2nd layer protection for USB drives: MCShield

Hello.
The problem is related to DPI settings on the PC (“size of text and other items”).
We’re looking into the possibilities… It’s not really the simplest one to fix.

Just tell me this: did you guys change the settings yourself or was it done by Windows?

Looking at my Display setting, I see it’s set for Medium: 125% (which I believe equates to 120 DPI). It’s been so long, but I’d have to say I opted for that myself… my eyes are getting worse, so it’s easier to see things when enlarged.

My video driver updated itself automatically about two months ago… I was not happy when it did so without checking with me first… I would NOT have permitted it, had I been asked.

I also accidentally adjusted my Display/Color settings about a month ago… and couldn’t figure out how to get back the previous settings… and have settled on an acceptable variation.

I didn’t change any settings that I’m aware of? ???

MCShield v3.0.4.27

v 3.0.4.27: 2nd February 2014.
  • fixed an issue that caused the scanner to crash on certain locked files;
  • updated Vietnamese language.

http://www.mcshield.net/

If MCshield detect any malware and quarantine it, avast detect that quarantine file and delite it.
As encryption havent add to program is there any other way to avoit this “conflict”?

Hi juuki,

Just to clarify. Any malware with intent to be transmitted via removable drives. :slight_smile:

Encryption is added to MCS’s Quarantine. Are you sure you have the latest version installed?

Avast shouldn’t touch MCS’s Quarantine. If “Quarantine” conflict does exists (there is always a possibility for avast to detects malicious files in MCS’s Quarantine based on his heuristics check), little can be done I think except to clear the MCS Quarantine folder as I do not see that as a problem. :slight_smile:

I have last version (as you can see in attachment, left is last downloaded version from theit website and right is my installed version).
Encryption is not added to MCS. Have no idea where you get that information.

Avast scan all changes made so when MCS send file to quarantine Avast also scan that quarantine folder.

In my case i insert USB. MCS detected 4 malware, i delite 3 and 1 is ingored.

Here is log:

MCShield ::Anti-Malware Tool:: http://www.mcshield.net/

>>> v 3.0.4.27 / DB: 2014.3.10.1 / Windows 7 <<<


12.3.2014. 17:05:17 > Drive F: - scan started (no label ~1960 MB, FAT flash drive )...


>>> F:\AVTORUN\Desktop.ini > ignored (user request). (MD5: f05d6580608901fa2aea2a1e711a8ff4)

> F:\AVTORUN
> F:\AVTORUN\Desktop.ini (MD5: f05d6580608901fa2aea2a1e711a8ff4)
> F:\AVTORUN\slovenec.exe (MD5: eb722f24b9affb0ecaf41cff09d0b241)

>>> F:\AVTORUN - Malware (folder) > Deleted. (14.03.12. 17.07 AVTORUN.45284)

> F:\ZNOJE
> F:\ZNOJE\Desktop.ini (MD5: f05d6580608901fa2aea2a1e711a8ff4)
> F:\ZNOJE\misejaja.exe (MD5: d6f30cf036932f1511c6a66e886a3868)

>>> F:\ZNOJE - Malware (folder) > Deleted. (14.03.12. 17.07 ZNOJE.314628)

> F:\NATASA
> F:\NATASA\Desktop.ini (MD5: f05d6580608901fa2aea2a1e711a8ff4)
> F:\NATASA\pazhin.exe (MD5: d5a130c139ebb1b133916823a065f3b5)

>>> F:\NATASA - Malware (folder) > Deleted. (14.03.12. 17.07 NATASA.118917)

>>> F:\xfl3hx.exe - Suspicious > Renamed. (MD5: 8b1fad2127a9920b4cf2cd6ff9306ce5)


=> Malicious files   : 6/6 deleted.
=> Malicious folders : 3/3 deleted.
=> Suspicious files  : 1/1 renamed.

____________________________________________

::::: Scan duration: 2min 15sec ::::::::::::
____________________________________________

after that Avast automaticly scan MCS quarantine, detect and delite that three malware.

Here is Avast FileSystemShield log:

* avast! Real-time Shield Scan Report
* This file is generated automatically
*
* Started on: Wednesday, March 12, 2014 4:20:49 PM
*

12.3.2014. 17:07:22	C:\ProgramData\MCShield\Quarantine\14.03.12. 17.07 AVTORUN.45284\slovenec.exe|>[UPX] [L] Win32:MalOb-IJ [Cryp] (0)
File was successfully moved to chest...
12.3.2014. 17:07:28	C:\ProgramData\MCShield\Quarantine\14.03.12. 17.07 ZNOJE.314628\misejaja.exe [L] Win32:Evo-gen [Susp] (0)
File was successfully moved to chest...
12.3.2014. 17:07:29	C:\ProgramData\MCShield\Quarantine\14.03.12. 17.07 NATASA.118917\pazhin.exe|>[UPX] [L] Win32:MalOb-AI [Cryp] (0)
File was successfully moved to chest...

