ewido security suite 3.5 beta

Discussion in 'other anti-trojan software' started by quexx88, May 27, 2005.

Thread Status:
Not open for further replies.
  1. andre25

    andre25 Registered Member

    Joined:
    Jun 5, 2005
    Posts:
    3
    false Positive in kaspersky internet security 2006 (beta)

    C:\Program Files\Kaspersky Lab\AVP6\pdmhist\c34.BEF0670A01C569A4.history\00000025.bak -> Spyware.Cookie.Bluestreak

    C:\Program Files\Kaspersky Lab\AVP6\pdmhist\c34.BEF0670A01C569A4.history\0000002d.bak -> Spyware.Cookie.Bluestreak

    C:\Program Files\Kaspersky Lab\AVP6\pdmhist\c34.BEF0670A01C569A4.history\0000002f.bak ->
    Spyware.Cookie.Bluestreak

    C:\Program Files\Kaspersky Lab\AVP6\pdmhist\c34.BEF0670A01C569A4.history\00000033.bak ->
    Spyware.Cookie.Bluestreak

    C:\Program Files\Kaspersky Lab\AVP6\pdmhist\c34.BEF0670A01C569A4.history\00000038.bak -> Spyware.Cookie.Bluestreak

    C:\Program Files\Kaspersky Lab\AVP6\pdmhist\c34.BEF0670A01C569A4.history\0000003e.bak -> Spyware.Cookie.Bluestreak

    C:\Program Files\Kaspersky Lab\AVP6\pdmhist\c34.BEF0670A01C569A4.history\00000045.bak -> Spyware.Cookie.Bluestreak

    C:\Program Files\Kaspersky Lab\AVP6\pdmhist\c34.BEF0670A01C569A4.history\00000110.bak -> Spyware.Cookie.Fastclick

    C:\Program Files\Kaspersky Lab\AVP6\pdmhist\c34.BEF0670A01C569A4.history\00000112.bak -> Spyware.Cookie.Adserver

    C:\Program Files\Kaspersky Lab\AVP6\pdmhist\c34.BEF0670A01C569A4.history\00000113.bak -> Spyware.Cookie.Adserver

    C:\Program Files\Kaspersky Lab\AVP6\pdmhist\c74.8CD5980801C569A9.history\00000004.bak -> Spyware.Cookie.Doubleclick

    C:\Program Files\Kaspersky Lab\AVP6\pdmhist\c74.8CD5980801C569A9.history\00000005.bak -> Spyware.Cookie.Atdmt

    Groeten uit nederland
     
  2. Don Pelotas

    Don Pelotas Registered Member

    Joined:
    Jun 29, 2004
    Posts:
    2,257
  3. Edwin024

    Edwin024 Registered Member

    Joined:
    Nov 14, 2004
    Posts:
    1,008
    I don't think so ;)

    I guess that Andre means that Ewido is flagging this as FP's.

    For that matter I have deleted ewido for the time being. The FP's are too much still.
     
  4. andre25

    andre25 Registered Member

    Joined:
    Jun 5, 2005
    Posts:
    3
    sorry ik spreek geen engels maar het gaat hier toch om de false postivie van ewido?
     
  5. Don Pelotas

    Don Pelotas Registered Member

    Joined:
    Jun 29, 2004
    Posts:
    2,257
    That could be it :D..........;). I have uninstalled too, but not because of false positives,those were down to two after submitting all that the FP's i had. Seemed to be a very nice improvement and i'm looking forward to when the final version is released. :)
     
  6. gerardwil

    gerardwil Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    4,750
    Location:
    EU
    As for now I don't have anymore FP's since last update (#1310)
    Btw it is quiet here ;)
     
    Last edited: Jun 5, 2005
  7. Don Pelotas

    Don Pelotas Registered Member

    Joined:
    Jun 29, 2004
    Posts:
    2,257
    Yes, have you submitted the files to:submit@ewido.net. :)
     
  8. andre25

    andre25 Registered Member

    Joined:
    Jun 5, 2005
    Posts:
    3
    no not yet this will do I now.
     
