Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of ewido Support Forums > ewido anti-spyware forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 27th, 2006, 12:55 PM
siliconman01 siliconman01 is offline
Frequent Poster
 
Join Date: Mar 2003
Location: West Virginia (USA)
Posts: 761
Default Please Stop 5 Second Registry Rewrite

In Ewido 4, Build 172, it writes to the startup registry every 5 seconds...as has already been discussed in another thread. Please, Ewido Developers, change this practice. It is driving other security programs NUTS that monitor and/or log entries into the RUN registry keys. RegDefend for example is getting 17280 logging entries per day from this tactic. Other security programs keep checking to see if the 5 second rewrite is new or possibly malicious.
  #2  
Old June 28th, 2006, 07:04 PM
TopperID's Avatar
TopperID TopperID is offline
Very Frequent Poster
 
Join Date: Oct 2004
Location: London
Posts: 1,527
Default Re: Please Stop 5 Second Registry Rewrite

Yes, I agree.

Maybe we could have the option whether to allow these writes or not?
  #3  
Old June 28th, 2006, 09:44 PM
Remouald's Avatar
Remouald Remouald is offline
Regular Poster
 
Join Date: Dec 2005
Posts: 85
Default Re: Please Stop 5 Second Registry Rewrite

I'd like to see it corrected as well...
  #4  
Old June 28th, 2006, 10:18 PM
nameless's Avatar
nameless nameless is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,122
Default Re: Please Stop 5 Second Registry Rewrite

I think any software monitoring the registry ought to be able to ignore certain user-specified activity (i.e. have a white list), as well as activity that doesn't result in any real changes... And of course, logging ought to be optional, not mandatory. I don't use RegDefend, but can't you create a rule in it to allow ewido to write/delete its Run value, and not log it?

The funny thing is that if you disable ewido's option to run at start up, it tries deleting its Run value every 5 seconds...

In any event, I would be somewhat annoyed if they added a registry SSDT hook to ewido, just to satisfy this gripe (which is really due to deficiencies in other software).
  #5  
Old June 28th, 2006, 11:41 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,052
Default Re: Please Stop 5 Second Registry Rewrite

Its, new for me, will the registry write/ delete will happen even if u are using it on-demand, not running all the time.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
  #6  
Old June 28th, 2006, 11:46 PM
Remouald's Avatar
Remouald Remouald is offline
Regular Poster
 
Join Date: Dec 2005
Posts: 85
Default Re: Please Stop 5 Second Registry Rewrite

Quote:
Originally Posted by nameless
I don't use RegDefend, but can't you create a rule in it to allow ewido to write/delete its Run value, and not log it?

I'm using RedDefend but I think I cannot disable the log for a specific software (here EWIDO).

What I can do is disable the loging for any software that set a value to:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Currentversion\Run**

@aigle Yes, but only when you open Ewido for scanning. The registry writes will stop when you exit the program from the system tray.
  #7  
Old June 29th, 2006, 12:29 AM
siliconman01 siliconman01 is offline
Frequent Poster
 
Join Date: Mar 2003
Location: West Virginia (USA)
Posts: 761
Default Re: Please Stop 5 Second Registry Rewrite

There are numerous security programs that provide protection and logging of the Startup registries....AdAware, SSM, SpySweeper, CounterSpy and on and on. This ewido technique of continously rewriting the startup key is unique to ewido. It is not a deficiency in the other security programs that they do not have an option to allow ignoring specific programs that want to write in the Startup registry area or the Startup folder in Programs list. Personnally I have never encountered a program of any type that does this continuous rewriting.

