Emsisoft Emergency Kit 10 available

Discussion in 'other anti-malware software' started by Fabian Wosar, Jun 17, 2015.

  1. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    Where did you send the email to and when was it sent?
     
  2. Tarantula

    Tarantula Guest

  3. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    Can you send me your email address you sent your message from in private so I can check out what happened to your message?
     
  4. Tarantula

    Tarantula Guest

    Ok, in a minute.
     
  5. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    Okay, I found your email. You sent it to the normal customer support which is only available on weekdays instead of using the false positive report address that anon posted for you here:

    https://www.wilderssecurity.com/threads/emsisoft-emergency-kit-10-available.377228/#post-2500477

    In any case, I have disabled the signature. The driver name we flag there is used by Qhosts, but it is so generic ("newdriver") that collisions with other applications or just self-written drivers are possible. The update is already available via online update.
     
  6. Tarantula

    Tarantula Guest

    Ok, thank you!
    I wasn't sure it's FP, so it was logical to send it to the normal customer support.
     
  7. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    You are welcome. I just wanted to make sure your mail wasn't somehow lost.
     
  8. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Just downloaded this in my Online Armor snapshot... Must try it out. ;)

    ScreenShot_Emsisoft_Emergency Kit_01.gif ScreenShot_Emsisoft_Emergency Kit_02.gif
     
  9. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    So, far so good...

    ScreenShot_Emsisoft_EKIT10_scan_10.gif ScreenShot_Emsisoft_EKIT10_scan_11.gif ScreenShot_Emsisoft_EKIT10_scan_12.gif ScreenShot_Emsisoft_EKIT10_scan_13.gif
     
    Last edited: Jun 22, 2015
  10. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Scan completed a short time ago...nothing untoward that I can see.

    ScreenShot_Emsisoft_EKIT10_scan_19.gif
     
  11. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Is EEK autostarting at boot or something?
    Getting an alert at boot about a2hooks.dll being started by rundll32.
     
  12. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    EEK does not install anything permanently. The file you mentioned is part of EAM/EIS.
     
  13. Mattchu

    Mattchu Registered Member

    Joined:
    Nov 8, 2008
    Posts:
    72
    Location:
    UK
    2015-06-23_141413.png

    Not sure if anyone else is seeing this but on opening EEK version 10 (both the gui and cmd line) i seem to get the file transfer window flash up (top left) about 2 or three times then the loading malware signatures windows appears...Windows 8.1 64Bit

    Managed to get a screenie, looks like it`s the drivers loading.


    p.s Congrats on the release, it loads the sigs a lot quicker now :thumb:
     
  14. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    But EIM/EIS is not installed and it started after installing EEK.
     
  15. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Yes, I've noticed that window also. It's opened only for a fraction of a second.
     
  16. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    Can you please send me the exact message you get about RunDLL32 trying to load the DLL? Preferably with the full path of the DLL it tries to load being visible. Thanks :)
     
  17. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    Correct. The driver is loaded through an INF file instead of installing it directly. One of the unfortunate side effects of doing it, is that the copy file dialog appears briefly.
     
  18. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    It's from AppGuard:
    "06/24/15 09:33:28 Prevented process <a2hooks64.dll | C:\Windows\System32\rundll32.exe> from launching from <c:\users\XXXX\documents\tools\emsisoftemergencykit\run>.
     
  19. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    Thanks. Will be looking into it shortly. It appears the driver thinks it is part of EAM.
     
  20. Joxx

    Joxx Registered Member

    Joined:
    Sep 5, 2012
    Posts:
    1,718
    The scan is fast and has very little disk read/write, but the update process is the opposite which defeats the purpose


    0.PNG 00.PNG 000.PNG
     
  21. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    We published an update today that should fix this particular issue.
     
  22. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Confirmed fixed, thanks :)
     
  23. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    You are very welcome :).
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.