Hi juuki,

Encryption is not added to MCS. Have no idea where you get that information.
Juuki believe me, I know. ;D Encription is added to MCShield Quarantine since version 2 (2.2.3.15) in October 2012. public info: [url=http://www.mcshield.net/]official site[/url] > changelog
In my case i insert USB. MCS detected 4 malware, i delite 3 and 1 is ingored.
I understand.

By logs my guess are that MCS has attempt to set and pack the malicious files in his Quarantine but avast! has block that operation. avast! has the routine to scan all new detected USB devices. Conflict may arises when AV (in this case avast!) wants to be the first in scanning, thereby not allowing access to the disk. MCShield attempts to access to disk as well to preform scanning and glitch occurs.

I would recommend as solution to disable that routine to allow MCShield that part of job if you will. That should be the solution for your problem. Or . . set the MCS’s Quarantine folder %path% as an exception in avast!. Quarantine is located in programdata folder.

%ProgramData%\MCShield\Quarantine

Anyway, I will preform some additional testing and report to dr_Bora.

Or you can use our contact support form.
http://www.mcshield.net/contactus.html

Thank you for your feedback.

MCS detect and send malicious files in quarantine. After that Avast detect that “new” files in quarantine and delite it or send it to ist quarantine.
Avast dont block any MCS operation.

Also Avast dont scan new detected USB devices, thats why is needed this 2nd layer protection for USB devices. So there is no conflict between Avast and MCS.

As solution i add exclusion in Avast (File System Shield) MCS Quarantine folder:

C:\ProgramData\MCShield\Quarantine\

selected R and W not X so if any file from quarantine folder try to execute it will be scanned by Avast.

I try test myself with this settings but MCS cant detect EICAR test file so i have no idea how to test it, and will it work.

No problem, im always here to help :wink:

Not really true. avast! DOES scan any accessed file in the USB devices. Like MCS, it does not scan ALL the files in the USB drive.
I also use MCS as a 2nd layer.

Hi all,

Fresh MCShield has been released.

Changelog:

version 3.0.5.28: 12th April 2014.

[] fixed an issue related to folder selection when adding files to the whitelist;
[
] improved handling stability for write protected drives;
[] improved display of tray notifications on high DPI configurations;
[
] updated Brasilian Portuguese language.

Official homepage:
http://www.mcshield.net/

Cheers,

Thanks, already updated. :slight_smile:

+1 :slight_smile:

Thanks. Already updated.
Last month, I’ve installed McShield in 3 computers :slight_smile:

@ magna86,

When will MCShield be available for Mac PC’s? Thank you.

Hi SafeSurf, Hi all, :slight_smile:

Probably never unfortunately.

Other rules apply for MAC eco system which means that the program should be re-written from the start and re-test from the beginning.
The authors do not have so much free time plus it is for wonder too . . if it is worth it?

Thank you Magna86. You have a great program as I use it on my other Windows machine. I guess I’ll have to find something else for the Mac. :cry: Thank you again for your hard work.

I am still a bit confuse, hope you don’t mind answering some question of my. I am asking these question after I have read all 15 page of post.

1)From what I understand MCShield operate on a real time scan whereas avast is on demand when it is regarding a removable drive. So if you choose to scan the removable drive after inserting it will it be the same as MCShield?

  1. considering that autorun for windows have been change to autoplay for the user to decide what action to take does this mean that unless the user run the autorun program most threat would not be activated upon inserting?

  2. if the removable drive have thousand of file wouldn’t that means that it will take at least a few hours to complete scan?

1)From what I understand MCShield operate on a real time scan whereas avast is on demand when it is regarding a removable drive. So if you choose to scan the removable drive after inserting it will it be the same as MCShield?
No .... and MCShield only look for the type of malware that use removable drive to spread when plugged in so if you have 50Gig of files on it these will not be checked by MCShield .....for that you use your AV
2) considering that autorun for windows have been change to autoplay for the user to decide what action to take does this mean that unless the user run the autorun program most threat would not be activated upon inserting?
autorun is only one way these malware spread
3) if the removable drive have thousand of file wouldn't that means that it will take at least a few hours to complete scan?

If traces of malware were found, it will take few minutes, but not hours.