It's a totally inadequate method of providing "self protection" because all that has to be done by a malicious program is to kill ewido in memory and then remove its startup registry key.
  #8  
Old June 29th, 2006, 01:16 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,052
Default Re: Please Stop 5 Second Registry Rewrite

Quote:
Originally Posted by Remouald
@aigle Yes, but only when you open Ewido for scanning. The registry writes will stop when you exit the program from the system tray.
Thanks, but I asked this as as I know guard.exe is still running even if i exit the prigramme, so does it will write in the registry or not? Can u confirm?
__________________
MalwareDefender / CFP, GesWall, KeyScrambler
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
  #9  
Old June 29th, 2006, 01:23 AM
Remouald's Avatar
Remouald Remouald is offline
Regular Poster
 
Join Date: Dec 2005
Posts: 85
Default Re: Please Stop 5 Second Registry Rewrite

It stops registry writes as soon as you exit ewido even if guard.exe is active. It's ewido.exe that writes into the registry.
  #10  
Old June 29th, 2006, 01:48 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,052
Default Re: Please Stop 5 Second Registry Rewrite

Thanks.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
  #11  
Old June 29th, 2006, 03:47 AM
vinzenz.ewido's Avatar
vinzenz.ewido vinzenz.ewido is offline
former ewido team
 
Join Date: Dec 2005
Location: Langenfeld, Germany
Posts: 425
Default Re: Please Stop 5 Second Registry Rewrite

This seems to be a bug, it shouldn't rewrite it everytime. It should only check if it is set and if the setting in the startup entries is not identical with the settings choosen by the user it should be written.

I'm sorry. We'll correct it asap.

BR
__________________
AVG Development Team
AVG Technologies
  #12  
Old July 5th, 2006, 02:46 AM
siliconman01 siliconman01 is offline
Frequent Poster
 
Join Date: Mar 2003
Location: West Virginia (USA)
Posts: 761
Default Re: Please Stop 5 Second Registry Rewrite

Any progress on fixing and issuing pgm update for this annoying bug.?
  #13  
Old July 6th, 2006, 03:59 PM
pbparker pbparker is offline
Infrequent Poster
 
Join Date: Jul 2006
Posts: 5
Default Re: Please Stop 5 Second Registry Rewrite

Me too, I uninstalled until it's fixed. BTW, it isn't 5 second rewrites for me, it's nonstop registry parsing and writing.

Use regmon at sysinternals.com and you can see how much it's churning away.
  #14  
Old July 6th, 2006, 05:30 PM
gerardwil's Avatar
gerardwil gerardwil is online now
Massive Poster
 
Join Date: Jan 2004
Location: The Netherlands
Posts: 4,014
Default Re: Please Stop 5 Second Registry Rewrite

OK here go, I try one more time.
I wonder what the outcome will be, I had these spikes shortly after ewido 4 was public.
But they are gone.....and didn't came back.
In my sig you can see whats running realtime on this box.
In the attachement you see ewido running and doing a scheduled scan (registry and memory).
In the next attachement you see ewido running and doing an update.
Darn: again I can't upload a .gif

Gerard
Attached Images
 
  #15  
Old July 6th, 2006, 05:37 PM
gerardwil's Avatar
gerardwil gerardwil is online now
Massive Poster
 
Join Date: Jan 2004
Location: The Netherlands
Posts: 4,014
Default Re: Please Stop 5 Second Registry Rewrite

And screenshot 2 (the first not being nice)
Attached Images
 
  #16  
Old July 7th, 2006, 06:38 AM
GWA's Avatar
GWA GWA is offline
Regular Poster
 
Join Date: May 2005
Location: Albuquerque, New Mexico
Posts: 59
Default Re: Please Stop 5 Second Registry Rewrite

As a result of the registry rewrite issue, I have terminated realtime scanning and no longer have Ewido start with Windows. I am using TH for realtime. As soon as this registry issue is corrected, I'll will reverse those roles.
  #17  
Old July 18th, 2006, 02:53 AM
siliconman01 siliconman01 is offline
Frequent Poster
 
Join Date: Mar 2003
Location: West Virginia (USA)
Posts: 761
Default Re: Please Stop 5 Second Registry Rewrite

