View Full Version : For fish25 re:eiwido/ESS
spy1
March 22nd, 2004, 12:20 PM
Besides the very big PLUS that it's free, is there anything that sets your program apart, detection-wise, from any of the pay programs?
IOW, what would make me choose your program over one of the other ones available?
How well does it "clean up" after an infection - or does it just "quarantine" stuff?
Are you using any "new" types of detection processes?
How about unpackers? More than one? Pete
spy1
March 22nd, 2004, 12:27 PM
Come to think of it - who are you?
What's your/your company's background?
(So many people come out of nowhere, you know what I mean?).
IOW - baldly put (but with no offense intended) - why should we trust either you or your program?
(As you come to know and love me, you'll notice that I ask awkward questions at times! ;D ). Pete
*Great catch on that re-basing issue, BTW!
peter.ewido
March 22nd, 2004, 12:46 PM
-{ Quote: "Besides the very big PLUS that it's free, is there anything that sets your program apart, detection-wise, from any of the pay programs?" }-
Many things ;) Just some examples:
Very strong binary signatures with Fuzzy Logic
Powerful unpacking engine based on emulation
Crypted database (AES 128-Bit)
Intelligent Online-Update with integrity-check
Generic-Binder-Detection
Very user-friendly Interface
...
The upcoming pro-Version will also feature a Guard running on Ring 0, a real memory Scanner (can detect e.g. armadillo copymem, api hooking), Heuristics and so on...
-{ Quote: "How well does it "clean up" after an infection - or does it just "quarantine" stuff?" }-
Searches for autostart/running processes and finally removes the file (with backup)... If not possible after reboot.
-{ Quote: "Are you using any "new" types of detection processes?" }-
Again, many (even more than KAV!)... Fuzzy signatures against patching & signature detection, immune against rebasing/OEP modifaction etc.
-{ Quote: "How about unpackers? More than one?" }-
More than one! We use generic emulation... So we're able to unpack e.g. upx, aspack, fsg, neolite, pepack, stones pe crypter, pklite32, morphine etc. Immune against entrypoint/stub patching...
spy1
March 22nd, 2004, 01:39 PM
Sounds good! Need a tester? Pete
solarpowered candle
March 22nd, 2004, 11:12 PM
why doesnt ESS support win98 now that microsoft have back tracked on their decisions due to the over whelming amount of businesses still using them and many home users also.
Slovak
March 23rd, 2004, 08:39 AM
For those of us using this "free" version, how much $$ will you take us for when the upcoming "pro" version comes out?
spy1
March 23rd, 2004, 10:07 AM
spc - Perhaps the technologies and features he's using simply don't work on the older OS's?
Slovak's question about the price was pertinent:
fish25 - how much are you going to charge for the "Pro" version?
And, once the "Pro" version comes out - are you still going to support the freeware version? Pete
peter.ewido
March 23rd, 2004, 11:31 AM
-{ Quote: "
fish25 - how much are you going to charge for the "Pro" version?
" }-
not quite sure yet, depends on the final features, but not too much ;)
-{ Quote: "
And, once the "Pro" version comes out - are you still going to support the freeware version?
" }-
sure we'll do!
Slovak
March 24th, 2004, 06:56 AM
-{ Quote: " quoting: fish25 link=board=25;threadid=25372;start=0#msg148528 date=1080059461]
-{ Quote: "
fish25 - how much are you going to charge for the "Pro" version?
" }-
not quite sure yet, depends on the final features, but not too much ;)
" }-
Not too much could be $50 or so, I am sure TDS says their product doesn't cost too much either. It would be nice if us so far faithful users of the "free" version that says "pro Version" when launched could get a really nice discounted price ;) ;)
peter.ewido
March 25th, 2004, 06:56 PM
the only thing i can say at the moment is that the ess will be cheaper than tds ;)
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums