Emsisoft Anti-Malware 8.1 released

Discussion in 'other anti-malware software' started by emsisoft, Aug 19, 2013.

Thread Status:
Not open for further replies.
  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    What i gleamed from the McAfee article is what we have here is a bogus installer with a valid certificate. I don't think it comes as a surprise currently that digital certs cannot be 100% trusted these days.

    The question is how will EAM's Mamutu respond to this? Would if allow everything since the app is trusted? Or will it detect the installation of the unsigned .dll into svchost.exe? I would think it would. Also if one is running EMET 4.0, it would catch it.
     
    Last edited: Sep 5, 2013
  2. nsm0220

    nsm0220 Registered Member

    Joined:
    Aug 30, 2013
    Posts:
    138
    Location:
    USA
    i tell what when i test Emsisoft Anti-Malware 9 i keep a look out for that for you
     
  3. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Are these accounts from the same person?
    Looks weird.
     
  4. SweX

    SweX Registered Member

    Joined:
    Apr 21, 2007
    Posts:
    6,429
    Are you talking about members here on Wilders, or? :)
     
  5. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Yeah, feels as if they were spamming/trolling. :rolleyes:
     
  6. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    Most likely part of the CDN we are using.

    The installer isn't bogus. It is a completely legitimate and valid installer. It just has a bug that is abused by malware.

    Online Armor as well as EAM have special handling for those cases. Online Armor will throw an alert like this:

    http://i.imgur.com/AwC1R5f.png

    EAM will simply not trust the process.
     
  7. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Nice, this is the first time I've seen a HIPS protect against the DLL loading vulnerability and inform about it as well, instead of just saying Process 'X' wants to load DLL 'Y'.
     
  8. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Well, not exactly. In Fabian's example, the .dll to be injected was sourced on the desktop. I am sure any respectable HIPS would catch that one.

    In the McAfee example, the installer was using the trusted user32.dll to inject the unsigned MSIMG32.DLL.
     

    Attached Files:

  9. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    I used the very same malware sample to take the screenshot that McAfee describes in their blog.

    You would be surprised.
     
  10. blasev

    blasev Registered Member

    Joined:
    Oct 25, 2010
    Posts:
    763
    a very good support from emsisoft (specially from fabian), I still think EAM is the best paid product :D :thumb:
     
  11. nsm0220

    nsm0220 Registered Member

    Joined:
    Aug 30, 2013
    Posts:
    138
    Location:
    USA
    but in online armor it says to investigate not blocked
     
  12. Nightwalker

    Nightwalker Registered Member

    Joined:
    Nov 7, 2008
    Posts:
    1,387
    :rolleyes:

    You need a new hobby pal
     
  13. nsm0220

    nsm0220 Registered Member

    Joined:
    Aug 30, 2013
    Posts:
    138
    Location:
    USA
    sorry i will be testing avs for a long time
     
  14. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Thats the thing of a HIPS. It takes time and patience to know what you are doing. Google is your best friend. :D
     
  15. avman1995

    avman1995 Registered Member

    Joined:
    Sep 24, 2012
    Posts:
    944
    Location:
    india
    Without any own experience!? who called youtube testers are 100% fool-proof and 100% correct.They are all home grown tests.You have always tried to force your opinions and views on AV's on others.You are NOT the boss anyways.Everyone have their own views and opinions.You dont need to boss around.Given the fact,you follow immature testers and tests and on top of that your facts are nothing but rubbish and secondly your alter ego is annoying.Whatever disability excuse you give has no match to your rubbish replies.

    If you want to be respected,get the basics right and learn how to respect good things and opinions and put the immature things to the fire.You should boycott all immature tests or any test to the fire because no testbed is 100% and everything has its own flaws.What is more important is how a product works out fro you or your concerned user in the real world.

    I know you and your friends have been doing these type of immature tests since ages and I know how pasionate you guys are.Any tests these days are useless with the influx of malwares coming out everyday.

    1/10 made me reply. >arguing with us on wilders about AV's effectivness >no own experience >quoting commercial and home grown testers >2013

    Learn the basics first,forum policy gives you enough about these type of home grown tests:
    If you still cant get your stuff right,then this place is not for you.
     
    Last edited: Sep 8, 2013
  16. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    I didn't say they don't, I said blocking in combination with being informative about it like that. It shows the requested DLL path, and the original Windows DLL path and informs about the DLL loading vulnerability. Most other HIPS would just throw a prompt X.exe wants to load Y.dll and then the user has to notice Y.dll is located in the Desktop folder for example, and not in the System32 folder.
     
  17. Nightwalker

    Nightwalker Registered Member

    Joined:
    Nov 7, 2008
    Posts:
    1,387
    I am experiencing some large updates again, I think it started two days ago ...

    8 ~ 12 mb each update :doubt:
     
  18. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Same here. Started 2 -3 days ago.
     
  19. emsisoft

    emsisoft Security Expert

    Joined:
    Mar 12, 2004
    Posts:
    328
    Location:
    Nelson, New Zealand
    Thanks for letting us know. The problem has been solved and small updates are available again!
     
  20. Pars

    Pars Registered Member

    Joined:
    Oct 22, 2011
    Posts:
    20
    Location:
    Tehran, Iran
    Emsisoft Anti-Malware 8.1.0.19 with BETA updates enabled:

    Program freeze issue fixed.
    Minor GUI bug fixed.


    Emsisoft Online Armor 7.0.0.1862 with BETA updates enabled:

    Filtering invalid MAC addresses feature blocking valid addresses – fixed.
     
  21. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    You are 11 days late......:D
     
  22. Pars

    Pars Registered Member

    Joined:
    Oct 22, 2011
    Posts:
    20
    Location:
    Tehran, Iran
    To remind :thumb:
     
  23. Brandonn2010

    Brandonn2010 Registered Member

    Joined:
    Jan 10, 2011
    Posts:
    1,854
    New Softpedia review:

    http://www.softpedia.com/reviews/windows/Emsisoft-Anti-Malware-Review-387635.shtml

    The Good

    It provides comprehensive protection against all sorts of malware and can function along with other security suites.

    The default configuration fits multiple user types and is flexible enough to offer more advanced users the possibility to customize how their system is protected. Notifications and the number of alerts can be cut down automatically, based on community input and other settings.

    The Bad

    The traditional interface could drive users away from it. The main application window features entries that point to different sections of the developer’s website and news notifications are turned on by default, showing up from time to time on the desktop.

    The Truth

    During our tests, Emsisoft Anti-Malware 8.1 managed to score high as far as the detection rate is concerned, proof that the Emsisoft-Bitdefender scan duo is highly efficient.

    However, the availability of some extra layers of protection (e.g. for financial online transactions, exploitation of vulnerabilities), would make it more appealing.
     
  24. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Official web page still shows 8.1.0.4 as the latest version.
    o_O
     
  25. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    Will be fixed ASAP :).
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.