Emsisoft Anti-Malware

Discussion in 'other anti-malware software' started by Austerity, Jan 10, 2015.

  1. Austerity

    Austerity Registered Member

    I really wouldn't recommend running EAM with any other true AV, and it really isn't need.

    As usual, MBAM and Webroot work perfectly with it, but I don't know if they even give you any more protection.

    If you really want something for second opinions, keep Hitman Pro and Herd Protect installed, keeping in mind that not much gets past Hitman, but Herd Protect you've got to look into the false positives..
     
  2. Nightwalker

    Nightwalker Registered Member

    Try Emsisoft AntiMalware 9 later, it may fit your needs ;)
     
  3. Mortal Raptor

    Mortal Raptor Banned

    I tried it 3 months back and loved it. Only stopped using it because they had an issue where on a Windows 8.1 system, the icon in the system tray would become hidden upon a reboot even though you have set it to always show. Do you think they fixed that yet?
     
  4. siketa

    siketa Registered Member

    Uhhh....now that was the reason to stop using it.... :)
     
  5. Mortal Raptor

    Mortal Raptor Banned

    I do not accept using buggy software. Especially after reporting it on their forums and no action taken for more than 10 days
     
  6. Nightwalker

    Nightwalker Registered Member

    I think they have, take a look here:

    http://changeblog.emsisoft.com/2014...alware-internet-security-9-0-0-4668-released/

    "Fixed a disappeared icon in the notification area (...) "
     
  7. Mortal Raptor

    Mortal Raptor Banned

    Last edited: Feb 18, 2015
  8. Mayahana

    Mayahana Banned

    LOL.. See you next week on the uninstall!
     
  9. Mortal Raptor

    Mortal Raptor Banned

    so far no disappearing icon and that was the only issue I faced before otherwise I liked it. so I think this time you may be wrong my friend
     
  10. LOL..


    No, I'll bet that Mayahana is right. I like Emsisoft quite a bit. I use the Freeware version on three computers. But the false positives you will encounter will not be to your liking.
     
  11. Mortal Raptor

    Mortal Raptor Banned

    that was true last year when I first used it, I found myself reporting FPs on the forums more than actually using my computer. Stuff like my VPN (Private Internet Access), Pale Moon, SVP (Smooth Video Project), like really popular stuff were flagged by their behavioral blocker. When I tested it again 3 months ago all that was gone thankfully with the exception of the disappearing taskbar icon that bugged the hell out of me and even though cosmetic, I just couldn't take it. The other bug wsa that the Windows 8 security center would sometimes report that EAM is off even thought it was on. haven't had that happen yet and according to the changelogs it should be fixed....
     
  12. Mayahana

    Mayahana Banned

    People leave security center running? That's one of the first services/icons I disable.
     
  13. phalanaxus

    phalanaxus Registered Member

    I haven't encountered any false poisitives with Emsisoft at all after they spotted using Ikarus.
     
  14. siketa

    siketa Registered Member

    Guys also consider BB alerts as false positives. ;)
     
  15. fblais

    fblais Registered Member

    Please forgive my ignorance but why?
    Is it a security threat?
     
  16. G1111

    G1111 Registered Member

    Same here, no FP's.
     
  17. anon

    anon Registered Member

  18. Rules

    Rules Registered Member

    No it is not a security threat. IMHO, you should leave it enabled, and just untick some option in the control panel and deactivate the icon why?

    1- WSCSVC, use about 10 mo (less or plus depend of machine).
    2- This service have components dependencies, for example on Windows 7_X64, they have two.
    3- Some security scanner could alert you (Malwarebyte's if i correct remember and....), if you're a novice user you could think that is a threat and delete the registry entries.
    4- If for some reasons you decide to re-enable it sometimes you could get a error code that the security center could not start, because of (cleaning software, major windows updates) this is related to the connexion tab in the service.

    @Mayahana
    Of course you could disable-it.

    sec.PNG ic.PNG task.PNG dep.PNG connex.PNG
     
  19. Mayahana

    Mayahana Banned

    No security risk. I disable it on my personal machines. But I turn off the System Icon for it so the flag goes away on most machines. The flag generates quite a number of 'useless' support calls usually pertaining to windows update mis-reads because we're pushing from a GP or something. But generally the flag goes off for me as well.
     
  20. markr7750

    markr7750 Registered Member

    This is not a false positive with the signature-based side of things (in the case of them being able to do further analysis on the program and then decide whether they wish to whitelist the file or keep the SHA-256/SHA-1/MD5 signatue in their virus definitions database), but a behaviour-side detection (the case where they won't release an update whitelisting this file in the Behaviour Blocker protection module, specifically).

    The detection name: "Behaviour.TrojanDown" suggests that it was trying to "invisibly" download data to the computer (a suggested trait of what a Trojan Downloader may attempt to do). The only way around this, would be for the developer to overview his code and change it so it doesn't become detected whilst downloading (update information, new versions) or to whitelist the program completely with the Application Rules area on Emsisoft Anti-Malware.

    The Emsisoft Anti-Malware Behaviour Blocker is very sophisticated, to an extent. I'd rather have a few false positives in the behaviour detection and a greater detection of live threats - especially when you have the ability to know if a file is malicious by analyzing the program yourself if it detects something you did not expect.

    Anyway, if you are wondering, "well why can't they whitelist Potplayer in the Behaviour Blocker?" - the answer to this is because this would be going against the point of a behaviour blocker (since it's not meant to be working with a blacklist of signatures, nor a whitelist made by them), and if in the future Potplayer decided to do something malicious and join the bad guys (which I doubt would happen but it's an example and something which could potentially happen with anyone's product), then a lot of users may become infected by it using Emsisoft products unless the Emsisoft staff managed to release a new update removing the whitelist quickly, in which may be too late having not known about it starting to do malicious things.

    Point is, it's a great product. Whitelist Potplayer and everything should be fine.
     
  21. hawki

    hawki Registered Member

    That issues was fixed in an update :)

    I never have that issue though I suppose YMMV.

    Also for a time Windows Action Center was not reporting EMIS as being on until you did an update, ALTHOUGH IT ALWAYS WAS on - had to do with a change in the order WAC looked for an av and the timing of when EMIS reported to WAC it was on, --that too was fixed)
     
    Last edited: Feb 22, 2015
  22. Mortal Raptor

    Mortal Raptor Banned

    yes been running it for more than 3 days now and very happy all the quirks that I had were ironed out, no false positives, light, excellent PUP detection. Truly pleased with this
     
  23. Nightwalker

    Nightwalker Registered Member

  24. jjc225

    jjc225 Registered Member

    I recently went back to Emsisoft on one of my computers. One of the first scans came up with this, some of which is in this screen shot. What is this?
     

    Attached Files:

  25. siketa

    siketa Registered Member

    I suggest to ask about this on Emsisoft forum.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice