ewido security suite 3.5 beta

Discussion in 'other anti-trojan software' started by quexx88, May 27, 2005.

Thread Status:
Not open for further replies.
  1. gerardwil

    gerardwil Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    4,748
    Location:
    EU
    just updated:

    heuristic.dat
     
  2. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    Thanks ;)
     
  3. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    No more handle leak :)
     
  4. gerardwil

    gerardwil Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    4,748
    Location:
    EU
    Major program update as well as sig update(1313)
     

    Attached Files:

  5. Defenestration

    Defenestration Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    1,108
    Any chance ewidoguard can be optimised so that scans faster when starting appications, as I previously mentioned in this post.

    Currently it is too slow. To see what I mean, startup Task Manager and watch the amount of CPU usage of ewidoguard when starting an app (eg. Offline Explorer is a good one for the test). You will see it scans for a long time before the app is finally allowed to start.
     
  6. Edwin024

    Edwin024 Registered Member

    Joined:
    Nov 14, 2004
    Posts:
    1,008
    A new heuristics part and again a load of false positives... Will this ever be solved? I don't see Ewido getting out of beta if every update brings new fp's, alas...
     

    Attached Files:

  7. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    I don't think so... It's the engine that takes all the power (e.g. when the emulation has to run)... However, I already have some ideas to improve this but it will take some time...

    @Edwin024: false positives are one of the last few things we are currently working on...
     
  8. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    In trying to do a complete system scan with the latest release, the securitysuite.exe keeps shutting down and will not complete a scan. Any ideas?
     
  9. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    It's a known bug, unfortunately we can only reproduce it by scanning our very large whitelist -> fixing could take some time :(
     
  10. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    Another "Complete System Scan" with the default settings more scan every file:

    Code:
    ---------------------------------------------------------
     ewido security suite - Scan report
    ---------------------------------------------------------
    
     + Created on:			12:32:20, 27-06-2005
     + Report-Checksum:		6C637275
    
     + Scan result:
    
    	C:\Program Files\NeoTheme\NeoTheme.exe -> TrojanDownloader.Sahat : Ignored
    	C:\WINDOWS\inf\biosinfo.inf -> Trojan.WinINF.Delreg : Ignored
    	D:\Aulas\Simulacao\Python 2.3.2.zip/Python 2.3.2.exe -> Spyware.VirtualBouncer : Ignored
    	D:\IRC\anaconda\mirc.ini -> Worm.Randon : Ignored
    	D:\IRC\AnacønÐa ns2.10.zip/anaconda/mirc.ini -> Worm.Randon : Ignored
    	D:\Software\File Managers\rjhExtensions 1.3.zip/Install.exe -> Spyware.eZula : Ignored
    	D:\Software\Internet\Browsers\IE plugins\Macromedia Shockwave Player 10.1.0.11.zip/Macromedia Shockwave Player 10.1.0.11.exe -> Spyware.eZula : Ignored
    	D:\Software\Internet\Browsers\Mozilla Firefox\Plugins\Macromedia Shockwave Player 10.1.0.11.zip/Macromedia Shockwave Player 10.1.0.11.exe -> Spyware.eZula : Ignored
    	D:\Software\Internet\Browsers\Opera\plugins\Macromedia Shockwave Player 10.0.1.4.zip/Shockwave_Installer_Full.exe -> Spyware.eZula : Ignored
    	D:\Software\Internet\Chat\Instant Messaging\ICQ 5.04 build 2321.zip/icq5_setup.exe -> Spyware.VirtualBouncer : Ignored
    	D:\Software\Internet Security Suites\ZoneAlarm Security Suite 5.5.094.zip/zaSuiteSetup_55_094_000.exe -> Spyware.VirtualBouncer : Ignored
    	D:\Software\Security\Firewall\Outpost Firewall\Outpost Firewall PRO 2.7.485.412.zip/OutpostProInstall.exe -> Spyware.VirtualBouncer : Ignored
    	D:\Software\Security\Firewall\Outpost Firewall\Plugins\PC Flank WhoEasy 1.0.zip/whoeasy.exe -> Spyware.VirtualBouncer : Ignored
    	D:\Software\System\OS Enhancements\XPlite Professional 1.6.0286.zip/XPlite.exe -> Heuristic.Win32.Backdoor3 : Ignored
    
    
    ::Report End
     
  11. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    Most of the fps should now be fixed... :)
     
  12. Edwin024

    Edwin024 Registered Member

    Joined:
    Nov 14, 2004
    Posts:
    1,008
    Fish: working on it sounds great! I hope 3.5 will be as stable as 3.0 but better in every aspect. And it looks like that!
     
    Last edited: Jun 27, 2005
  13. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Maybe this screenshot will help...
     

    Attached Files:

  14. Starrob

    Starrob Registered Member

    Joined:
    Apr 14, 2004
    Posts:
    493

    I still got more than a few FP's on my last scan with the database released today. I already sent in a list of the files.
     
  15. Edwin024

    Edwin024 Registered Member

    Joined:
    Nov 14, 2004
    Posts:
    1,008
    Me too... and again new ones...it's amzing ;)
     
  16. gottadoit

    gottadoit Security Expert

    Joined:
    Jul 12, 2004
    Posts:
    605
    Location:
    Australia
    fish25,
    When I start the securitysuite.exe why does it poll the following keys multiple times per second ? Is there some other process out there that is going to change them that would need the main executable to respond in near-real time

    Would it be worth considering polling less frequently to help reduce unncessary context switching (for those of us still suffering the burden of having a single cpu) ?

    Here are the keys I see on this system, quite possibly the ones with odd characters are specific to each install....

     
  17. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    "Complete System Scan" with the default settings more scan every file:

    Code:
    ---------------------------------------------------------
     ewido security suite - Scan report
    ---------------------------------------------------------
    
     + Created on:			19:54:30, 27-06-2005
     + Report-Checksum:		60E55C0D
    
     + Scan result:
    
    	C:\Program Files\NeoTheme\NeoTheme.exe -> TrojanDownloader.Sahat : Ignored
    	D:\Software\System\OS Enhancements\XPlite Professional 1.6.0286.zip/XPlite.exe -> Heuristic.Win32.Backdoor3 : Ignored
    
    
    ::Report End
    Only 2 FP ;)
     
  18. WilliamP

    WilliamP Registered Member

    Joined:
    Jun 1, 2003
    Posts:
    2,208
    Location:
    Fayetteville, Ga
    I am running 3.5 BETA and this morning Process Guard had Ewido blocked because something had changed. Then I had to reboot to be able to get into Firefox. Was there an update that needed to reboot?
     
  19. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    yes, ewidoguard.exe, securitysuite.exe, engine.dll etc. have been updated...
     
  20. WilliamP

    WilliamP Registered Member

    Joined:
    Jun 1, 2003
    Posts:
    2,208
    Location:
    Fayetteville, Ga
    Thank you Fish. The 3.5 BETA has been doing good on my system.
     
  21. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    fish25,

    it will be possible to add support for 7-Zip and Ace archives?

    Regards
     
  22. feddup

    feddup Registered Member

    Joined:
    Oct 30, 2004
    Posts:
    160
    latest update?

    Is anyone else having trouble getting the latest update. Last night ewido deleted it's definitions and said a new update is available. About 5.2 Mb. It gives me a "connection timeout error" about 2/3rds of the way through everytime. I've tried 5-6 times. My internet connection is fine other than being dial up and thus slow. I e-mailed support but only got an automated message so far.
     
  23. Notok

    Notok Registered Member

    Joined:
    May 28, 2004
    Posts:
    2,969
    Location:
    Portland, OR (USA)
    Re: latest update?

    The processes list seems to be crashing on mouse-over again.. (same issue, no crash when mouse software is disabled)
     
  24. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    Re: latest update?

    Nothing has been change on that part :) Which mouse software?
     
  25. peter.ewido

    peter.ewido former ewido team

    Joined:
    Nov 10, 2003
    Posts:
    737
    Location:
    Brno, Czech Republic
    Sorry but I don't think so... It would take too much time and isn't used very widely...
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.