(Poll) I got a rootkit - why?

You don’t play with fire, do you David?
If not, ok, UAC is just another question you need to answer…

You won’t like Linux one then either :slight_smile:

so basically we’ve mentioned and linked the sum of these comments:

uac doesn’t provide protection against malware running
uac attempts to keep things in user-mode not admin mode
uac can easily be bypassed by malware

thus, uac attempts to keep legitimate programs in user-mode and does nothing about protecting from viruses/malware

thus it’s just an annoyance?

I have survived this long without UAC on XP Pro so I guess I will for the foreseeable future. I take proactive measures to help negate risk and if all else fails I have a robust back-up and recovery strategy.

It has been a very long time since I used Linux or rather Unix (in the Army) and that was on a very limited basis at those times it was pretty command line only not many nice applications knocking around then. I have tried a few Live Linux CDs and never got beyond that point, wasn’t that impressed.

Wrong.

Didn’t you use DropMyRights?

UAC is not a panacea of course…

so having uac, which malware can turn off easily, is like asking every bank patron “are you a bank robber?” of course the would-be robber will say no, but now every single patron has to stop and answer too.

DropMyRights was one, but that isn’t available (doesn’t work) in win7.

For me getting ride of it has made using my win7 netbook more user friendly.

Any so called security feature has to make life easier and not harder once you agree to allowing a program to run UAC should remember that decision and not keep harping on and on and on if the file hasn’t changed (MD5, etc.).

The more of a pain in the a**e it is the more likely it is that people will switch it off, so much for it being a security feature when the user has switched of because it is more rouble than it is worth when malware can circumvent it so darn easily.

When UAC was first muted I thought good idea, that is the death-knell for AVs then if the UAC can prevent driveby infection, etc. The first Vista one was horrendous and it didn’t seem to make life any harder for malware as the forums attested.

Then win7 came out touted to be much more secure and with a more friendly UAC, should this sound the death-knell for AVs again. No win7 systems seem to be getting infected just as easily as seen in the forums.

So for me UAC is far from being a panacea. It is well named User Access Control, the legit User has no Control over Access, but that doesn’t seem to be a problem for non-users (malware).

It does not needed if you use UAC.
Win7 already works with non-admin privileges.

Symantec started to develop a tool for Windows Vista but (I think) stopped it.
Hash calculation is an intensive action, specially for big executables.

It seems the same reason for what people disable the antivirus while installing software… that annoying messages of sandboxing, false positives and so on ;D

People are giving UAC access to malware…

sorry what? ;D :smiley: ;D

that’s the thing - if you ask a user over and over every few seconds/minutes, they’re not even going to read they’re just going to click yes.

makes me think back to when vista first came out, and the old mac versus pc commercials aired:
“mac wishes to great you, allow or deny?”

heh

You won’t never be an user of HIPS technology…
You won’t set avast autosandbox and behavior blocker to “Ask” mode…

i would be when i wanted to be - i’d have that in my VM… but for my day to day operations, probably not

for many home-users, and even employees at workstations, that would last for about a day before they screamed bloody murder

for a security expert in his field, yes - yes to both… but for an average “sheep” user, no way.

The difference being, HIPS or Auto-Sandbox and the Behavior Shield are able to remember your decision and not permanently keep pestering you over and over and over again, there really is no comparison to how much UAC is a pain in the a**e is. Until it become more user friendly/configurable many will end up disabling it.

I have both auto-sandbox and the behaviour shield and all other avast settings set to Ask and that doesn’t bother me in the slightest. I like to know what is going on in my system and don’t mind answering a question once.

Until it become more user friendly/configurable many will end up disabling it.

there’s a group policy to disable UAC - maybe that’s too far though, to not even give them the choice

Because you’re a good guy and do not go to dark side, or test new software, or visit dangerous places…
Then, avast is so silent for you.

Eh… Just got bored, so I tested 5 random rootkits that infect MBR. Guess what - with UAC on, 5/5 failed. :stuck_out_tongue:

BTW, wondering where are the votes from users who come here daily to complain they got infected with TDL etc. ???

My experience with UAC?
It stopped me from accidentally installing system tool when trying to add to the chest. It did have the UAC icon though…so could well have been coded to ask for admin rights…

Other than that, I will admit, it does drive me a little crazy… ;D

Hi spg SCOTT,

Found this article on the merits and annoyances of UAC very worth reading: http://www.brighthub.com/computing/windows-platform/articles/20268.aspx
A pre-check on eventual downloads for being free of malcode is also a good prevention scheme, scan at a reliable url meta scan, copy into a virustotal.scan, pre-check with good old avast and/or SAS. Just clicking away and the initial “Oh I see something goes wrong” is adding to the awe and shock whn people realize they act before they think,

polonus

yes even if don’t believe blindly in the power of UAC, I must admit that I got it “on” for a few years now. It doesn’t bother me… I don’t test malware on my system (not in VMs either) but if Dok has observed that UAC prevented some rootkits from infecting his system, well that’s interesting. That’s interesting because Dok runs Seven/32, less immune to rootkits than Seven/64.

Move the slider to Notify me only when programs try to make changes to my computer (do not dim my desktop)
http://support.microsoft.com/kb/975787