View Full Version : Eset Sysinspector
demonio
August 24th, 2008, 08:31 AM
I wanted to know if the new versions of Eset Sysinspector can make changes or deletions directly from the program
Best Regards;)
SystemJunkie
August 24th, 2008, 08:46 AM
Which version do you consider as latest? 1.1.1.0 is read only.
Kosak
August 24th, 2008, 11:18 AM
Hello,
according to my informations ESI will be only analytical utility. Actually I would see problem in discovering hidden objects. Then you can use other application to remove malware traces, when you see them. But yes, better is "app" all-in-one. Other side is that ESI will be integrated into ESS and for better protection of beginners is, if ESET'll keep only analytical program.
Regards
ASpace
August 24th, 2008, 01:59 PM
{QUOTE-> Other side is that ESI will be integrated into ESS and for better protection of beginners is, if ESET'll keep only analytical program. <-QUOTE}
In my own opinion , integration in ESET products will be pointless if it just integrates it in the program . It should either help ESET find new malware or help users manually remove malware found thanks to its more sensitive heuristics.
I have once suggested ESET to make ESI like another anti-malware program I really like -> deep integration with ThreatSense.NET
ESI should do full scan by default with the Scheduler (once per week , for example) . When ESI (integrated in EAV/ESS) finds unknown objects (rating 5 or more) , it should ask the user in a kind message something like this "We have found a suspicous file . ESET would be glad if you submit a copy of it so that we can analyse it -> buttons Submit now or Don't submit"
Then , ThreatSense.NET simply takes a copy and push it in ESET Virus Lab.
If they find the "suspicious file" is real malware , detection can be added and later the malware killed. Hope they make something like this :) Note that another very big company , which offers a free anti-malware product have similar function and it DOES work well with them.
SystemJunkie
August 25th, 2008, 06:14 PM
Eset Sysinspector deserves many respect. This tool detects unknown user mode rootkits I tested myself. Great work, already on Level 5 you should consider to find malware, this is proven. Use it! On the whole it ranks in lower midfield it detects not everything but good for detection of e.g. specialized user mode rootkits. Many other tools may fail that is a good point for Eset.
Kosak
August 25th, 2008, 06:23 PM
I would like see ESI with upgraded Antistealth module, because my tests don't say about 100%. Other thing is that safe programs have been signed as unknown or unsafe.
HiTech_boy, nice idea. It wants statemant from ESET.
Regards
agoretsky
August 26th, 2008, 06:54 PM
Hello,
Future features and functionality in ESET SysInspector will be determined by a number of factors, including requests from users.
If there are changes you would like to see in the software, please let ESET know.
Regards,
Aryeh Goretsky
SystemJunkie
August 28th, 2008, 08:59 AM
I have a result that could be interesting for your team:
http://i36.tinypic.com/110djl2.png
Only unknown or exploit?
Marcos
August 28th, 2008, 09:23 AM
{QUOTE-> I have a result that could be interesting for your team:
http://i36.tinypic.com/110djl2.png
Only unknown or exploit? <-QUOTE}
It seems to be ok, just don't know where svchost.exe and lsass.exe are connecting to.
SystemJunkie
August 28th, 2008, 09:07 PM
They connect this way:http://i36.tinypic.com/n4ch39.jpg
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums