PDA

View Full Version : ewido slip up??


WhiteWhaleHoly...
August 10th, 2005, 07:00 AM
hello,

my nod32 progrma recently detected a scrip that someone was trying to put onto my computer over the internet. My question is simple, why the hell didnt ewido also detect this, its a trojan suite for gods sake! Nod32 found 7 attempted infections, ewido said nothing at all.

thanks,

WWHG.

.....
August 10th, 2005, 07:53 AM
Hi WhiteWhaleHoly...,

Out of intrest, what was the name of the malware detected by NOD32? The realtime ewido guard only detects EXECUTED files and scans only .dll's and .exe's afaik. However the on-demand scanner can be setup to scan all file types. Maybe you should run the on-demand scanner too?

However, please note that no one scanner can detect 100% of malware. Perhaps you should submit the malware to ewido so they can add it to there database?

Don Pelotas
August 10th, 2005, 08:15 AM
The anti-virus will always detect it first, thats how they (anti-trojans) work as backup to your AV if this slips up, so if you had run an on-demand, Ewido would most likely have detected it. :)

WhiteWhaleHoly...
August 10th, 2005, 08:51 AM
they were .htm files. I dont know if I really buy the whole 'backup' thing. I bought ewido to provide strong real time protection from trojans and malware, in this case it did not spot this:

JS/TrojanDownloader.IstBar.J trojan

If it is intended for use as a backup for on-demand scanning only ewido should make it clear on their website.

thanks for the replies.

WWHG.

peter.ewido
August 10th, 2005, 08:54 AM
-{ Quote: "

Before the file execution (by "double clicking" on it) it gets scanned
Active scan of the system memory
" }-

-> No http traffic scanning as your antivirus already does this.

Don Pelotas
August 10th, 2005, 09:20 AM
-{ Quote: "they were .htm files. I dont know if I really buy the whole 'backup' thing. I bought ewido to provide strong real time protection from trojans and malware, in this case it did not spot this:

JS/TrojanDownloader.IstBar.J trojan." }-
You are missing the point, if it's in Ewido's signature's and your AV misses it, then Ewido steps in, thats what i meant by "backup". :)

WhiteWhaleHoly...
August 10th, 2005, 10:04 AM
ahh, ok. So it knows when nod32 has found something and lets it deal with it. Im impressed!


thanks,

WWHG.