ewido security suite 3.5 beta

Discussion in 'other anti-trojan software' started by quexx88, May 27, 2005.

Thread Status:
Not open for further replies.
  1. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    As I tried to explain to you earlier, this is NOT an issue... Memory usage will again go down as soon as another program needs the memory (This is btw. what these so called "ram cleaners" do... They simply allocate as much ram as possible... This gives you ZERO additional performance or "free" memory... In fact the system will be even SLOWER after a "memory defragmentation" as things have to be read again into memory when needed.)...
     
  2. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    I did a restart and no change. I will see if the next update date shows when it becomes available...
     
  3. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    Sounds like a bug to me, will be checked :)
     
  4. colorado13

    colorado13 Registered Member

    Joined:
    Apr 16, 2005
    Posts:
    117
    Location:
    Orihuela, Spain
    I perform a full scan of my computer and ewido security suite 3.5 beta gave me:

    C:\Program Files\AnalogX\Script Defender\test.vbs -> Trojan.Io
    C:\Program Files\Debugging Tools for Windows\adplus.vbs -> Trojan.Io
    C:\Program Files\Yahoo!\Messenger\YPager.exe -> Heuristic.Win32.Backdoor
    C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe -> TrojanDownloader.TSUpdate.i
    C:\WINDOWS\PCHealth\HelpCtr\System\NetDiag\dglogs.htm -> Trojan.Io

    Should i worry?

    Regards
     
  5. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    Nope, "luckily" these are false positives... Could you please send them to submit@ewido.net so we get an overview of all of them? Many thanks!
     
  6. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA

    Attached Files:

  7. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    fish25,

    for when a ewido forum? :)

    Regards
     
  8. colorado13

    colorado13 Registered Member

    Joined:
    Apr 16, 2005
    Posts:
    117
    Location:
    Orihuela, Spain
    I supposed that but i'm not shure!
    Many thanks for your help!
     
  9. gottadoit

    gottadoit Security Expert

    Joined:
    Jul 12, 2004
    Posts:
    605
    Location:
    Australia
    Have had a bit of a play with the UI and done some scans, have found a few little oddities. Like everyone else I got a few false positives (Trojan.Io seems popular), but being a beta thats to be expected

    Problem #1 :
    After a Full Scan the SecuritySuite.exe process has 66,660 handles left open. Most of these handles are to the Key HKLM\SOFTWARE\ewido\config
    This can be trivially reproduced by doing a registry scan and then looking at the open handles with process explorer

    Odd/Undesirable Behaviour #1 (ewidoguard) :
    ewidoguard.exe seems to be very rapidly read polling the key HKLM\software\ewido\guard
    I would like an option to be able to turn this off please, I can just as easily protect this key with RegDefend and lose the multiple times per second poll and associated Context Switching
    Even with realtime protection turned of the guard is still doing this...
    Code:
    0.00328701 ewidoguard.exe:3120	OpenKey HKLM\software\ewido\guard	SUCCESS Access: 0x20019 	
    0.00669135	ewidoguard.exe:3120 QueryValue HKLM\software\ewido\guard\guard SUCCESS	0x12345678	
    0.00669750	ewidoguard.exe:3120 OpenKey	HKLM\software\ewido\guard SUCCESS	Access: 0x20019 	
    0.00675281	ewidoguard.exe:3120 OpenKey	HKLM\software\ewido\guard SUCCESS	Access: 0x20019 	
    0.00698105	ewidoguard.exe:3120 QueryValue HKLM\software\ewido\guard\guard SUCCESS	0x12345678	
    0.00698552	ewidoguard.exe:3120 QueryValue HKLM\software\ewido\guard\guard SUCCESS	0x12345678	
    0.00698944	ewidoguard.exe:3120 CloseKey	HKLM\software\ewido\guard SUCCESS		
    0.00705509	ewidoguard.exe:3120 CloseKey	HKLM\software\ewido\guard SUCCESS		
    0.00709951	ewidoguard.exe:3120 CloseKey	HKLM\software\ewido\guard SUCCESS		
    0.03539584	ewidoguard.exe:3120 OpenKey	HKLM\software\ewido\guard SUCCESS	Access: 0x20019 	
    0.03540869	ewidoguard.exe:3120 OpenKey	HKLM\software\ewido\guard SUCCESS	Access: 0x20019 	
    0.03562101	ewidoguard.exe:3120 QueryValue HKLM\software\ewido\guard\guard SUCCESS	0x12345678	
    0.03562548	ewidoguard.exe:3120 OpenKey	HKLM\software\ewido\guard SUCCESS	Access: 0x20019 	
    0.04401788	ewidoguard.exe:3120 QueryValue HKLM\software\ewido\guard\guard SUCCESS	0x12345678	
    0.04412516	ewidoguard.exe:3120 CloseKey	HKLM\software\ewido\guard SUCCESS		
    0.04416623	ewidoguard.exe:3120 QueryValue HKLM\software\ewido\guard\guard SUCCESS	0x12345678	
    0.04438050	ewidoguard.exe:3120 CloseKey	HKLM\software\ewido\guard SUCCESS		
    0.04438497	ewidoguard.exe:3120 CloseKey	HKLM\software\ewido\guard SUCCESS		
    0.06002858	ewidoguard.exe:3120 OpenKey	HKLM\software\ewido\guard SUCCESS	Access: 0x20019 	
    0.06003500	ewidoguard.exe:3120 OpenKey	HKLM\software\ewido\guard SUCCESS	Access: 0x20019 	
    0.06004786	ewidoguard.exe:3120 OpenKey	HKLM\software\ewido\guard SUCCESS	Access: 0x20019 	
    0.06017916	ewidoguard.exe:3120 QueryValue HKLM\software\ewido\guard\guard SUCCESS	0x12345678	
    0.06025710	ewidoguard.exe:3120 QueryValue HKLM\software\ewido\guard\guard SUCCESS	0x12345678	
    0.06036829	ewidoguard.exe:3120 CloseKey	HKLM\software\ewido\guard SUCCESS		
    0.06041019	ewidoguard.exe:3120 CloseKey	HKLM\software\ewido\guard SUCCESS		
    Odd/Undesirable Behaviour #2 (SecuritySuite.exe) :
    The SecuritySuite.exe main window is showing high ongoing Context Switching when its doing nothing. what is it doing ?


