Immunet 5 beta

Discussion in 'other anti-virus software' started by Mops21, Jul 30, 2016.

  1. Tarantula

    Tarantula Guest

    I know very well what they mean. I have used their free version before. That was the difference between free and commercial version. First one was lacking the most important engine. Means they are now releasing the good old basic free version, just updated. I was hoping they'll release the full version for free. That's it.
     
  2. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    No paid version anymore, interesting.

    ETHOS en SPERO engines both enabled by default(Afaik Immunets own) and ClamAV disabled by default. It does still contain a Tetra folder with Bitdefender files in it.

    ClamAV folder contains OpenSSL DLL's which are still vulnerable to Heartbleed...
    (Version 1.0.1e, 10 releases behind the latest 1.0.1 release.)
     
  3. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    "Eye sea," said the blind man. May I ask: what "most important engine" is missing in the free that was present in the non-free?
     
  4. Tarantula

    Tarantula Guest

    I'll quote Immunet forum moderator on this:

    "Bitdefender's detection engine was licensed for use and was modified and enhanced to make it much better at detecting threats and thus became the Tetra engine. This is now only available to the remaining Plus users or those using FireAMP."
     
  5. entropism

    entropism Registered Member

    Joined:
    Dec 9, 2004
    Posts:
    500
    So what engines are in use for the current free version? Just Clam AV?
     
  6. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Strange that the Bitdefender/Tetra files are still there then, even looks like they still install the driver:
    immunet.png

    5.0.2 released:
    http://support.immunet.com/index.php?/topic/3063-new-release-immunet-502/
    Update to newer ClamAV also contains up to date OpenSSL.

    Also 2 engines from Immunet itself, SPERO and ETHOS.
     
  7. Oximoronman

    Oximoronman Registered Member

    Joined:
    Jun 7, 2013
    Posts:
    95
    Pff they are very unknown for me.
     
  8. haakon

    haakon Guest

    OH NO! Immunet is doomed!! :eek:
     
  9. Oximoronman

    Oximoronman Registered Member

    Joined:
    Jun 7, 2013
    Posts:
    95
    Can anyone sniff connection of beta 5 and release link for offline installer?
     
  10. Antivirus Tester

    Antivirus Tester Registered Member

    Joined:
    Jun 14, 2015
    Posts:
    6
    This av is never going to beat Emsisoft or Bitdefender
     
  11. ArchiveX

    ArchiveX Registered Member

    Joined:
    Apr 7, 2014
    Posts:
    1,501
    Location:
    .
    I feel the same...;)
     
  12. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    AFAIK, Immunet is designed to be an adjunct AV, not the principal.
     
  13. Iangh

    Iangh Registered Member

    Joined:
    Jul 13, 2005
    Posts:
    849
    Location:
    Melbourne, Australia
    Has anybody tested, or seen a test, of the Immunet engines?
     
  14. haakon

    haakon Guest

    Immunet 5.0.2.10301
    Windows 10 Home X64 not-AU
    Defender
    MBAE Free 1.09.1.1175
    SpyShelter Free 10.8.4
    VoodooShield Free 3.31 Beta

    ImmunetGUI.jpg

    Three drivers are injected into System:
    •Immunet Self Protect Driver - immunetselfprotect.sys
    •Immunet Protect Driver - immunetprotect.sys
    •Immunet Network Monitor Driver WFP - ImmunetNetworkMonitor.sys

    Two processes are running:
    •Immunet Protect Tray Client - iptray.exe
    •Sourcefire Connector - sfc.exe - Service, Automatic Startup, display name Immunet 5.0.2.

    The usual Clam stuff is present including, of course, the main.cvd defs file, 106,586 KB.

    The Connector consists of:

    ImmunetSFCstuff.jpg

    During user file activities both iptray and sfc open connections to Amazon cloud services and cloud-consumer-asn dot immunet dot com on port 443. These connections close once their cloud work is done.

    I have briefly seen freshclam.exe open a connection to a Clam named domain in Singapore (according to the latest GeoCity database) but hosted by a Brazilian provider (sagres dot c3sl dot ufpr dot br). I wasn't sniffing/logging at the time but as Clam is reserved for offline protection, I believe this is a definitions check/update routine.

    All these connectivity observations are casual. I won't be digging into it any further considering that one's location globally might present differing connections.

    Suffice to day, when online Immunet is cloud.

    Three tray icon notifications are available, cloud, tray and game, all off by default. With Cloud Notifications and Verbose Tray Notifications enabled, things get pretty chatty:

    ImmunetTRAY.jpg

    The tetra folder has a few, very few, Bitdefender components but none are active that I can find. The Plugins folder where one would find at least a subset of the hundreds of BD defs/sigs is empty but for a 0KB update.txt. I believe these could be leftovers, therefore now as place holders, from the previous paid version for when BD went active when Immunet was offline. Tetra was, in addtion to Clam, the offline component in that era and not active in the free version. I believe the same holds true now though the active Tetra Engine Library in the Connector presents an enigma. One that I might resolve in a discussion with Support. Or not.
    Immunet Ethos and Spero use the cloud side via the Sourcefire Connector.
    IMHO considering its history and pedigree, Immunet is a worthwhile layer and a valuable enhancement to Defender's core mission.
     
    Last edited by a moderator: Sep 7, 2016
  15. Iangh

    Iangh Registered Member

    Joined:
    Jul 13, 2005
    Posts:
    849
    Location:
    Melbourne, Australia
    I've always had a lot of respect for Cisco and, therefore, assume Immunet is OK. Would love to see a test if somebody that knows what they are doing would oblige.:thumb:
     
  16. haakon

    haakon Guest

    I have no idea what I'm doing, but what the heck...

    I opened over a dozen threats "off the top" of VXVault and malc0de.

    For for each the tray icon animated and a connection by sfc.exe was opened. The connection was closed immediately upon the Warning!

    All threats I selected were snagged. xxxx

    Downloads were not permitted to complete - only partial files made it to the system Temp folder.

    ImmunetQ.jpg

    ImmunetAlerts.jpg

    Windows 10 Home x64 not-AU
    Cyberfox 48.0.2 - Safe Browsing disabled
    All other anti-whatever disabled.
     
  17. haakon

    haakon Guest

    Oh look!

    https://www.youtube.com/watch?v=RoLFL8gwqSY
     
    Last edited by a moderator: Sep 12, 2016
  18. Iangh

    Iangh Registered Member

    Joined:
    Jul 13, 2005
    Posts:
    849
    Location:
    Melbourne, Australia
    I found it really slowed my internet.
     
  19. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
    Had too much false positives myself and rapidly got rid of it.
     
  20. haakon

    haakon Guest

    Well, just for the record in response to what is at best anecdotal evidence:

    I use an eight year old system as a Windows 10 test system and I hammer the crud out of it.

    In about a month of running Immunet 5... zero false positives.

    The only time Immunet uses "my Internet" is when it's scanning a file using Sourcefire Connector (sfc.exe) and its occasional Check for Updates.

    The connection persists for a few seconds; the bandwidth barely registers in my network logging with ~900 KB (yes, KB) so far.

    Total traffic up to right now is 2.4 MB dominated by Clam's off line support files updating. This can be eliminated by setting Allow Definition Updates to Off.

    As far as "the Internet" is concerned, it barely knows Immunet is there.

    Oh wait! Never mind. Immunet just reported Wilders as W32.WUZZAT100.WTF.TG and it's taken five hours to type this in. :argh:
     
  21. Iangh

    Iangh Registered Member

    Joined:
    Jul 13, 2005
    Posts:
    849
    Location:
    Melbourne, Australia
    I re-installed Immunet to measure the delay. Home page is BBC News and I measured how long to load BBC Sport from News to allow Chrome to be fully working. Without Immunet 2.5s, with Immunet 7.5s.
     
  22. haakon

    haakon Guest

    Thanks for the feedback.

    bbc dot com/sport fully renders before I can finish saying "one one thousand." I won't be uninstalling Immunet to find out if it's any faster than that.

    Sorry you're having browser issues.
     
  23. Iangh

    Iangh Registered Member

    Joined:
    Jul 13, 2005
    Posts:
    849
    Location:
    Melbourne, Australia
    Are you also using WD?
     
  24. Oximoronman

    Oximoronman Registered Member

    Joined:
    Jun 7, 2013
    Posts:
    95
    Immunet is trash- trash detection,trash gui...
     
  25. haakon

    haakon Guest

    Another interesting "test."
    https://www.youtube.com/watch?v=aohmW4tPz64

    At the very beginning he states that Sourcefire recently acquired Immunet while displaying the news article dated... January 2011. :argh: :rolleyes:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.