Any luck in correcting these issues and releasing an ewido update in the foreseeable future?
  #18  
Old July 18th, 2006, 11:15 AM
robinb's Avatar
robinb robinb is offline
Frequent Poster
 
Join Date: Jun 2006
Location: NJ
Posts: 354
Default Re: Please Stop 5 Second Registry Rewrite

can you explain and tell me where to look where ewido does this rewriting? so I can check my computer too?

thanks
robin
  #19  
Old July 18th, 2006, 11:48 AM
siliconman01 siliconman01 is offline
Frequent Poster
 
Join Date: Mar 2003
Location: West Virginia (USA)
Posts: 761
Default Re: Please Stop 5 Second Registry Rewrite

It shows up by using Ghost Security's RegDefend which guards the Startup RUN registry key. The logger of RegDefend logs an entry every 5 seconds.

You can also view the file access activity of ewido by install and running FileMon from SysInternals.

http://www.sysinternals.com/Utilities/Filemon.html
  #20  
Old July 18th, 2006, 12:53 PM
robinb's Avatar
robinb robinb is offline
Frequent Poster
 
Join Date: Jun 2006
Location: NJ
Posts: 354
Default Re: Please Stop 5 Second Registry Rewrite

does it use up memory or does it use up space?
and when is ewido going to fix this?

robin
  #21  
Old July 18th, 2006, 01:15 PM
siliconman01 siliconman01 is offline
Frequent Poster
 
Join Date: Mar 2003
Location: West Virginia (USA)
Posts: 761
Default Re: Please Stop 5 Second Registry Rewrite

Quote:
does it use up memory or does it use up space?
Yes, and Yes

Quote:
and when is ewido going to fix this?

That was my question too
  #22  
Old July 18th, 2006, 01:41 PM
vinzenz.ewido's Avatar
vinzenz.ewido vinzenz.ewido is offline
former ewido team
 
Join Date: Dec 2005
Location: Langenfeld, Germany
Posts: 425
Default Re: Please Stop 5 Second Registry Rewrite

It will be fixed within the next release of the binaries. It is already fixed in the code actually but we need some more fixes and we have to figure out another problem first.

Regards,
Vinzenz
__________________
AVG Development Team
AVG Technologies
  #23  
Old July 18th, 2006, 01:44 PM
robinb's Avatar
robinb robinb is offline
Frequent Poster
 
Join Date: Jun 2006
Location: NJ
Posts: 354
Default Re: Please Stop 5 Second Registry Rewrite

does that mean you will send out an update for this fix in all versions of 4.0 because i have the pro version of 4.00.172 plus?

or will you put it in a new version that we will have to download and install over it?

and how soon do you think this will be?

robin
  #24  
Old July 18th, 2006, 02:07 PM
Chubb's Avatar
Chubb Chubb is offline
Very Frequent Poster
 
Join Date: Aug 2005
Posts: 1,807
Default Re: Please Stop 5 Second Registry Rewrite

Quote:
Originally Posted by robinb
does that mean you will send out an update for this fix in all versions of 4.0 because i have the pro version of 4.00.172 plus?

or will you put it in a new version that we will have to download and install over it?

You will probably get the update through automatic update. You don't need to re-install it using the new setup file.
  #25  
Old July 19th, 2006, 05:08 AM
vinzenz.ewido's Avatar
vinzenz.ewido vinzenz.ewido is offline
former ewido team
 
Join Date: Dec 2005
Location: Langenfeld, Germany
Posts: 425
Default Re: Please Stop 5 Second Registry Rewrite

Quote:
Originally Posted by Chubb
You will probably get the update through automatic update. You don't need to re-install it using the new setup file.
correct

Quote:
Originally Posted by robinb
and how soon do you think this will be?
I'm sorry I actually don't know. I hope that it will be asap.

Regards,

Vinzenz
__________________
AVG Development Team
AVG Technologies
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of ewido Support Forums > ewido anti-spyware forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 02:17 PM.


Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2010, Wilders Security Forums