View Full Version : SysInspector versus Sysinspector EAV 4.0 Beta
Donald®
November 20th, 2008, 07:53 PM
SysInspector stand alone application version 1.1.2.0 don't detect the process AUDIODG.EXE (Windows Vista = Windows Audio Device Graph Isolation that appears on Windows Task Manager), but SysInspector integrated on ESET EAV 4.0 Beta detects the process and classify as ROOTKIT.
So I thing something is wrong in both versions...................:blink:
agoretsky
November 20th, 2008, 08:27 PM
Hello,
The issue is being investigated. Thank you for your report.
Regards,
Aryeh Goretsky
Kosak
November 21st, 2008, 08:57 AM
Hello, reason of better ESI in v4 is latter Antistealth module. :thumb:
SuicidePunk
November 21st, 2008, 10:19 AM
The reason is Vista Protected Process, it mean Windows vista has protected this process (AUDIODG.EXE), its kind of anti piracy stuff.
Integrated version SysInspector in ESET EAV 4, has detected the process cause it use the AV/ESET 4, scan engin ( anti stealth ).
For more information about protected process:
http://www.microsoft.com/whdc/system/vista/process_vista.mspx
SystemJunkie
December 20th, 2008, 12:58 PM
{QUOTE-> it mean Windows vista has protected this process (AUDIODG.EXE), its kind of anti piracy stuff. <-QUOTE}There you see how trustworthy this os is. Security through obscurity once more. The <unknown> user stacks are likely memory relocations, they use user mode rootkit technology to prevent access to audiodg, really bad, reminds me to some r3 rootkit. Never forget it is a extremely rich company who used cracked sf 4.5 to create windows xp internal soundfiles, what else to say. How should one trust in such a enterprise. A company claims to make anti-piracy-stuff but did piracy (http://www.pcwelt.de/bildpopup/104700/104785/32052/index.html). Devilish cynism.
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums