8.2.xxx Up Dated daily.
Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Thu Jun 07, 2007 7:40 pm    Post subject:
Reply with quote

I've heard of SSM before. Found it here: http://www.snapfiles.com/get/systemsafetymonitor.html

It's trialware.

One user's opinion on it (someone I knew in the past--and yes, he knows his stuff):

bellgamin wrote:
System Safety Monitor (SSM) belongs to a class of security programs known as "HIPS" (Host-based Intrusion Security Prevention). SSM is arguably THE very best HIPS for use on personal computer or home office. SSM needs no signature updates, and is effective against zero-day attacks, viruses, rootkits and other trojans, worms, etc. SSM will also protect any or all of your processes against being shutdown or counterfeited by malware. The only caveat in using SSM is that you, the user, must answer pop-ups whenever SSM encounters any process that is unknown to it, or is attempting an action which SSM considers is potentially hostile, and/or you have set a rule that requires SSM to ask your permission before running that particular process. In other words, SSM is a superb TOOL for protecting your computer, but it most assuredly is not your nanny. SIDE NOTE- If you happen to PREFER a "nanny-type" HIPS, try PREVX1 and set it to "abc" mode.


Prevx has a forum at CC: CastleCops Link/f146-Prevx.html

More info on Host-Based Intrusion Prevention


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 171
Location: USA

PostPosted: Thu Jun 07, 2007 8:56 pm    Post subject: SSM . . .
Reply with quote

Princely informer,

Thank you for this reply, from what I have seen about the latest FREE version that works on Win98SE is good. Your friend is giving the same impression from that quote.

Their website is syssafety.com , with the usual leading characters. The have it for all of the new software for Windows. v2.0.8.583 is the last one that works on Win98.

BellGamin, is a very reliable source of information. From what I have seen on him is WildersSecurity forums is where he posts, mostly.

Thank you for reading my posts and this rapid response,


_________________
TIA, CU L8R, >'Lkkb'<Inspiron D531s Vista HE Pre SP1 AMD Athlon 64 Dual Core Processor O/S 32Bit 2.3G RAM 3.0Gb, IE v7.0, FFv3.0.3/w/PWM v1.7.2 & NoScript v1.8.4.1; CFP v3.5.54375.427/w CFP AV updated daily; AntiVir v8.2.xxx Up Dated daily.
Back to top
View users profile Send private message
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5394

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Fri Jun 08, 2007 5:55 pm    Post subject:
Reply with quote

Just to add a few more links to those already provided by Larry:

Here is a general and excellent article on HIPS Comparision by ErikAlbert in the CC wiki
http://wiki.castlecops.com/HIPS/IDP_programs/services

EA's article on SSM with links to relevant studies:
http://wiki.castlecops.com/System_Safety_Monitor

Though this is a little dated - testing of SSM and thirteen other HIP programs,was conducted here by kareldjag in his Host intrusion and Prevention System Test study
http://kareldjag.over-blog.com/8-categorie-69553.html

SSM release notes:
http://www.syssafety.com/releasenotes.html?pid=104


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 171
Location: USA

PostPosted: Sat Jun 09, 2007 1:15 am    Post subject: Re: SSM . . . WOW! !
Reply with quote

Princely & Negs22,

This is one of my favorite features of this forum, probably the BEST, only item that could be BETTER is the people here that provide unlimited info and HELP!

Thank you BOTH for these links and this assistance in finding information on that subject. What you have provided is what is really needed for people to see how different programs, under a given subject, perform not necessarily a direct comparison, which is better or not providing enough protection. Just some information to munch on and see if it is digestible for my needs. Maybe this will give some of our members that are not as proficient on these systems, like myself, a place to see and maybe even learn more about these different types of protection and maybe we can get these creators to work with some of the AV software companies to make them more compatible or they will work together BETTER.


