Emsisoft Anti-Malware 8.1 released

Discussion in 'other anti-malware software' started by emsisoft, Aug 19, 2013.

Thread Status:
Not open for further replies.
  1. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Good point of views. :D
    I still wonder why EAM cant catch lots of cookies that HMP do. Or is it that they get through when i disable the guard from time to time.
     
  2. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    The thing with cookies is, that it is incredibly difficult to determine whether they are good or "bad". Quite frankly, your browser does a way better job protecting you from tracking cookies, if you disable third party cookies and enable the DNT flag, then any outside application can, as the browser knows a lot more about the circumstances of how those cookies were created. That is one of the reasons why we will likely remove the cookie scan entirely in one of the next releases.
     
  3. pablozi

    pablozi Registered Member

    Joined:
    Oct 24, 2010
    Posts:
    215
    Location:
    nowhere
    I think, there are some quite useful browser addons that can help to secure your system from "bad cookies", like Vanilla for Chrome or even ABP or Ghostery.
     
  4. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Oh i understand. I dont really care that much about cookies because cookies at least for me is not really a big deal but i always wondered why HMP always found so many of them. :D
     
  5. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    :thumb:
     
  6. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    Personally, I would prefer Disconnect over Ghostery, as the later will share information with ad networks. You can disable the information sharing by disabling the GhostRank, but it is enabled by default.
     
  7. FOXP2

    FOXP2 Guest

    MBAM is the Kevlar for your head.
    .
     
  8. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    I never should have used that analogy because it only enabled people to create arguments based on pure speculation, which, thanks to the analogy, now seem more solid.
     
  9. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Sorry for a bit off topic.

    Is HIPS of Online Armor freemium the same as of the paidee?
     
  10. guest

    guest Guest

    Take a look
    http://www.areweprivateyet.com/
    Thanks to sharing this information (statistics, and without ID you) they are able to add more and more trackers to the list, this is why now they are slightly better than ABP lists

    Yes, http://support.emsisoft.com/topic/12457-oa-free-vs-premium/
     
    Last edited by a moderator: Jan 2, 2014
  11. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Thank you. So from anti-malware tests follows that OA fremium (Standard Mode) is a bit weaker then OA premium in Advanced Mode as 90% vs 95%.
     
  12. The Hammer

    The Hammer Registered Member

    Joined:
    May 12, 2005
    Posts:
    5,752
    Location:
    Toronto Canada
    There was speculation by all sides.
     
  13. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Afaik GhostRank is disabled by default, and has always been like that.
     
  14. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    I am pretty sure it was opt-out the last time I tried it, which admittedly has been a while ago. If they changed it to opt-in, that's great. In general I prefer Adblock Edge with customized filter lists, disabled third party cookies, and DNT header over Disconnect or Ghostery anyways, as Adblock and Ghostery/Disconnect produce a huge overlap in functionality from a technical point of view.
     
  15. henryg

    henryg Registered Member

    Joined:
    Dec 13, 2005
    Posts:
    342
    Location:
    Boston
    After trying Ghostery, I've decided to do a system scan it with MBAM....the result was somewhat unsettling:



    Registry Keys Detected: 12
    HKCR\CrossriderApp0020900.BHO (PUP.Optional.CrossRider.A) -> No action taken.
    HKCR\CrossriderApp0020900.BHO.1 (PUP.Optional.CrossRider.A) -> No action taken.
    HKCR\CrossriderApp0020900.Sandbox (PUP.Optional.CrossRider.A) -> No action taken.
    HKCR\CrossriderApp0020900.Sandbox.1 (PUP.Optional.CrossRider.A) -> No action taken.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211091100} (PUP.Optional.CrossRider.M) -> No action taken.
    HKCR\CLSID\{11111111-1111-1111-1111-110211091100} (PUP.Optional.CrossRider.M) -> No action taken.
    HKCR\TypeLib\{44444444-4444-4444-4444-440244094400} (PUP.Optional.CrossRider.M) -> No action taken.
    HKCR\Interface\{55555555-5555-5555-5555-550255095500} (PUP.Optional.CrossRider.M) -> No action taken.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110211091100} (PUP.Optional.CrossRider.M) -> No action taken.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110211091100} (PUP.Optional.CrossRider.M) -> No action taken.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211091100} (PUP.Optional.CrossRider.M) -> No action taken.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211091100} (PUP.Optional.CrossRider.M) -> No action taken.

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 1
    C:\Program Files (x86)\Ghostery IE\Ghostery IE.dll (PUP.Optional.CrossRider.M) -> No action taken.
     
  16. eplose

    eplose Registered Member

    Joined:
    Sep 28, 2009
    Posts:
    51
    - Does EAM use the latest BD engine?
     
  17. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Yes...and signatures as well.
     
  18. m0use0ver

    m0use0ver Registered Member

    Joined:
    Jun 30, 2011
    Posts:
    81
  19. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I am running v8.1.0.35, and decided to run my first custom scan.

    However, I wish I hadn't because I don't believe the results. I think in future I think I will forego this type of after the event scanning.

    ScreenShot_EAM_custom scan_false positives_03.gif

    ScreenShot_EAM_custom scan_false positives_05.gif

    P.S. I system restored to a point previous, after running a HMP scan which didn't seem to run well.
     
  20. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Looks like FPs from Bitdefender....I hope you have reported them.
     
  21. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I really shouldn't need to...;)
     
  22. fixanoid

    fixanoid Registered Member

    Joined:
    Feb 17, 2011
    Posts:
    24
    Hi! Ghostery for IE uses Crossrider framework that has also been used by unsavory parties in the past. That said, Ghostery for IE acts same way as Ghostery for any other browsers, and PUP (Potentially Unwanted Program) in this case is a false positive.
     
  23. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    See a follow up in the Prevx Releases thread - Scan results that are confusing... here
     
  24. Cassy

    Cassy Registered Member

    Joined:
    Jan 8, 2010
    Posts:
    6
    Trying out 8.1.0.31

    When I do a deep scan, it finds :

    Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\AU__RASAPI32 detected: Application.Win32.InstallExt (A)
    Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\AU__RASMANCS detected: Application.Win32.InstallExt (A)

    What are these two beings and how do I get red of them?

    In general, when emsisoft finds something, how do I get information on it?

    Thanks.
    C.
     
  25. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,076
    Location:
    UK
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.