  9. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    For the time being, I am going back to version 3 as I am having a lot of problems with the guard sticking on 50 % cpu. When it does this I have to deactivate the guard and wait a few minutes, then reactivate it. It is getting to be too much of a hassle... I will look for either a later beta or when you get this problem fixed...
     
  10. Edwin024

    Edwin024 Registered Member

    Joined:
    Nov 14, 2004
    Posts:
    1,008
    That's exactly the feeling I had: hassle... I just hope that the final 3.5 will be much better than the beta.
     
  11. chaos16

    chaos16 Registered Member

    Joined:
    Feb 14, 2005
    Posts:
    1,004
    i had loads of problems with ewido 3.5 so i changed to 3.0.

    i just find that Heuristic scanning is not a must have coz it brings so much false positives.

    but the other features i find really good but its still in beta so i understand that there is alot of bugs and false positives.
     
  12. Defenestration

    Defenestration Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    1,108
    Is there a problem with updates on ewido 3.5 beta because mine is stuck at db version #1306, with Last Update of 02/06/2005 (Known threats 162.603). When I update it keeps telling me No update available.

    BTW, why is a '.' used as the separator instead of a ',' ? My system default is a ','.
     
  13. Starrob

    Starrob Registered Member

    Joined:
    Apr 14, 2004
    Posts:
    493
    I think there is some problem on how Ewido 3.5 counts the updates. I had db version #1306 too but I went and looked in the signature folder in the Ewido Security folder, I see 6 files 1305.dat, 1306.dat, 1307.sig, 1308.sig, 1309.sig, and 1310.sig.

    I guess for some reason Ewido 3.5 counts the dat files but does not count the sig files. Maybe Fish can say why this is.


    Starrob


     
  14. feddup

    feddup Registered Member

    Joined:
    Oct 30, 2004
    Posts:
    160
    3.5 beta does seem to have some weird CPU activity. I'm not sure it plays well with pc-cillin. The unusual behavior is occuring less than 5% of the time so I'm just watching it for now. After all it is a beta. No false advertising.
     
  15. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    The ewido already scans and prevent rootkits or this will be available in the next version?
     
  16. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
  17. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    fish25,

    it's possible to:
    1. add an option to SKIP the file that the scanner is checking?
    2. add an option to ask an action for the infected files at the end of the scan?

    Thanks
     
    Last edited: Jun 6, 2005
  18. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
  19. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    Great! :D
     
  20. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    I made another scan, but without the Heuristics enable, and still get the items reported as Heuristic.Suspicious-Zip?

    Is this a bug?
     
  21. Edwin024

    Edwin024 Registered Member

    Joined:
    Nov 14, 2004
    Posts:
    1,008
    I have installed the program again too...just like it too much, I guess :)

    I also disabled the heuristics scan but still Ewido finds countless cookies, which Counterspy doesn't do and Crap Cleaner also doesn't do... They are all in the firefox directory so it seems. Maybe a bit too much form Ewido?
     
  22. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
    considered HijackThis as malware - with #1306 database - full scan
     
    Last edited: Jun 7, 2005
  23. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    1. ewido, not edwido
    2. it doesn't, at least not when I tested...

    could you please recheck? which version btw.? detected as what?
     
  24. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
    it's a TYPO - so what. You think it's going to confuse anyone? I fixed it.

    I'll edit this post after I run it again.

    *edit - sorry, I did not think that to be that erroneous to be pointed out (perhaps if I stated "CounterSpy" reported it). But anyway, I was incorrect about HijackThis, It was CWShredder 15901 (old - new version is 20000). I'll update and run EWIDO again with new post. I do think, however, it's useless to scan for all those common cookies as they come right back when visiting some popular message boards.

    http://img80.echo.cx/img80/6776/found7sr.jpg
     
    Last edited: Jun 7, 2005
  25. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    ;) no prob but I'm reading it everyday
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.