_________________
TIA, CU L8R, >'Lkkb'<Inspiron D531s Vista HE Pre SP1 AMD Athlon 64 Dual Core Processor O/S 32Bit 2.3G RAM 3.0Gb, IE v7.0, FFv3.0.3/w/PWM v1.7.2 & NoScript v1.8.4.1; CFP v3.5.54375.427/w CFP AV updated daily; AntiVir v8.2.xxx Up Dated daily.
Back to top
View users profile Send private message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 171
Location: USA

PostPosted: Sat Jun 09, 2007 1:48 am    Post subject: RE: SSM . . . WOW ! again . .
Reply with quote

negster22 wrote:
Just to add a few more links to those already provided by Larry:

Here is a general and excellent article on HIPS Comparision by ErikAlbert in the CC wiki
http://wiki.castlecops.com/HIPS/IDP_programs/services

EA's article on SSM with links to relevant studies:
http://wiki.castlecops.com/System_Safety_Monitor

Though this is a little dated - testing of SSM and thirteen other HIP programs,was conducted here by kareldjag in his Host intrusion and Prevention System Test study
http://kareldjag.over-blog.com/8-categorie-69553.html

SSM release notes:
http://www.syssafety.com/releasenotes.html?pid=104


Negs22,

After taking some time to look over some of these informational links provided I find one point that should have been included maybe as first read, http://kareldjag.over-blog.com/10-categorie-69553.html , where some disclaimer information is provided but most of all a description of TEST methodology and how they are done. Very extensive and I would think pretty much a full disclosure of procedures and equipment used. To give you as much info on the tested software for comparison to your own, I like this link.


_________________
TIA, CU L8R, >'Lkkb'<Inspiron D531s Vista HE Pre SP1 AMD Athlon 64 Dual Core Processor O/S 32Bit 2.3G RAM 3.0Gb, IE v7.0, FFv3.0.3/w/PWM v1.7.2 & NoScript v1.8.4.1; CFP v3.5.54375.427/w CFP AV updated daily; AntiVir v8.2.xxx Up Dated daily.
Back to top
View users profile Send private message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 171
Location: USA

PostPosted: Sat Jun 09, 2007 4:32 pm    Post subject: RE: SSM . . . WOW ! again . More . .
Reply with quote

Negs22,

This one would also be a good one to include:

http://kareldjag.over-blog.com/2-categorie-69553.html

it is a comparison of (Quote from that test page) "ProcessGuard (PG) VS System Safety Monitor (SSM) VS Viguard" to give a better evaluation for one's needs and your decision should be based on your requirements.

Seems there are more evaulation comparisons in this link than the other thirteen that are available. Of course the other links are not for comparison but individual evaluation and testing information. There were many points of interest for each one. You should read all of them and make one's own decision from all of the data available by this one person with some assistance from friends. Very extensive and much hard work went into this.

I am not in any way a Professional in or on any thingy, this is just my evaluation of a very indepth evaluation of some added protection for our home computers. For anyone that is using their computer for a business will have different needs and requirements and should consult a Professional.


_________________
TIA, CU L8R, >'Lkkb'<Inspiron D531s Vista HE Pre SP1 AMD Athlon 64 Dual Core Processor O/S 32Bit 2.3G RAM 3.0Gb, IE v7.0, FFv3.0.3/w/PWM v1.7.2 & NoScript v1.8.4.1; CFP v3.5.54375.427/w CFP AV updated daily; AntiVir v8.2.xxx Up Dated daily.
Back to top
View users profile Send private message
ErikAlbert
Warnings : 3

Captain
Captain


Joined: Jan 20, 2005
Posts: 424


PostPosted: Tue Jun 12, 2007 5:14 am    Post subject:
Reply with quote

I'm sure Negster has read everything you mentioned Ikkeb.

Kareldjag's blog is full of information but very hard to navigate. There are still many more interesting urls on the same site that you have not mentioned.

A dedicated student should go to that site, and work backwards by time to look at the entries.

Back to top
View users profile Send private message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 171
Location: USA

PostPosted: Wed Jun 13, 2007 8:55 pm    Post subject:
Reply with quote

ErikAlbert wrote:
I'm sure Negster has read everything you mentioned Ikkeb.

Kareldjag's blog is full of information but very hard to navigate. There are still many more interesting urls on the same site that you have not mentioned.

A dedicated student should go to that site, and work backwards by time to look at the entries.


EA,

Thank you for this message, I am also very sure Negs22 is aware of all that I had posted. Did that so if any other is reading this they will also know of the other items that they may miss if they are not curious enough to move around on that blog. Yes, I am very sure there are many other items or tid-bits of info there, just have to have the need and time to roam around.