    • The threads securitysuite.exe+0x146f6 and MSVCR71.dll!endthreadex+0x31 seem to be responsible for the context switching
    • The main window is continuously getting WM_GETICON messages which is not a behaviour I am seeing for other apps on the PC
    Enhancement #1 :
    Allow the SecuritySuite GUI window to be resized so that the report can be read onscreen a little more easily

    Enhancement #2 :
    Having cookies mixed in with all the other results makes it a little harder to distinguish between non-desirables and actual problems, maybe

    Enhancement #3 :
    Have an easy way to get back and see logs from previous scans

    Enhancement #4 :
    After a memory scan, possibly show "no infected processes found" rather than files ?
     
  10. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    You're right, these are all enhancements already planned (most of them for 3.6) ;)
     
  11. Infinity

    Infinity Registered Member

    Joined:
    May 31, 2004
    Posts:
    2,651
    Fish, did you encounter some issues about lock ups when scanning? this occurs at random moments...if I close/end all other apps lock up still takes place...
    sometimes it's at about 5% scantime, sometimes at 15%...but a cold reboot has to take place to get ahold of my computer back...
     
  12. Infinity

    Infinity Registered Member

    Joined:
    May 31, 2004
    Posts:
    2,651
    /edit: I know it's beta and I don't mind that :) just like to inform you.
     
  13. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    During which scan? Registry, Memory or Files?
     
  14. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    I have a gmail account and use the gmail notifier to let me know when I have mail. It sits in my system tray. Whenever I doubleclick the icon or right click >> view inbox to go to my mailbox in my browser, the guards CPU jumps up to 50 % and stays there indefinitely. I have to deactivate realtime protection and wait for the CPU usage to return to normal, then reactivate to fix the problem. I wonder if anyone else that uses gmail has this problem?
     
  15. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    No problem here (with firefox being the default browser)...
     
  16. Infinity

    Infinity Registered Member

    Joined:
    May 31, 2004
    Posts:
    2,651
    Hi, this happens at random intervals...if I use registry scan, fast scan, complete scan..it doesn't matter what type of scan I take.
    sometimes it happens at 10% or 15% when scanning.
     
  17. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    all these scans have one in common... the registry scan... does it also happen when you do a custom scan of your drives?
     
  18. gottadoit

    gottadoit Security Expert

    Joined:
    Jul 12, 2004
    Posts:
    605
    Location:
    Australia
    Thanks for the quick reply

    I would have thought that what I reported as problem #1 was simply a bug to get fixed in the beta, its a bit excessive consuming all those filehandles for no reason
     
  19. Edwin024

    Edwin024 Registered Member

    Joined:
    Nov 14, 2004
    Posts:
    1,008
    I do believe you but still I think that the 3.5 beta is not ok. When I do a scan with Counter Spy you see that only the counterspy file grows in memory use. The other programs do not. And when the CS scan is done the program immidiately drops back to 8 mb or so. Ewido's new one has a memory effect on ALL other programs and doesn't drop back at all. So ALL programs stay on very high RAM numbers. Do you find that correct?

    I don't see the memory drop that you are writing about too, by the way. Only a new startup makes that happen. Or using the MemTurbo.
     
  20. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    Yes, it's perfectly ok... We could even praise it as a new feature... As the memscanner of the ewido security suite scans all modules of each process (which most others don't!), they will get loaded into memory (this is where the hdd activity comes from)... This no problem, bug or whatever, have a look here:

    http://aumha.org/win5/a/xpvm.php

    Try to start a program that uses much memory (like a game or something) and watch the memory usages of the other programs... They will go back down...
     
  21. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    I use Opera as my default browser (8.01)...
     
  22. gerardwil

    gerardwil Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    4,748
    Location:
    EU
    Some updates right now for B-users.

    Gerard
     
  23. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    With the last update, this problem is fixed :)
     
  24. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Same here ;) ...
     
  25. Notok

    Notok Registered Member

    Joined:
    May 28, 2004
    Posts:
    2,969
    Location:
    Portland, OR (USA)
    The update does seem to have helped the CPU usage, however it still uses 10-20% with Prevx running.. shutting either of them down brings CPU down to 1-5%
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.