Have had other problems that I needed to chase down and am still chasing them. Will get back ASAP, after my chase has come to a successful conclusion, I hope any way.

Thank you for reading my posts and giving a reply. This is just one of the reasons I like CC for HELP, everyone gives an input that I find very helpful.


_________________
TIA, CU L8R, >'Lkkb'<Inspiron D531s Vista HE Pre SP1 AMD Athlon 64 Dual Core Processor O/S 32Bit 2.3G RAM 3.0Gb, IE v7.0, FFv3.0.3/w/PWM v1.7.2 & NoScript v1.8.4.1; CFP v3.5.54375.427/w CFP AV updated daily; AntiVir v8.2.xxx Up Dated daily.
Back to top
View users profile Send private message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 171
Location: USA

PostPosted: Fri Aug 31, 2007 6:38 pm    Post subject:
Reply with quote

Neg22, Princely informer, ErikAlbert, any other Poster,

I have been OFF the web for about the last 2.5 months because my system begin to act very strangely, kept getting slower and slower. To make a very long story shorter, thanks to my GeekAzoid Nephew I am now on a different Computer running XP Home. Still have my Win98SE2ME system just have not been able to do much with it, yet. Still behind the curve learning how to work in XP, abit different but getting there.

Do NOT use SSM any longer, I think that is where my problems came from and DONOT plan on installing it on this one. Testing and experimenting operations are now OVER and not used any more.

Thank you one and ALL that have suggested or recommended thingys to try. I also feel my main problem was NOT having SSM set properly, due to my paranoia may have it set too restrictive and not sure of what exactly was set too tight. Game over, not planning on going there any.


_________________
TIA, CU L8R, >'Lkkb'<Inspiron D531s Vista HE Pre SP1 AMD Athlon 64 Dual Core Processor O/S 32Bit 2.3G RAM 3.0Gb, IE v7.0, FFv3.0.3/w/PWM v1.7.2 & NoScript v1.8.4.1; CFP v3.5.54375.427/w CFP AV updated daily; AntiVir v8.2.xxx Up Dated daily.
Back to top
View users profile Send private message
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 171
Location: USA

PostPosted: Fri Aug 31, 2007 6:42 pm    Post subject:
Reply with quote

Admins,

Do not know why there are three copies of my post. While the first attempt was underway I went in and downloaded some e-mail and sent out some. Came back and it was still attempting to send my message. Then suddenly it completed and when viewing my post there are three copies. Please remove the redundant copies.

EDited by LKKKB : I was away sending email for about 15 minutes, only thingy I did do was originally clicked on PreView and then Submit only once.

Thank you


_________________
TIA, CU L8R, >'Lkkb'<Inspiron D531s Vista HE Pre SP1 AMD Athlon 64 Dual Core Processor O/S 32Bit 2.3G RAM 3.0Gb, IE v7.0, FFv3.0.3/w/PWM v1.7.2 & NoScript v1.8.4.1; CFP v3.5.54375.427/w CFP AV updated daily; AntiVir v8.2.xxx Up Dated daily.
Back to top
View users profile Send private message
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5394

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Sat Sep 01, 2007 4:34 am    Post subject:
Reply with quote

Congrats on your new XP system and may it live a long life. Smile

I removed the duplicate messages.

Welcome back!


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
lkkb

Lieutenant
Lieutenant


Joined: Aug 10, 2005
Posts: 171
Location: USA

PostPosted: Sun Sep 02, 2007 9:42 pm    Post subject:
Reply with quote

NegTwoTwo,

Thank you, time will tell the tail/tale, whatever, as to what will happen with this system. My main objective it to learn how to use it to the best and that will need to be done when my Nephew returns. Am still learning what all software is installed.

It is good to be back,


_________________
TIA, CU L8R, >'Lkkb'<Inspiron D531s Vista HE Pre SP1 AMD Athlon 64 Dual Core Processor O/S 32Bit 2.3G RAM 3.0Gb, IE v7.0, FFv3.0.3/w/PWM v1.7.2 & NoScript v1.8.4.1; CFP v3.5.54375.427/w CFP AV updated daily; AntiVir v8.2.xxx Up Dated daily.
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer